Sign in

Compass Security

@compass-security.com
471 followers 1K following 96 posts

Penetration Testing, Red Teaming, Incident Response, Managed Detection, Digital Forensics, Security Training, Managed Bug Bounty, Cyber Training Range

PostsRepliesMedia
Compass Security @compass-security.com · 03/09/2026
From 11 September 2026, manufacturers selling digital products in the EU have 24 hours to report actively exploited vulnerabilities. ⏱️ Andreas Brombach explains what is reportable, and how to actually make those deadlines. blog.compass-security.com/2026/09/cra-... #CRA #ProductSecurity
010
Compass Security @compass-security.com · 25/08/2026
Pentesting passkeys? Security analyst @emanuelduss.ch shows two JS snippets for tampering with the WebAuthn APIs. Handy for checking if you can login using a security key without knowing the PIN. Check out the technical details and how he got there: blog.compass-security.com/2026/08/a-no...
021
Compass Security @compass-security.com · 04/08/2026
Pipeleek 1.0 is out 💧 Secret scanning across 7 CI/CD platforms, plus runner and Renovate bot exploitation. Want to see one leaked job log turn into repo takeover? Try our deliberately vulnerable GitLab Attack Lab. Happy leeking! blog.compass-security.com/2026/08/pipe... #DevSecOps #CICD
111
Compass Security @compass-security.com · 21/07/2026
Your team evaluated that automation platform as a productivity tool. Attackers see a jump host with SSH access, stored credentials, and a path around your network segmentation. Read our latest blog post before deploying any automation platform: blog.compass-security.com/2026/07/the-...
010
Compass Security @compass-security.com · 07/07/2026
How do you translate the Cyber Resilience Act into technical testing? Part II of our #CRA series follows a cheap IP camera, from STRIDE threat modelling and firmware analysis to compliance with IEC 62443-4-2. blog.compass-security.com/2026/06/cybe... #CyberSecurity #CyberResilienceAct #IEC62443
031
Compass Security @compass-security.com · 26/06/2026
How do you prepare a product for the Cyber Resilience Act? Our latest article covers #CRA scope, product classification, threat modelling, technical security testing, and why we use IEC 62443 as an assessment framework. Part I of a two part series: blog.compass-security.com/2026/06/cybe...
Screenshot of an IEC 62443-4-2 security assessment report showing three overlapping report sections. The background page contains an overview table listing security requirements and the achieved Security Level (SL0 to SL4) for each requirement. In the foreground, a detailed table breaks down individual security controls, with cells color coded in green, yellow, and red to indicate the level of compliance or coverage across Security Levels SL1 through SL4. A gauge chart at the bottom visualizes the overall achieved Security Level, with the needle pointing toward the lower end of the scale. The layout resembles a professional cybersecurity assessment report summarizing compliance and maturity against IEC 62443-4-2 component requirements.
021
Compass Security @compass-security.com · 16/06/2026
Attending Area41 Security Conference in Dübendorf/Zurich (CH)? 🎯 Swing by our booth and check out RAPTR: our open-source collab platform for Purple Team ops. Plan, attack, detect, report. All in one place. See you there on Thursday/Friday! @defcon.bsky.social #Area41 #PurpleTeam
041
Compass Security @compass-security.com · 11/06/2026
At Area41 Security Conference (CH) next week? Come to our booth to see EntraFalcon in action: our open-source tool for assessing Microsoft Entra ID security posture. Privileged objects, risky assignments, conditional access misconfigs: find what's hiding in your tenant. @defconch.bsky.social
042
Compass Security @compass-security.com · 09/06/2026
AI agents in your Entra ID tenant? They come with new identities, permissions, fresh attack paths. Chrigi @zh54321.bsky.social breaks down Entra Agent ID security, capabilities, control paths, abuse scenarios, and how to review exposure with EntraFalcon. blog.compass-security.com/2026/06/entr...
