Sign in

Compass Security

@compass-security.com
471 followers 1K following 96 posts

Penetration Testing, Red Teaming, Incident Response, Managed Detection, Digital Forensics, Security Training, Managed Bug Bounty, Cyber Training Range

PostsRepliesMedia
Compass Security @compass-security.com · 03/09/2026
From 11 September 2026, manufacturers selling digital products in the EU have 24 hours to report actively exploited vulnerabilities. ⏱️ Andreas Brombach explains what is reportable, and how to actually make those deadlines. blog.compass-security.com/2026/09/cra-... #CRA #ProductSecurity
010
Compass Security @compass-security.com · 25/08/2026
Pentesting passkeys? Security analyst @emanuelduss.ch shows two JS snippets for tampering with the WebAuthn APIs. Handy for checking if you can login using a security key without knowing the PIN. Check out the technical details and how he got there: blog.compass-security.com/2026/08/a-no...
021
Compass Security @compass-security.com · 04/08/2026
Pipeleek 1.0 is out 💧 Secret scanning across 7 CI/CD platforms, plus runner and Renovate bot exploitation. Want to see one leaked job log turn into repo takeover? Try our deliberately vulnerable GitLab Attack Lab. Happy leeking! blog.compass-security.com/2026/08/pipe... #DevSecOps #CICD
111
Compass Security @compass-security.com · 21/07/2026
Your team evaluated that automation platform as a productivity tool. Attackers see a jump host with SSH access, stored credentials, and a path around your network segmentation. Read our latest blog post before deploying any automation platform: blog.compass-security.com/2026/07/the-...
010
Compass Security @compass-security.com · 07/07/2026
How do you translate the Cyber Resilience Act into technical testing? Part II of our #CRA series follows a cheap IP camera, from STRIDE threat modelling and firmware analysis to compliance with IEC 62443-4-2. blog.compass-security.com/2026/06/cybe... #CyberSecurity #CyberResilienceAct #IEC62443
031
Compass Security @compass-security.com · 26/06/2026
How do you prepare a product for the Cyber Resilience Act? Our latest article covers #CRA scope, product classification, threat modelling, technical security testing, and why we use IEC 62443 as an assessment framework. Part I of a two part series: blog.compass-security.com/2026/06/cybe...
Screenshot of an IEC 62443-4-2 security assessment report showing three overlapping report sections. The background page contains an overview table listing security requirements and the achieved Security Level (SL0 to SL4) for each requirement. In the foreground, a detailed table breaks down individual security controls, with cells color coded in green, yellow, and red to indicate the level of compliance or coverage across Security Levels SL1 through SL4. A gauge chart at the bottom visualizes the overall achieved Security Level, with the needle pointing toward the lower end of the scale. The layout resembles a professional cybersecurity assessment report summarizing compliance and maturity against IEC 62443-4-2 component requirements.
021
Compass Security @compass-security.com · 16/06/2026
Attending Area41 Security Conference in Dübendorf/Zurich (CH)? 🎯 Swing by our booth and check out RAPTR: our open-source collab platform for Purple Team ops. Plan, attack, detect, report. All in one place. See you there on Thursday/Friday! @defcon.bsky.social #Area41 #PurpleTeam
041
Compass Security @compass-security.com · 11/06/2026
At Area41 Security Conference (CH) next week? Come to our booth to see EntraFalcon in action: our open-source tool for assessing Microsoft Entra ID security posture. Privileged objects, risky assignments, conditional access misconfigs: find what's hiding in your tenant. @defconch.bsky.social
042
Compass Security @compass-security.com · 09/06/2026
AI agents in your Entra ID tenant? They come with new identities, permissions, fresh attack paths. Chrigi @zh54321.bsky.social breaks down Entra Agent ID security, capabilities, control paths, abuse scenarios, and how to review exposure with EntraFalcon. blog.compass-security.com/2026/06/entr...
