Sign in

Cyrill

@bcyrill.bsky.social
84 followers 222 following 0 posts
PostsRepliesMedia
Reposted by Cyrill
TrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026
Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 & 2 Master of Pwn points. #Pwn2Own
085
Reposted by Cyrill
TrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026
Very nicely done! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit Anthropic Claude Code! They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin
183
Reposted by Cyrill
Compass Security @compass-security.com · 15/05/2026
4th place after two days of #pwn2own in Berlin. Fingers crossed for the 3rd day and our colleagues attempt on Claude Code.
072
Reposted by Cyrill
TrendAI Zero Day Initiative @thezdi.bsky.social · 15/05/2026
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security exploited Cursor in the second round, earning $15,000 and 3 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
041
Reposted by Cyrill
TrendAI Zero Day Initiative @thezdi.bsky.social · 15/05/2026
Boom! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security was able to exploit Cursor! They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin
032
Reposted by Cyrill
TrendAI Zero Day Initiative @thezdi.bsky.social · 14/05/2026
It's official! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) used a single CWE-150 bug to exploit OpenAI Codex, earning $40,000 and 4 Master of Pwn points. #Pwn2Own #P2OBerlin
023
Reposted by Cyrill
TrendAI Zero Day Initiative @thezdi.bsky.social · 14/05/2026
Big W!! 💪 Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit OpenAI Codex! Off to the disclosure room to spill the tea. #Pwn2Own #P2OBerlin
042
Reposted by Cyrill
Compass Security @compass-security.com · 13/05/2026
Compass vulnerability research identified code execution paths affecting AI coding assistants including Claude Code, OpenAI Codex and Cursor. The findings will be demonstrated live at @thezdi.bsky.social Initiative #Pwn2Own Berlin 2026, May 14 to 16. #AIsecurity #LLM
042
Reposted by Cyrill
Compass Security @compass-security.com · 11/05/2026
🦖 Meet RAPTR: our new open source platform for red and purple team collaboration. Plan engagements, document attacks and detections, evaluate results, and generate reports, all API-driven. Beta is live, feedback welcome! #PurpleTeam blog.compass-security.com/2026/05/intr...
011
Reposted by Cyrill
Compass Security @compass-security.com · 07/04/2026
Part 3 of our Entra ID blog series looks at common weak PIM configurations, practical abuse scenarios, and how to identify them with EntraFalcon: blog.compass-security.com/2026/04/comm...
021
Reposted by Cyrill
Compass Security @compass-security.com · 24/03/2026
Foreign enterprise apps can expose your Entra ID tenant. Today, we release part 1 of our 4-part weekly series on common Entra ID pitfalls and how to detect them with EntraFalcon. Learn how external apps can lead to data access or worse: blog.compass-security.com/2026/03/comm...
032
Reposted by Cyrill
Compass Security @compass-security.com · 17/03/2026
EntraFalcon update 🚀 The new Security Findings Report turns Entra ID enumeration into actionable findings with 60+ checks and colorful charts. Read Chrigi's @zh54321.bsky.social blog and try the tool now on your tenant! blog.compass-security.com/2026/03/from... #EntraID #CloudSecurity #EntraFalcon
044
Reposted by Cyrill
Compass Security @compass-security.com · 21/01/2026
A night full of exciting happenings. Compass #Pwn2Own team chained zero days to run code on the Canada built Grizzl-e Smart level 2 charger. Colleagues also demoed the manipulation of of the charging control protocol. Well earned 25‘000 USD!
274
Reposted by Cyrill
Compass Security @compass-security.com · 21/01/2026
We have exciting news to share. Compass folks made the Alpine car infotainment system to run arbitrary code and earn a 10‘000 USD. 🎉🎉🎉
284
Reposted by Cyrill
TrendAI Zero Day Initiative @thezdi.bsky.social · 21/01/2026
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) exploited one exposed dangerous method/function bug on the Alpine iLX-F511, winning Round 2 for $10,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto
034
Reposted by Cyrill
James Kettle @jameskettle.com · 14/07/2025
We've just released a massive update to Collaborator Everywhere! This is a complete rewrite by @compass-security.com which adds loads of features including in-tool payload customization. Massive thanks to Compass for this epic project takeover. Check out the new features:
1187