Sign in

cybrz

@cybrz.bsky.social
283 followers 1K following 18 posts

Master of Disaster @compass-security.com 🔥 for all sorts crises, scada, chunk hacking, electronics, cryptography and cyber all the things.

PostsRepliesMedia
Reposted by cybrz
Compass Security @compass-security.com · 10h
Compass Security supports Graubündner Kantonalbank with a structured bug bounty program that enables responsible reporting of potential vulnerabilities within a defined framework. bugbounty.compass-security.com/service-deta... #bugbounty #ethicalhacking #cybersecurity
231
Reposted by cybrz
Compass Security @compass-security.com · 07/07/2026
How do you translate the Cyber Resilience Act into technical testing? Part II of our #CRA series follows a cheap IP camera, from STRIDE threat modelling and firmware analysis to compliance with IEC 62443-4-2. blog.compass-security.com/2026/06/cybe... #CyberSecurity #CyberResilienceAct #IEC62443
031
Reposted by cybrz
Compass Security @compass-security.com · 26/06/2026
How do you prepare a product for the Cyber Resilience Act? Our latest article covers #CRA scope, product classification, threat modelling, technical security testing, and why we use IEC 62443 as an assessment framework. Part I of a two part series: blog.compass-security.com/2026/06/cybe...
Screenshot of an IEC 62443-4-2 security assessment report showing three overlapping report sections. The background page contains an overview table listing security requirements and the achieved Security Level (SL0 to SL4) for each requirement. In the foreground, a detailed table breaks down individual security controls, with cells color coded in green, yellow, and red to indicate the level of compliance or coverage across Security Levels SL1 through SL4. A gauge chart at the bottom visualizes the overall achieved Security Level, with the needle pointing toward the lower end of the scale. The layout resembles a professional cybersecurity assessment report summarizing compliance and maturity against IEC 62443-4-2 component requirements.
021
Reposted by cybrz
Compass Security @compass-security.com · 16/06/2026
Attending Area41 Security Conference in Dübendorf/Zurich (CH)? 🎯 Swing by our booth and check out RAPTR: our open-source collab platform for Purple Team ops. Plan, attack, detect, report. All in one place. See you there on Thursday/Friday! @defcon.bsky.social #Area41 #PurpleTeam
041
Reposted by cybrz
Compass Security @compass-security.com · 11/06/2026
At Area41 Security Conference (CH) next week? Come to our booth to see EntraFalcon in action: our open-source tool for assessing Microsoft Entra ID security posture. Privileged objects, risky assignments, conditional access misconfigs: find what's hiding in your tenant. @defconch.bsky.social
042
Reposted by cybrz
Compass Security @compass-security.com · 17/03/2026
EntraFalcon update 🚀 The new Security Findings Report turns Entra ID enumeration into actionable findings with 60+ checks and colorful charts. Read Chrigi's @zh54321.bsky.social blog and try the tool now on your tenant! blog.compass-security.com/2026/03/from... #EntraID #CloudSecurity #EntraFalcon
044
Reposted by cybrz
Compass Security @compass-security.com · 09/06/2026
AI agents in your Entra ID tenant? They come with new identities, permissions, fresh attack paths. Chrigi @zh54321.bsky.social breaks down Entra Agent ID security, capabilities, control paths, abuse scenarios, and how to review exposure with EntraFalcon. blog.compass-security.com/2026/06/entr...
021
Reposted by cybrz
Compass Security @compass-security.com · 20/05/2026
Excited to be on board as a Platinum Sponsor. Looking forward to connecting with the community on-site!
032
Reposted by cybrz
TrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026
Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 & 2 Master of Pwn points. #Pwn2Own
085
Reposted by cybrz
TrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026
Very nicely done! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit Anthropic Claude Code! They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin
183
Reposted by cybrz
Compass Security @compass-security.com · 15/05/2026
4th place after two days of #pwn2own in Berlin. Fingers crossed for the 3rd day and our colleagues attempt on Claude Code.
072
Reposted by cybrz
Compass Security @compass-security.com · 13/05/2026
Compass vulnerability research identified code execution paths affecting AI coding assistants including Claude Code, OpenAI Codex and Cursor. The findings will be demonstrated live at @thezdi.bsky.social Initiative #Pwn2Own Berlin 2026, May 14 to 16. #AIsecurity #LLM
042
cybrz @cybrz.bsky.social · 01/04/2026
Fellow #bughunters, there is fresh #bugbounty scope
000
Reposted by cybrz
Compass Security @compass-security.com · 03/03/2026
WinGet can be more than a package manager. We show how .𝚠𝚒𝚗𝚐𝚎𝚝 configs + a self-referencing LNK become a viable initial access payload when Microsoft Store is enabled. Includes detection queries & mitigation tips. blog.compass-security.com/2026/03/wing... #RedTeam #Windows #LOLBins #InitialAccess
043
Reposted by cybrz
Compass Security @compass-security.com · 10/02/2026
John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to a working PoC. blog.compass-security.com/2026/02/from... #Windows #CVE #SecurityResearch #PrivEsc
053
Reposted by cybrz
Compass Security @compass-security.com · 20/01/2026
The schedule is out! 🗓️ We’re hitting the stage on January 21st at 12:30 JST (4:30 CET) and at 14:00 JST (6:00 CET). Time to see if all the work in the lab pays off. Wish us luck! #Pwn2Own www.zerodayinitiative.com/blog/2026/1/...
