Mänu @emanuelduss.ch · 30/08/2026Nice, there is a new SSH client option -Z in OpenSSH 10.5 that prints the keys that will be tried for public key authentication in the order that they will be used. Manpage: man.openbsd.org/ssh.1#Z So you can see which public keys are disclosed to the remote system. #ssh #openssh 030
Reposted by MänuCompass Security @compass-security.com · 25/08/2026Pentesting passkeys? Security analyst @emanuelduss.ch shows two JS snippets for tampering with the WebAuthn APIs. Handy for checking if you can login using a security key without knowing the PIN. Check out the technical details and how he got there: blog.compass-security.com/2026/08/a-no... 021
Reposted by MänuCompass Security @compass-security.com · 04/08/2026Pipeleek 1.0 is out 💧 Secret scanning across 7 CI/CD platforms, plus runner and Renovate bot exploitation. Want to see one leaked job log turn into repo takeover? Try our deliberately vulnerable GitLab Attack Lab. Happy leeking! blog.compass-security.com/2026/08/pipe... #DevSecOps #CICD 111
Reposted by MänuSynacktiv @synacktiv.com · 02/07/2026#RBCD attacks in Impacket have been extended across an arbitrary number of domains! 🚀 Discover how to impersonate arbitrary identities through complex #ActiveDirectory forest trusts, including SPN-less exploitation. 📚 www.synacktiv.com/en/publicati... 🔨 github.com/synacktiv/im...synacktiv.comExploring cross-domain & cross-forest RBCD: part 2Exploring cross-domain & cross-forest RBCD: part 2 152
Reposted by MänuAdrienne Fichter @adfichter.eurosky.social · 02/06/2026Frisch von der Presse: Du protestiert gegen neue Rechenzentren für Big Tech oder bist für Palästina? Dann solltest du die nächsten Abschnitte lesen. Es könnte ein Revival des Fichenstaats geben. Wo genau solche Aktivitäten in Datenbanken des Geheimdiensts landen www.republik.ch/2026/06/02/c...republik.chDer Nachrichtendienst profitiert vom ZeitgeistWie die Schweiz sich vom liberalen Rechtsstaat verabschiedet. 13126
Mänu @emanuelduss.ch · 27/05/2026On sshlabs.compass-security.training you can find a presentation and a Docker-based hands-on lab in which you can learn how SSH works, how it can be attacked and how to protect it. #security #infosec #network #ssh #openssh #pentestsshlabs.compass-security.trainingSSH Labs - SSH LabsLabs to learn about SSH security. 072
Reposted by MänuCompass Security @compass-security.com · 27/05/2026SSH everywhere, misconfigurations somewhere. Our new SSH Labs let you get your hands dirty: slides, video, and a Docker-based lab. Created by our Security Analyst @emanuelduss.ch, learn how SSH breaks and how to fix it: blog.compass-security.com/2026/05/ssh-... #SSH #InfoSec #Security 072
Reposted by MänuTrendAI Zero Day Initiative @thezdi.bsky.social · 16/05/2026Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 & 2 Master of Pwn points. #Pwn2Own 085
Mänu @emanuelduss.ch · 16/05/2026Fast Android File Access via SSHFS over Wi-Fi or USB (MTP Alternative): emanuelduss.ch/posts/fast-a... #android #mtp #sshfsemanuelduss.chFast Android File Access via SSHFS over Wi-Fi or USB (MTP Alternative)Introduction The MPT protocol used to access files via USB on your phone is not that efficient. This post shows you an alternative to MTP for accessing your files on your mobile phone. It works by ins... 010
Mänu @emanuelduss.ch · 23/04/2026Simple shell function that calls the ip.thc.org service to get subdomains or CNAMEs pointing to a subdomain, or IP addresses pointing to a subdomain: gist.github.com/emanuelduss/... For quick and dirty subdomain enumeration 😀 THX @hackerschoice.bsky.social for this nice service 🤘 #pentest #dns 010