021
Compass Security @compass-security.com · 04/06/2026
The monkey is still curious 🐒 Teleboy has topped up its #bugbounty program with another CHF 10'000 in rewards. Explore a platform serving 400'000+ users across TV, internet, and telephony. Ready for another hunt? bugbounty.compass-security.com/bug-bounties... #ethicalhacking #cybersecurity
020
Compass Security @compass-security.com · 27/05/2026
SSH everywhere, misconfigurations somewhere. Our new SSH Labs let you get your hands dirty: slides, video, and a Docker-based lab. Created by our Security Analyst @emanuelduss.ch, learn how SSH breaks and how to fix it: blog.compass-security.com/2026/05/ssh-... #SSH #InfoSec #Security
072
Compass Security @compass-security.com · 20/05/2026
Excited to be on board as a Platinum Sponsor. Looking forward to connecting with the community on-site!
032
Reposted by Compass Security
TrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026
Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 & 2 Master of Pwn points. #Pwn2Own
085
Reposted by Compass Security
TrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026
Very nicely done! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit Anthropic Claude Code! They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin
183
Compass Security @compass-security.com · 15/05/2026
4th place after two days of #pwn2own in Berlin. Fingers crossed for the 3rd day and our colleagues attempt on Claude Code.
072
Reposted by Compass Security
TrendAI Zero Day Initiative @thezdi.bsky.social · 14/05/2026
Big W!! 💪 Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit OpenAI Codex! Off to the disclosure room to spill the tea. #Pwn2Own #P2OBerlin
042
Compass Security @compass-security.com · 13/05/2026
Compass vulnerability research identified code execution paths affecting AI coding assistants including Claude Code, OpenAI Codex and Cursor. The findings will be demonstrated live at @thezdi.bsky.social Initiative #Pwn2Own Berlin 2026, May 14 to 16. #AIsecurity #LLM
042
Compass Security @compass-security.com · 11/05/2026
🦖 Meet RAPTR: our new open source platform for red and purple team collaboration. Plan engagements, document attacks and detections, evaluate results, and generate reports, all API-driven. Beta is live, feedback welcome! #PurpleTeam blog.compass-security.com/2026/05/intr...
011
Compass Security @compass-security.com · 28/04/2026
Tabletop exercises show how incident response processes fall apart under pressure, far beyond what any plan suggests. In our blog post, we share key lessons from real TTX sessions: failures in communication, decision-making, structure, and human factors. blog.compass-security.com/2026/04/tabl...
0141
Compass Security @compass-security.com · 14/04/2026
The final part of our Entra ID blog series looks at common Conditional Access weaknesses, practical attack scenarios, and how to identify such issues with EntraFalcon. blog.compass-security.com/2026/04/comm...
020
Compass Security @compass-security.com · 07/04/2026
Part 3 of our Entra ID blog series looks at common weak PIM configurations, practical abuse scenarios, and how to identify them with EntraFalcon: blog.compass-security.com/2026/04/comm...
021
Compass Security @compass-security.com · 01/04/2026
🏃‍♂️ Time for a security workout. Sanitas is launching its #bugbounty program and inviting ethical hackers to help keep its digital healthcare services in peak condition. Hunt vulnerabilities and help protect critical healthcare systems: bugbounty.compass-security.com/bug-bounties...
010
Compass Security @compass-security.com · 31/03/2026
Unprotected groups in Entra ID can lead to privilege escalation. Part 2 of our 4-part series shows how weakly protected groups can be abused to bypass controls, gain privileged access, and lead to full compromise - and how to detect this with EntraFalcon: blog.compass-security.com/2026/03/comm...
010
Reposted by Compass Security
Defcon Switzerland @defconch.bsky.social · 20/03/2026
✨ We’re excited to welcome Compass Security as a Platinum Sponsor for the AREA41 security conference 2026 🛸 👽 Thank you for supporting the infosec community, we look forward to seeing you‼️ ➡️ Check them out at: compass-security.com @compass-security.com 📅 June 18-19. 2026, Zürich - area41.io
0104
Compass Security @compass-security.com · 24/03/2026
Foreign enterprise apps can expose your Entra ID tenant. Today, we release part 1 of our 4-part weekly series on common Entra ID pitfalls and how to detect them with EntraFalcon. Learn how external apps can lead to data access or worse: blog.compass-security.com/2026/03/comm...