zerodayinitiative.com
Zero Day Initiative — Pwn2Own Automotive 2026 - The Full Schedule
おかえりなさい (Welcome back!) The third annual Pwn2Own Automotive competition has returned to Automotive World in Tokyo, and the excitement is building. This year marks a major milestone for Pwn2Own, with...
021
cybrz @cybrz.bsky.social · 19/01/2026
🤞 fingers crossed you guys get drawn for the pole position and get away without collisions. 🇨🇭#BringEnHei
010
cybrz @cybrz.bsky.social · 18/12/2025
There will be… Switzerland's highest max. bounty EVER
000
Reposted by cybrz
Compass Security @compass-security.com · 16/12/2025
In a new video, Nicolò @rationalpsyche.bsky.social walks through how to fuzz with AFL++, how to pick targets, avoid common pitfalls, and boost effectiveness. Find performance tips, fuzzing theory, and AFL++ internals. Watch here: youtu.be/L5Tin7m5sbE?... #security #fuzzing #AFLplusplus #appsec
youtu.be
Fuzzing and AFL++
YouTube video by Compass Security
032
Reposted by cybrz
Compass Security @compass-security.com · 26/11/2025
NTLM relay works against HTTPS if channel binding is missing. Our new blog post explains why, shows how tooling evolved, and highlights defensive measures. blog.compass-security.com/2025/11/ntlm...
033
Reposted by cybrz
TrendAI Zero Day Initiative @thezdi.bsky.social · 21/10/2025
🧭 Navigation complete! The team from Compass Security just charted a course straight into @home_assistant Green at #Pwn2Own. They head off to the disclosure room to spill how they did it. #P2OIreland
053
Reposted by cybrz
Compass Security @compass-security.com · 21/10/2025
#Pentest of gRPC-Web apps is tricky due to the binary format. We are releasing bRPC-Web, a @portswigger.net @burpsuite.bsky.social extension developed by our @muukong.bsky.social that helps manipulate #gRPC-Web traffic, even in absence of #protobuf schemas. blog.compass-security.com/2025/10/brpc...
073
Reposted by cybrz
Compass Security @compass-security.com · 21/10/2025
@thezdi.bsky.social #Pwn2own schedule is out. Compass folks have been drawn 3rd to exploit the @home-assistant.io Green for $40,000. 🤞for a #bounty today Tuesday Oct 21st, 5pm (Swiss time). #ethicalhacking Schedule www.zerodayinitiative.com/blog/2025/20...
zerodayinitiative.com
Zero Day Initiative — Pwn2Own Ireland 2025: The Full Schedule
Welcome to Pwn2Own Ireland 2025! We have some amazing spooky entries for this year’s contest, and a potential of up to $2,000,000 - including our largest ever single prize for a 0-click in WhatsApp fo...