Reposted by MänuCompass Security @compass-security.com · 03/03/2026WinGet can be more than a package manager. We show how .𝚠𝚒𝚗𝚐𝚎𝚝 configs + a self-referencing LNK become a viable initial access payload when Microsoft Store is enabled. Includes detection queries & mitigation tips. blog.compass-security.com/2026/03/wing... #RedTeam #Windows #LOLBins #InitialAccess 043
Reposted by MänuCompass Security @compass-security.com · 10/02/2026John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to a working PoC. blog.compass-security.com/2026/02/from... #Windows #CVE #SecurityResearch #PrivEsc 053
Mänu @emanuelduss.ch · 31/01/2026This was a really cool and awesome course ❤️! I learned so much in these two days and did a lot of stuff I never did and never heard about before. It was cool when (after some nasty debugging 🫠) the encryption key could finally be sniffed 🤘. Thanks a lot for your training, you guys rock! 062
Reposted by Mänucy//ective @cyllective.bsky.social · 17/01/2026🚨 New blog post! Read about CVE-2025-13154, a privilege-escalation vulnerability in a Lenovo Vantage add-in called SmartPerformance. cyllective.com/blog/posts/l... #windows #cve #infosec #pentestcyllective.comLenovo Vantage LPE/EoP (CVE-2025-13154)A write-up of CVE-2025-13154, a privilege escalation vulnerability in Lenovo Vantage. 111
Mänu @emanuelduss.ch · 09/01/2026This is probably the easiest way to perform reverse DNS lookups over IP address ranges using the built-in tool getent and bash brace expansion: getent hosts 130.59.{20,31}.{0..255} Useful if you are on a system/container with limited tools. #pentest #dns #linux 040
Reposted by MänuThe Hacker's Choice (1995) @hackerschoice.bsky.social · 17/12/2025THC Release 💥: The world’s largest IP<>Domain database: ip.thc.org All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free. Updated monthly. Try: curl ip.thc.org/1.1.1.1 Raw data (187GB): ip.thc.org/docs/bulk-da... (The fine work of messede 👌) 14620
Reposted by Mänu💥 leonjza @leonjza.bsky.social · 07/12/2025Two blog posts just dropped - one with the details on the bloatware pwning shenanigans I was up to earlier in the year, and another on pipetap, a new Windows named pipe proxy/tool. sensepost.com/blog/2025/pw... sensepost.com/blog/2025/pi... 032
Reposted by MänuCompass Security @compass-security.com · 02/12/2025New video out! Security analyst John Ostrowski show the hands-on process behind discovering CVE-2025-24076 and CVE-2025-24994 described in our recent blog post. Watch here: youtu.be/YwNcTuHxnAI #security #pentest #windowsinternals #vulnresearchyoutu.be300 Milliseconds to Admin: Mastering DLL Hijacking and Hooking to Win the RaceYouTube video by Compass Security 042
Reposted by MänuSpecterOps @specterops.io · 25/11/2025NTLM relays failing because of EPA? 😒 Nick Powers & @tw1sm.bsky.social break down how to enumerate EPA settings across more protocols + drop new tooling (RelayInformer) to make relays predictable. Check out their blog for more: ghst.ly/4rqwpRsghst.lyLess Praying More Relaying - Enumerating EPA Enforcement for MSSQL and HTTPS - SpecterOpsIt's important to know if your NTLM relay will be prevented by integrity protections such as EPA, before setting up for and attempting the attack. In this post, we share how to solve this problem for ... 042
Mänu @emanuelduss.ch · 06/11/2025The slides can be downloaded here: www.compass-security.com/fileadmin/Re...compass-security.com 010
Reposted by MänuCompass Security @compass-security.com · 04/11/2025Want to understand how Windows handles authentication and access tokens? Security analyst @emanuelduss.ch explains how they’re created, used, and abused - with live demos. 🎥Presentation: youtu.be/_ODdwpxXRR4?... #Security #Pentest #WindowsInternalsyoutu.beWindows Access Tokens - From Authentication to ExploitationYouTube video by Compass Security 131