032
Compass Security @compass-security.com · 17/03/2026
EntraFalcon update 🚀 The new Security Findings Report turns Entra ID enumeration into actionable findings with 60+ checks and colorful charts. Read Chrigi's @zh54321.bsky.social blog and try the tool now on your tenant! blog.compass-security.com/2026/03/from... #EntraID #CloudSecurity #EntraFalcon
044
Compass Security @compass-security.com · 03/03/2026
WinGet can be more than a package manager. We show how .𝚠𝚒𝚗𝚐𝚎𝚝 configs + a self-referencing LNK become a viable initial access payload when Microsoft Store is enabled. Includes detection queries & mitigation tips. blog.compass-security.com/2026/03/wing... #RedTeam #Windows #LOLBins #InitialAccess
043
Compass Security @compass-security.com · 10/02/2026
John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to a working PoC. blog.compass-security.com/2026/02/from... #Windows #CVE #SecurityResearch #PrivEsc
053
Compass Security @compass-security.com · 21/01/2026
A night full of exciting happenings. Compass #Pwn2Own team chained zero days to run code on the Canada built Grizzl-e Smart level 2 charger. Colleagues also demoed the manipulation of of the charging control protocol. Well earned 25‘000 USD!
274
Compass Security @compass-security.com · 21/01/2026
We have exciting news to share. Compass folks made the Alpine car infotainment system to run arbitrary code and earn a 10‘000 USD. 🎉🎉🎉
284
Reposted by Compass Security
TrendAI Zero Day Initiative @thezdi.bsky.social · 21/01/2026
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) exploited one exposed dangerous method/function bug on the Alpine iLX-F511, winning Round 2 for $10,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto
034
Compass Security @compass-security.com · 20/01/2026
How do we keep our security analysts up to date? Our latest blog post looks inside our internal training week, from Kubernetes security to red teaming and our annual Security Boot Camp. blog.compass-security.com/2026/01/cont... #CyberSecurity #Learning #Pentesting #Kubernetes
030
Compass Security @compass-security.com · 20/01/2026
The schedule is out! 🗓️ We’re hitting the stage on January 21st at 12:30 JST (4:30 CET) and at 14:00 JST (6:00 CET). Time to see if all the work in the lab pays off. Wish us luck! #Pwn2Own www.zerodayinitiative.com/blog/2026/1/...
zerodayinitiative.com
Zero Day Initiative — Pwn2Own Automotive 2026 - The Full Schedule
おかえりなさい (Welcome back!) The third annual Pwn2Own Automotive competition has returned to Automotive World in Tokyo, and the excitement is building. This year marks a major milestone for Pwn2Own, with...
021
Compass Security @compass-security.com · 19/01/2026
Here we are again! Finally on the ground for #Pwn2Own Automotive in Tokyo 🏎️💻 Our team is ready, and we’re just waiting for the Tuesday draw to see when we’re up. Big week ahead! Stay tuned! 🛠️🔥
040
Reposted by Compass Security
cy//ective @cyllective.bsky.social · 17/01/2026
The final stage would not have been possible without John Ostrowski from @compass-security.com thanks for the Swiss infosec collaboration! 🫕🤝
131
Compass Security @compass-security.com · 18/12/2025
Thank you #BugHunters for your relentless curiosity and clean reports that keep our customers #BugBountyProgram sharp. Soon to announce: Switzerland's highest max. bounty ever, new programs and budget refills. Stay tuned! For now: shutdown, enjoy the festive season and recharge.