021
Reposted by cybrz
Compass Security @compass-security.com · 18/09/2025
The final episode of our Kerberos deep dive is live! RBCD opens new attack paths in Kerberos. Learn how misconfigs enable privilege escalation and how to defend. youtu.be/l97RDnzdrXY?... #Kerberos #ActiveDirectory
youtu.be
Kerberos Deep Dive Part 6 - Resource-Based Constrained Delegation
YouTube video by Compass Security
043
Reposted by cybrz
Compass Security @compass-security.com · 16/09/2025
Episode 5 of our Kerberos deep dive is live. Constrained delegation isn’t bulletproof. See how attackers exploit it, and how to defend with monitoring & best practices. youtu.be/rnhr02eKU0I?... #Kerberos #ActiveDirectory
youtu.be
Kerberos Deep Dive Part 5 - Constrained Delegation
YouTube video by Compass Security
032
Reposted by cybrz
Compass Security @compass-security.com · 11/09/2025
Episode 4 of our Kerberos deep dive is live. Unconstrained delegation can expose critical credentials. Learn how attackers abuse it. And how to lock down your systems. youtu.be/_6FYZRTJQ-s?... #Kerberos #ActiveDirectory
youtu.be
Kerberos Deep Dive Part 4 - Unconstrained Delegation
YouTube video by Compass Security
031
Reposted by cybrz
Compass Security @compass-security.com · 09/09/2025
Episode 3 of our Kerberos deep dive is live. AS-REP Roasting abuses accounts without pre-auth. Learn the risks, how attackers exploit it, and how to defend. youtu.be/56BjmyOTN5o?... #Kerberos #ActiveDirectory
youtu.be
Kerberos Deep Dive Part 3 - AS-REP Roasting
YouTube video by Compass Security
033
Reposted by cybrz
Compass Security @compass-security.com · 09/09/2025
We use @jameskettle.com Burp extension Collaborator Everywhere daily. Now our upgrades are in v2: customizable payloads, storage, visibility. Perfect for OOB bugs like SSRF. Find out more here: blog.compass-security.com/2025/09/coll... #AppSec #BurpSuite #Pentesting
086
Reposted by cybrz
Compass Security @compass-security.com · 04/09/2025
Episode 2 of our Kerberos deep dive is live. Kerberoasting lets attackers steal AD service account credentials. See how it works and how to protect your systems: youtu.be/PhNspeJ0r-4?... #Kerberos #ActiveDirectory
youtu.be
Kerberos Deep Dive Part 2 - Kerberoasting
YouTube video by Compass Security
054
Reposted by cybrz
Compass Security @compass-security.com · 03/09/2025
Kerberos powers auth in Windows and hides big security risks. We’re launching a 6-part deep dive: from protocol basics to attacks plus how to stop them. Starts today → blog.compass-security.com/2025/09/tami... → Subscribe to our channel! #Kerberos #ActiveDirectory
152
Reposted by cybrz
Compass Security @compass-security.com · 01/09/2025
Calling all bug hunters! schulNetz by Centerboard AG is now in scope! Help protect over 100k users in schools. Are you ready to make the grade and earn bounties? Program: bugbounty.compass-security.com/bug-bounties... #bugbounty #cybersecurity #ethicalhacking
032
Reposted by cybrz
Compass Security @compass-security.com · 26/08/2025
Passwords are dead, long live passkeys! 🔑 In our latest blog, we go hands-on: real-life setups, plus tips for recovery and avoiding pitfalls. blog.compass-security.com/2025/08/into... #Passkeys #CyberSecurity #Authentication
043
cybrz @cybrz.bsky.social · 15/07/2025
Burp collaborator just got a bunch a new features. Credits go to our @compass-security.com Basel team member, Andreas 🙏
051
Reposted by cybrz
Compass Security @compass-security.com · 08/07/2025
LLM-based vuln hunting just leveled up with xvulnhuntr - a fork of vulnhuntr with support for: C#, Java, Go. Read @rationalpsyche.bsky.social's blog post and go grab the project on GitHub. blog.compass-security.com/2025/07/xvul...
032
Reposted by cybrz
Bill Marczak @billmarczak.org · 29/06/2025
Excited to talk today at @reconmtl.bsky.social with @droethlisberger.bsky.social about a 2017 iOS persistence exploit used by NSO's Pegasus (and, interestingly, other threat actors too)! 10:00AM in the Grand Salon cfp.recon.cx/recon-2025/t...
0115
Reposted by cybrz
Compass Security @compass-security.com · 26/06/2025
Exploiting the @ubiquiti.bsky.social AI Bullet camera for #Pwn2Own made us sweat more than once. But persistence paid off. Our detailed blog post is now live: blog.compass-security.com/2025/06/pwn2... #penetrationtest #pentest #iot #embedded #cybersecurity www.compass-security.com/en/services/...
142
Reposted by cybrz
Compass Security @compass-security.com · 25/06/2025
Thrilled for #TROOPERS25 Thursday! Emanuele & @yvesbieri.bsky.social share #Pwn2Own wins on #surveillance cams. Method, #exploit, lessons. Drop in, trade war-stories! Talk: troopers.de/troopers25/t... Compass pentest: www.compass-security.com/en/services/... #cybersecurity #iot #hw #fw #ot
High-resolution photo of Compass Security’s IoT and industrial penetration-testing workspace: on a light wooden workbench a large-lens, black surveillance camera sits half-disassembled beside its white Synology® housing, revealing the internal printed-circuit board, image sensor and ribbon connectors targeted during firmware extraction and vulnerability analysis. A chaotic web of multicolored diagnostic leads, Ethernet patch cables, alligator clips, UART/serial breakout wires and power adapters snakes across the table, illustrating real-world hardware hacking, fault-injection and secure-boot bypass techniques used in red-team assessments of networked CCTV, smart-factory and critical OT devices. The blue pentagonal TROOPERS25 shield logo occupies the upper-right corner, signalling that this lab scene supports Compass Security’s conference presentation on Pwn2Own-grade research into surveillance-camera exploits, remote-code-execution vectors and zero-day discovery. The image underscores expert penetration-testing methodology—threat modeling, reverse engineering, embedded Linux analysis, secure-element probing and API fuzzing.