Mänu @emanuelduss.ch · 27/10/2025802.11evil now shows a Wi-Fi QR code, sends router advertisements for IPv6 support, can set static routes via DHCP and disable Wi-Fi to only act as a router. See changelog: emanuelduss.ch/posts/create... #pentest #network #tls #mitmemanuelduss.chCreate Evil Wi-Fi Access Point (802.11evil)Introduction In pentests, connecting devices to your own network can be very useful. This enables you to exfiltrate data, download tools, analyze the network traffic and even use a transparent HTTP pr... 010
Reposted by MänuSpecterOps @specterops.io · 23/10/2025Credential Guard was supposed to end credential dumping. It didn't. Valdemar Carøe just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more: ghst.ly/4qtl2rmghst.lyCatching Credential Guard Off Guard - SpecterOpsUncovering the protection mechanisms provided by modern Windows security features and identifying new methods for credential dumping. 01710
Reposted by MänuTrendAI Zero Day Initiative @thezdi.bsky.social · 21/10/2025📢 Confirmed! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security combined an arbitrary file write & cleartext transmission of sensitive data to exploit the @home_assistant Green. Their third round win earns them $20,000 and 4 Master of Pwn points. #Pwn2Own 052
Reposted by MänuCompass Security @compass-security.com · 21/10/2025#Pentest of gRPC-Web apps is tricky due to the binary format. We are releasing bRPC-Web, a @portswigger.net @burpsuite.bsky.social extension developed by our @muukong.bsky.social that helps manipulate #gRPC-Web traffic, even in absence of #protobuf schemas. blog.compass-security.com/2025/10/brpc... 073
Reposted by MänuCompass Security @compass-security.com · 15/10/2025Learn about a FortiProxy Domain Fronting Protection bypass discovered by our analyst @emanuelduss.ch. Details in the advisory: www.compass-security.com/en/news/deta... Curious how web filters are evaded? Read his blog series: blog.compass-security.com/2025/03/bypa... #cve #pentest #bypasscompass-security.comVulnerability in FortiProxySecurity analyst Emanuel Duss identified a vulnerability in FortiProxy. 021
Reposted by MänuCatalin Cimpanu @campuscodi.risky.biz · 11/10/2025Talks from the Balkan Computer Congress 2025 security conference, which took place last September, are available on YouTube www.youtube.com/playlist?lis...youtube.comBalCCon2k25 - YouTubeBalCCon2k25 - Against the current 062
Reposted by Mänud4d @zakfedotkin.bsky.social · 07/10/2025I’m excited to announce that I’ll be presenting The Fragile Lock: Novel Bypasses for SAML Authentication at Black Hat Europe! In this talk, I’ll show how I was able to continuously bypass security patches to achieve complete auth bypass for major libraries. #BHEU @blackhatevents.bsky.social 0266
Reposted by MänuCompass Security @compass-security.com · 18/09/2025The final episode of our Kerberos deep dive is live! RBCD opens new attack paths in Kerberos. Learn how misconfigs enable privilege escalation and how to defend. youtu.be/l97RDnzdrXY?... #Kerberos #ActiveDirectoryyoutu.beKerberos Deep Dive Part 6 - Resource-Based Constrained DelegationYouTube video by Compass Security 043
Reposted by MänuDirk-jan @dirkjanm.io · 17/09/2025I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-gl...dirkjanm.ioOne Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokensWhile preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise ... 98738
Reposted by MänuCompass Security @compass-security.com · 16/09/2025Episode 5 of our Kerberos deep dive is live. Constrained delegation isn’t bulletproof. See how attackers exploit it, and how to defend with monitoring & best practices. youtu.be/rnhr02eKU0I?... #Kerberos #ActiveDirectoryyoutu.beKerberos Deep Dive Part 5 - Constrained DelegationYouTube video by Compass Security 032