021
Compass Security @compass-security.com · 04/06/2026
The monkey is still curious 🐒 Teleboy has topped up its #bugbounty program with another CHF 10'000 in rewards. Explore a platform serving 400'000+ users across TV, internet, and telephony. Ready for another hunt? bugbounty.compass-security.com/bug-bounties... #ethicalhacking #cybersecurity
020
Compass Security @compass-security.com · 27/05/2026
SSH everywhere, misconfigurations somewhere. Our new SSH Labs let you get your hands dirty: slides, video, and a Docker-based lab. Created by our Security Analyst @emanuelduss.ch, learn how SSH breaks and how to fix it: blog.compass-security.com/2026/05/ssh-... #SSH #InfoSec #Security
072
Compass Security @compass-security.com · 13/05/2026
Compass vulnerability research identified code execution paths affecting AI coding assistants including Claude Code, OpenAI Codex and Cursor. The findings will be demonstrated live at @thezdi.bsky.social Initiative #Pwn2Own Berlin 2026, May 14 to 16. #AIsecurity #LLM
042
Compass Security @compass-security.com · 11/05/2026
🦖 Meet RAPTR: our new open source platform for red and purple team collaboration. Plan engagements, document attacks and detections, evaluate results, and generate reports, all API-driven. Beta is live, feedback welcome! #PurpleTeam blog.compass-security.com/2026/05/intr...
011
Compass Security @compass-security.com · 28/04/2026
Tabletop exercises show how incident response processes fall apart under pressure, far beyond what any plan suggests. In our blog post, we share key lessons from real TTX sessions: failures in communication, decision-making, structure, and human factors. blog.compass-security.com/2026/04/tabl...
0141
Compass Security @compass-security.com · 14/04/2026
The final part of our Entra ID blog series looks at common Conditional Access weaknesses, practical attack scenarios, and how to identify such issues with EntraFalcon. blog.compass-security.com/2026/04/comm...
020
Compass Security @compass-security.com · 07/04/2026
Part 3 of our Entra ID blog series looks at common weak PIM configurations, practical abuse scenarios, and how to identify them with EntraFalcon: blog.compass-security.com/2026/04/comm...
021
Compass Security @compass-security.com · 01/04/2026
🏃‍♂️ Time for a security workout. Sanitas is launching its #bugbounty program and inviting ethical hackers to help keep its digital healthcare services in peak condition. Hunt vulnerabilities and help protect critical healthcare systems: bugbounty.compass-security.com/bug-bounties...
010
Compass Security @compass-security.com · 31/03/2026
Unprotected groups in Entra ID can lead to privilege escalation. Part 2 of our 4-part series shows how weakly protected groups can be abused to bypass controls, gain privileged access, and lead to full compromise - and how to detect this with EntraFalcon: blog.compass-security.com/2026/03/comm...
010
Compass Security @compass-security.com · 24/03/2026
Foreign enterprise apps can expose your Entra ID tenant. Today, we release part 1 of our 4-part weekly series on common Entra ID pitfalls and how to detect them with EntraFalcon. Learn how external apps can lead to data access or worse: blog.compass-security.com/2026/03/comm...
032
Compass Security @compass-security.com · 17/03/2026
EntraFalcon update 🚀 The new Security Findings Report turns Entra ID enumeration into actionable findings with 60+ checks and colorful charts. Read Chrigi's @zh54321.bsky.social blog and try the tool now on your tenant! blog.compass-security.com/2026/03/from... #EntraID #CloudSecurity #EntraFalcon
044
Compass Security @compass-security.com · 03/03/2026
WinGet can be more than a package manager. We show how .𝚠𝚒𝚗𝚐𝚎𝚝 configs + a self-referencing LNK become a viable initial access payload when Microsoft Store is enabled. Includes detection queries & mitigation tips. blog.compass-security.com/2026/03/wing... #RedTeam #Windows #LOLBins #InitialAccess
043
Compass Security @compass-security.com · 10/02/2026
John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to a working PoC. blog.compass-security.com/2026/02/from... #Windows #CVE #SecurityResearch #PrivEsc
053
Compass Security @compass-security.com · 20/01/2026
How do we keep our security analysts up to date? Our latest blog post looks inside our internal training week, from Kubernetes security to red teaming and our annual Security Boot Camp. blog.compass-security.com/2026/01/cont... #CyberSecurity #Learning #Pentesting #Kubernetes
030
Compass Security @compass-security.com · 19/01/2026
Here we are again! Finally on the ground for #Pwn2Own Automotive in Tokyo 🏎️💻 Our team is ready, and we’re just waiting for the Tuesday draw to see when we’re up. Big week ahead! Stay tuned! 🛠️🔥
040
Compass Security @compass-security.com · 18/12/2025
Thank you #BugHunters for your relentless curiosity and clean reports that keep our customers #BugBountyProgram sharp. Soon to announce: Switzerland's highest max. bounty ever, new programs and budget refills. Stay tuned! For now: shutdown, enjoy the festive season and recharge.