020
Compass Security @compass-security.com · 16/12/2025
In a new video, Nicolò @rationalpsyche.bsky.social walks through how to fuzz with AFL++, how to pick targets, avoid common pitfalls, and boost effectiveness. Find performance tips, fuzzing theory, and AFL++ internals. Watch here: youtu.be/L5Tin7m5sbE?... #security #fuzzing #AFLplusplus #appsec
youtu.be
Fuzzing and AFL++
YouTube video by Compass Security
032
Reposted by Compass Security
Compass Security @compass-security.com · 02/12/2025
New video out! Security analyst John Ostrowski show the hands-on process behind discovering CVE-2025-24076 and CVE-2025-24994 described in our recent blog post. Watch here: youtu.be/YwNcTuHxnAI #security #pentest #windowsinternals #vulnresearch
youtu.be
300 Milliseconds to Admin: Mastering DLL Hijacking and Hooking to Win the Race
YouTube video by Compass Security
042
Compass Security @compass-security.com · 02/12/2025
New video out! Security analyst John Ostrowski show the hands-on process behind discovering CVE-2025-24076 and CVE-2025-24994 described in our recent blog post. Watch here: youtu.be/YwNcTuHxnAI #security #pentest #windowsinternals #vulnresearch
youtu.be
300 Milliseconds to Admin: Mastering DLL Hijacking and Hooking to Win the Race
YouTube video by Compass Security
042
Compass Security @compass-security.com · 26/11/2025
NTLM relay works against HTTPS if channel binding is missing. Our new blog post explains why, shows how tooling evolved, and highlights defensive measures. blog.compass-security.com/2025/11/ntlm...
033
Compass Security @compass-security.com · 04/11/2025
Want to understand how Windows handles authentication and access tokens? Security analyst @emanuelduss.ch explains how they’re created, used, and abused - with live demos. 🎥Presentation: youtu.be/_ODdwpxXRR4?... #Security #Pentest #WindowsInternals
youtu.be
Windows Access Tokens - From Authentication to Exploitation
YouTube video by Compass Security
131
Compass Security @compass-security.com · 22/10/2025
🎉Success. Our #Pwn2own team combined #zeroday bugs to #exploit @home-assistant.io green which earned them $20'000 and 4 pts. Congratz to @bcyrill.bsky.social Emanuele, Lukasz @muukong.bsky.social and @yvesbieri.bsky.social. Respect to @stephenfewer.bsky.social and the Summoning Team for the wins.
050
Compass Security @compass-security.com · 21/10/2025
So proud. Congratz. This is pwntastic!
181
Reposted by Compass Security
TrendAI Zero Day Initiative @thezdi.bsky.social · 21/10/2025
🧭 Navigation complete! The team from Compass Security just charted a course straight into @home_assistant Green at #Pwn2Own. They head off to the disclosure room to spill how they did it. #P2OIreland
053
Compass Security @compass-security.com · 21/10/2025
#Pentest of gRPC-Web apps is tricky due to the binary format. We are releasing bRPC-Web, a @portswigger.net @burpsuite.bsky.social extension developed by our @muukong.bsky.social that helps manipulate #gRPC-Web traffic, even in absence of #protobuf schemas. blog.compass-security.com/2025/10/brpc...
073
Compass Security @compass-security.com · 21/10/2025
@thezdi.bsky.social #Pwn2own schedule is out. Compass folks have been drawn 3rd to exploit the @home-assistant.io Green for $40,000. 🤞for a #bounty today Tuesday Oct 21st, 5pm (Swiss time). #ethicalhacking Schedule www.zerodayinitiative.com/blog/2025/20...
zerodayinitiative.com
Zero Day Initiative — Pwn2Own Ireland 2025: The Full Schedule
Welcome to Pwn2Own Ireland 2025! We have some amazing spooky entries for this year’s contest, and a potential of up to $2,000,000 - including our largest ever single prize for a 0-click in WhatsApp fo...
021
Compass Security @compass-security.com · 20/10/2025
Heading to Cork for #Pwn2Own Ireland 🇮🇪. Watch the live draw at 15:00 (Swiss time) to see which target we’ll be taking on 👀🔗 www.linkedin.com/events/pwn2o...
031
Compass Security @compass-security.com · 15/10/2025
Learn about a FortiProxy Domain Fronting Protection bypass discovered by our analyst @emanuelduss.ch. Details in the advisory: www.compass-security.com/en/news/deta... Curious how web filters are evaded? Read his blog series: blog.compass-security.com/2025/03/bypa... #cve #pentest #bypass
compass-security.com
Vulnerability in FortiProxy
Security analyst Emanuel Duss identified a vulnerability in FortiProxy.
021
Compass Security @compass-security.com · 07/10/2025
The leaked LockBit chats give a rare inside look at ransomware ops. Read our blog for an analysis and lessons for defenders: blog.compass-security.com/2025/10/lock... #CyberSecurity #Ransomware #LockBit
020