Reposted by Mänu💥 leonjza @leonjza.bsky.social · 10/09/2025I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :) 297
Reposted by MänuCompass Security @compass-security.com · 09/09/2025Episode 3 of our Kerberos deep dive is live. AS-REP Roasting abuses accounts without pre-auth. Learn the risks, how attackers exploit it, and how to defend. youtu.be/56BjmyOTN5o?... #Kerberos #ActiveDirectoryyoutu.beKerberos Deep Dive Part 3 - AS-REP RoastingYouTube video by Compass Security 033
Reposted by MänuCompass Security @compass-security.com · 09/09/2025We use @jameskettle.com Burp extension Collaborator Everywhere daily. Now our upgrades are in v2: customizable payloads, storage, visibility. Perfect for OOB bugs like SSRF. Find out more here: blog.compass-security.com/2025/09/coll... #AppSec #BurpSuite #Pentesting 086
Reposted by MänuCompass Security @compass-security.com · 04/09/2025Episode 2 of our Kerberos deep dive is live. Kerberoasting lets attackers steal AD service account credentials. See how it works and how to protect your systems: youtu.be/PhNspeJ0r-4?... #Kerberos #ActiveDirectoryyoutu.beKerberos Deep Dive Part 2 - KerberoastingYouTube video by Compass Security 054
Mänu @emanuelduss.ch · 04/09/2025New blog post about fast and easy file sharing via IPv6 link-local addresses over a network cable and how it can be used to bypass & abuse some always-on corporate VPNs: emanuelduss.ch/posts/fast-a... #ipv6emanuelduss.chFast and Easy File Sharing via IPv6 Link-Local Addresses Over a Network Cable (and Bypass/Abuse Corporate VPNs)Introduction There are a ton of ways to copy data between two systems. You can use a file sharing service on the Internet, transfer files via your self-hosted server or even use USB drives. This blog ... 000
Reposted by MänuCompass Security @compass-security.com · 03/09/2025Kerberos powers auth in Windows and hides big security risks. We’re launching a 6-part deep dive: from protocol basics to attacks plus how to stop them. Starts today → blog.compass-security.com/2025/09/tami... → Subscribe to our channel! #Kerberos #ActiveDirectory 152
Reposted by MänuCompass Security @compass-security.com · 26/08/2025Passwords are dead, long live passkeys! 🔑 In our latest blog, we go hands-on: real-life setups, plus tips for recovery and avoiding pitfalls. blog.compass-security.com/2025/08/into... #Passkeys #CyberSecurity #Authentication 043
Reposted by MänuSpecterOps @specterops.io · 14/08/2025The DSInternals PowerShell module just got an upgrade! 🔥 Updates include: ✅ Golden dMSA Attack ✅ Full LAPS support ✅ Trust password & BitLocker recovery key extraction ✅ Read-only domain controller database compatibility Read more from Michael Grafnetter: ghst.ly/412rZ7Fghst.lyJuicing ntds.dit Files to the Last Drop - SpecterOpsDiscover the latest enhancements to the DSInternals PowerShell module, including the Golden dMSA Attack and support for LAPS, trust passwords, or BitLocker recovery keys. 054
Mänu @emanuelduss.ch · 10/08/2025Zscaler SAML SP Authentication Bypass via Certificate Cloning & Signature Spoofing (CVE-2025-54982) by @amberwolfsec.bsky.social: blog.amberwolf.com/blog/2025/au... #saml #zscalerblog.amberwolf.comAdvisory - Zscaler SAML Authentication Bypass (CVE-2025-54982)AmberWolf Security Research Blog 000
Reposted by MänuCatalin Cimpanu @campuscodi.risky.biz · 02/08/2025China has started filtering and censoring internet traffic taking place over the QUIC protocol. The filtering started in April last year. The Great Firewall now decrypts QUIC packets at scale and uses a separate blocklist for QUIC traffic, separate from its main filters gfw.report/publications... 02917
Reposted by MänuSensePost @sensepost.com · 31/07/2025Reverse engineering Microsoft’s SQLCMD.exe to implement Channel Binding support for MSSQL into Impacket’s mssqlclient.py. Storytime from Aurelien (@Defte_ on the bird site), including instructions for reproducing the test environment yourself. sensepost.com/blog/2025/a-... 0106