020
Compass Security @compass-security.com · 26/11/2025
NTLM relay works against HTTPS if channel binding is missing. Our new blog post explains why, shows how tooling evolved, and highlights defensive measures. blog.compass-security.com/2025/11/ntlm...
033
Compass Security @compass-security.com · 22/10/2025
🎉Success. Our #Pwn2own team combined #zeroday bugs to #exploit @home-assistant.io green which earned them $20'000 and 4 pts. Congratz to @bcyrill.bsky.social Emanuele, Lukasz @muukong.bsky.social and @yvesbieri.bsky.social. Respect to @stephenfewer.bsky.social and the Summoning Team for the wins.
050
Compass Security @compass-security.com · 21/10/2025
#Pentest of gRPC-Web apps is tricky due to the binary format. We are releasing bRPC-Web, a @portswigger.net @burpsuite.bsky.social extension developed by our @muukong.bsky.social that helps manipulate #gRPC-Web traffic, even in absence of #protobuf schemas. blog.compass-security.com/2025/10/brpc...
073
Compass Security @compass-security.com · 20/10/2025
Heading to Cork for #Pwn2Own Ireland 🇮🇪. Watch the live draw at 15:00 (Swiss time) to see which target we’ll be taking on 👀🔗 www.linkedin.com/events/pwn2o...
031
Compass Security @compass-security.com · 07/10/2025
The leaked LockBit chats give a rare inside look at ransomware ops. Read our blog for an analysis and lessons for defenders: blog.compass-security.com/2025/10/lock... #CyberSecurity #Ransomware #LockBit
020
Compass Security @compass-security.com · 23/09/2025
NIS2 means stricter rules and steep fines. Penetration testing is key to proving compliance & improving security, uncovering flaws before attackers do. Our latest blog explains why you need it now: blog.compass-security.com/2025/09/ensu... #CyberSecurity #NIS2 #Pentesting
020
Compass Security @compass-security.com · 09/09/2025
We use @jameskettle.com Burp extension Collaborator Everywhere daily. Now our upgrades are in v2: customizable payloads, storage, visibility. Perfect for OOB bugs like SSRF. Find out more here: blog.compass-security.com/2025/09/coll... #AppSec #BurpSuite #Pentesting
086
Compass Security @compass-security.com · 03/09/2025
Kerberos powers auth in Windows and hides big security risks. We’re launching a 6-part deep dive: from protocol basics to attacks plus how to stop them. Starts today → blog.compass-security.com/2025/09/tami... → Subscribe to our channel! #Kerberos #ActiveDirectory
152
Compass Security @compass-security.com · 01/09/2025
Calling all bug hunters! schulNetz by Centerboard AG is now in scope! Help protect over 100k users in schools. Are you ready to make the grade and earn bounties? Program: bugbounty.compass-security.com/bug-bounties... #bugbounty #cybersecurity #ethicalhacking
032
Compass Security @compass-security.com · 26/08/2025
Passwords are dead, long live passkeys! 🔑 In our latest blog, we go hands-on: real-life setups, plus tips for recovery and avoiding pitfalls. blog.compass-security.com/2025/08/into... #Passkeys #CyberSecurity #Authentication
043
Compass Security @compass-security.com · 08/07/2025
LLM-based vuln hunting just leveled up with xvulnhuntr - a fork of vulnhuntr with support for: C#, Java, Go. Read @rationalpsyche.bsky.social's blog post and go grab the project on GitHub. blog.compass-security.com/2025/07/xvul...
032
Compass Security @compass-security.com · 26/06/2025
Exploiting the @ubiquiti.bsky.social AI Bullet camera for #Pwn2Own made us sweat more than once. But persistence paid off. Our detailed blog post is now live: blog.compass-security.com/2025/06/pwn2... #penetrationtest #pentest #iot #embedded #cybersecurity www.compass-security.com/en/services/...
142
Compass Security @compass-security.com · 25/06/2025
Azure IAM is meant to protect your infrastructure. But misconfigurations do the opposite. 5 critical IAM & Entra ID risks - and how to mitigate them: blog.compass-security.com/2025/06/the-...