074
Reposted by cybrz
Compass Security @compass-security.com · 02/06/2025
Primate traits run deep at Teleboy smart, curious, and always evolving. If that sounds like you, challenge the boundaries of their infra and secure streaming, internet, and phone experience of 400'000+ users. #bugbounty #ethicalhacking #cybersecurity bugbounty.compass-security.com/bug-bounties...
011
Reposted by cybrz
Compass Security @compass-security.com · 27/05/2025
Many CI/CD tools promise to keep your dependencies up to date - but if misconfigured, they can expose your organization. From token leaks to MR hijacks, Jan's latest blog post shows how bad configuration can turn a security tool into an attack vector. 🛠️💣 blog.compass-security.com/2025/05/reno...
053
Reposted by cybrz
Compass Security @compass-security.com · 29/04/2025
Tired of sifting through Entra ID manually? EntraFalcon is a PowerShell tool that flags risky objects configs & privileged role assignments with ⚡ Scoring model 📊 HTML reports 🔒 No Graph API consent hassle. Get it now: blog.compass-security.com/2025/04/intr... #EntraID #IAM
065
Reposted by cybrz
Compass Security @compass-security.com · 15/04/2025
3 milliseconds to admin — Our analyst John Ostrowski turned a DLL hijacking into a reliable local privilege escalation on Windows 11. He chained opportunistic locks, and API hooking to win the race to CVE-2025-24076 & CVE-2025-24994. Read his blog post: blog.compass-security.com/2025/04/3-mi...
0194
cybrz @cybrz.bsky.social · 27/03/2025
The seasoned IT crowd among us might remember the search for extraterrestrial intelligence SETI project screensaver and client software… BOINC is the platform beneath it and used for the distributed computing approach. 😎
020
Reposted by cybrz
Compass Security @compass-security.com · 26/03/2025
Dear #bughunter, gear up! dEURO launches its program. Hunt for vulnerabilities, secure the oracle-free #stablecoin, and get rewarded. #API, mobile apps and solidity contract in scope. Max. bounty at CHF 10'000. Ready to mint your victory? 🚀 #DeFi bugbounty.compass-security.com/bug-bounties...
021
Reposted by cybrz
Compass Security @compass-security.com · 20/03/2025
No system is perfect! In part 4 of his blog series, @emanuelduss.ch shows how detection mechanisms of web filters can be bypassed: blog.compass-security.com/2025/03/bypa... #pentest #network
033
Reposted by cybrz
Compass Security @compass-security.com · 11/02/2025
Avoid LDAP monitoring by leveraging local registry data with certipy parse! Check out our latest pull request and read Marc Tanner’s (@brain-dump.org) blog post: blog.compass-security.com/2025/02/stea...
074
Reposted by cybrz
Compass Security @compass-security.com · 21/01/2025
The Compass #Pwn2Own team will be targeting the Alpine iLX-507 In-Vehicle Infotainment at Pwn2Own Automotive #P2OAuto in Tokyo. Turns out it’s a popular target and our colleagues were drawn by @thezdi.bsky.social to attempt an exploit as 8th out of 10 groups targeting the device. Schedule tba
092
Reposted by cybrz
Compass Security @compass-security.com · 15/01/2025
Avoid the pitfalls and make #managed #cybersecurity services a win-win situation with our hitchhiker's guide👍 From detection gaps to communication breakdowns, we've seen it all. Managed services depend on their alignment with an organization's needs. Tips: blog.compass-security.com/2025/01/hitc...
031
Reposted by cybrz
Compass Security @compass-security.com · 13/01/2025
🎙️📺 ch media, home to 70+ brands including radio stations, TV channels, news outlets, and digital platforms, is launching a #bug #bounty program! Earn up to CHF 5’000 for securing Switzerland’s media backbone. Ready to make headlines? #bugbounty program at bugbounty.compass-security.com
012
Reposted by cybrz
Compass Security @compass-security.com · 13/01/2025
We adopted the 5+2 framework (swiss armed forces crisis management) for #cyber incidents! 🚨 ✅ Clear phases: Problem Capture → Decision ✅ Factors: Timeline, Business, IT, Stakeholders, TA Refined and ready to be applied in upcoming cyber #crisis. #incident #response #management #cybersecurity
011
Reposted by cybrz
Compass Security @compass-security.com · 10/01/2025
👏 Huge thanks to @dirkjanm.io for an exceptional Azure & Entra security training! The nitty-gritty, and real-world examples resonated strongly among our class of 25 security analysts. Thank you! #microsoft #azure #entra #cyber #security #training #cybersecurity
092