Reposted by MänuSpecterOps @specterops.io · 29/07/2025BloodHound v8.0 is here! 🎉 This update introduces BloodHound OpenGraph, revolutionizing Identity Attack Path Management by exposing attack paths throughout your entire tech stack, not just AD/Entra ID. Read more from Justin Kohler: ghst.ly/bloodhoundv8 🧵: 1/7 1139
Reposted by MänuJames Kettle @jameskettle.com · 30/07/2025Not at Black Hat / DEF CON? You can still join the mission to kill HTTP/1.1: - Watch the livestream from #DEFCON at 16:30 PT on the 8th - Read the whitepaper on our website - Grab the HTTP Request Smuggler update & WebSecAcademy lab Follow for updates & links. It's nearly time!portswigger.netUpcoming Conference Talks - PortSwigger ResearchFind details of upcoming talks from the PortSwigger Research team. We also have research papers and recordings available from previous conferences and events. 0112
Reposted by MänuSpecterOps @specterops.io · 30/07/2025Entra Connect sync accounts can be exploited to hijack device userCertificate properties, enabling device impersonation and conditional access bypass. @hotnops.bsky.social explores cross-domain compromise tradecraft within the same tenant. Read more: ghst.ly/3ISMGN9ghst.lyEntra Connect Attacker Tradecraft: Part 3 - SpecterOpsHow Entra Connect and Intune can be abused via userCertificate hijacking to bypass conditional access and compromise hybrid domains 196
Reposted by MänuDirk-jan @dirkjanm.io · 30/07/2025It's been almost a year since my last blog... So, here is a new one: Extending AD CS attack surface to the cloud with Intune certificates. Also includes ESC1 over Intune (in some cases). dirkjanm.io/extending-ad... Oh, and a new tool for SCEP: github.com/dirkjanm/sce...dirkjanm.ioExtending AD CS attack surface to the cloud with Intune certificatesActive Directory Certificate Services (AD CS) attack surface is pretty well explored in Active Directory itself, with *checks notes* already 16 “ESC” attacks being publicly described. Hybrid attack pa... 0159
Reposted by MänuJames Kettle @jameskettle.com · 14/07/2025We've just released a massive update to Collaborator Everywhere! This is a complete rewrite by @compass-security.com which adds loads of features including in-tool payload customization. Massive thanks to Compass for this epic project takeover. Check out the new features: 1187
Reposted by Mänumodzero @modzero.bsky.social · 29/06/2025Teammate Leonid discovered a leaked credential that allowed anyone unauthorized access to all Microsoft tenants of orgs that use Synology's "Active Backup for Microsoft 365" (ABM), including sensitive data like Teams channel messages. 🤓 #synology #disclosure #modzero modzero.com/en/blog/when...modzero.comWhen Backups Open Backdoors: Accessing Sensitive Cloud Data via 12214
Reposted by MänuSpecterOps @specterops.io · 17/06/2025Introducing the BloodHound Query Library! 📚 @martinsohn.dk & @joeydreijer.bsky.social explore the new collection of Cypher queries designed to help BloodHound users to unlock the full potential of the BloodHound platform by creating an open query ecosystem. ghst.ly/4jTgRQQghst.lyIntroducing the BloodHound Query Library - SpecterOpsThe BloodHound Query Library is a community-driven collection of BloodHound Cypher available at https://queries.specterops.io 01410
Reposted by MänuRedTeam Pentesting @redteam-pentesting.de · 11/06/2025👀 We have also released a paper which really goes into the nitty-gritty for those who are interested 🕵️♀️: www.redteam-pentesting.de/publications... For those that only need a short overview, here's our advisory 🚨: www.redteam-pentesting.de/advisories/r...redteam-pentesting.de 011