010
Compass Security @compass-security.com · 25/06/2025
Thrilled for #TROOPERS25 Thursday! Emanuele & @yvesbieri.bsky.social share #Pwn2Own wins on #surveillance cams. Method, #exploit, lessons. Drop in, trade war-stories! Talk: troopers.de/troopers25/t... Compass pentest: www.compass-security.com/en/services/... #cybersecurity #iot #hw #fw #ot
High-resolution photo of Compass Security’s IoT and industrial penetration-testing workspace: on a light wooden workbench a large-lens, black surveillance camera sits half-disassembled beside its white Synology® housing, revealing the internal printed-circuit board, image sensor and ribbon connectors targeted during firmware extraction and vulnerability analysis. A chaotic web of multicolored diagnostic leads, Ethernet patch cables, alligator clips, UART/serial breakout wires and power adapters snakes across the table, illustrating real-world hardware hacking, fault-injection and secure-boot bypass techniques used in red-team assessments of networked CCTV, smart-factory and critical OT devices. The blue pentagonal TROOPERS25 shield logo occupies the upper-right corner, signalling that this lab scene supports Compass Security’s conference presentation on Pwn2Own-grade research into surveillance-camera exploits, remote-code-execution vectors and zero-day discovery. The image underscores expert penetration-testing methodology—threat modeling, reverse engineering, embedded Linux analysis, secure-element probing and API fuzzing.
074
Compass Security @compass-security.com · 11/06/2025
LinkedIn: your job history and your attacker’s roadmap. In his latest blog post, Ivano Somaini shows how malicious actors could mine profiles, badges, and more. Learn from our experienced Social Engineer: blog.compass-security.com/2025/06/link...
010
Compass Security @compass-security.com · 02/06/2025
Primate traits run deep at Teleboy smart, curious, and always evolving. If that sounds like you, challenge the boundaries of their infra and secure streaming, internet, and phone experience of 400'000+ users. #bugbounty #ethicalhacking #cybersecurity bugbounty.compass-security.com/bug-bounties...
011
Compass Security @compass-security.com · 27/05/2025
Many CI/CD tools promise to keep your dependencies up to date - but if misconfigured, they can expose your organization. From token leaks to MR hijacks, Jan's latest blog post shows how bad configuration can turn a security tool into an attack vector. 🛠️💣 blog.compass-security.com/2025/05/reno...
053
Compass Security @compass-security.com · 13/05/2025
In his latest blog post, Marc Tanner @brain-dump.org shows how to bypass BitLocker using BitPixie (CVE-2023-21563) and signed Microsoft components only. Check out the blog post for a PoC and a demo. #BitLocker #RedTeam blog.compass-security.com/2025/05/bypa...
095
Compass Security @compass-security.com · 29/04/2025
Tired of sifting through Entra ID manually? EntraFalcon is a PowerShell tool that flags risky objects configs & privileged role assignments with ⚡ Scoring model 📊 HTML reports 🔒 No Graph API consent hassle. Get it now: blog.compass-security.com/2025/04/intr... #EntraID #IAM
065
Compass Security @compass-security.com · 15/04/2025
3 milliseconds to admin — Our analyst John Ostrowski turned a DLL hijacking into a reliable local privilege escalation on Windows 11. He chained opportunistic locks, and API hooking to win the race to CVE-2025-24076 & CVE-2025-24994. Read his blog post: blog.compass-security.com/2025/04/3-mi...
0194
Compass Security @compass-security.com · 02/04/2025
How can I become a Red Team Operator? – Yours sincerely, A recent graduate. We break down what it takes and why there's no shortcut, and why pentesting is the place to start: blog.compass-security.com/2025/04/i-wa... #redteam #infosec #pentest #career
000
Compass Security @compass-security.com · 26/03/2025
Dear #bughunter, gear up! dEURO launches its program. Hunt for vulnerabilities, secure the oracle-free #stablecoin, and get rewarded. #API, mobile apps and solidity contract in scope. Max. bounty at CHF 10'000. Ready to mint your victory? 🚀 #DeFi bugbounty.compass-security.com/bug-bounties...
021
Compass Security @compass-security.com · 20/03/2025
No system is perfect! In part 4 of his blog series, @emanuelduss.ch shows how detection mechanisms of web filters can be bypassed: blog.compass-security.com/2025/03/bypa... #pentest #network
033
Compass Security @compass-security.com · 18/03/2025
Web filters can often be bypassed in various ways. In part 3 of his blog series, @emanuelduss.ch explains how Domain Fronting works, how attackers use it to evade restrictions and how you can detect it. Read the blog post to find out: blog.compass-security.com/2025/03/bypa... #pentest #network
031
Compass Security @compass-security.com · 17/03/2025
IT-Security kann stressig sein – wir sorgen für Entspannung! Besuchen Sie uns auf der #secIT2025 und holen sich eine kleine Auszeit. #CyberSecurity #ITSecurity #secit #StaySafe
000