Pipeleek 1.0 is out 💧 Secret scanning across 7 CI/CD platforms, plus runner and Renovate bot exploitation. Want to see one leaked job log turn into repo takeover? Try our deliberately vulnerable GitLab Attack Lab. Happy leeking! blog.compass-security.com/2026/08/pipe... #DevSecOps #CICD
Compass Security
@compass-security.com
Penetration Testing, Red Teaming, Incident Response, Managed Detection, Digital Forensics, Security Training, Managed Bug Bounty, Cyber Training Range
Your team evaluated that automation platform as a productivity tool. Attackers see a jump host with SSH access, stored credentials, and a path around your network segmentation. Read our latest blog post before deploying any automation platform: blog.compass-security.com/2026/07/the-...
How do you translate the Cyber Resilience Act into technical testing? Part II of our #CRA series follows a cheap IP camera, from STRIDE threat modelling and firmware analysis to compliance with IEC 62443-4-2. blog.compass-security.com/2026/06/cybe... #CyberSecurity #CyberResilienceAct #IEC62443
How do you prepare a product for the Cyber Resilience Act? Our latest article covers #CRA scope, product classification, threat modelling, technical security testing, and why we use IEC 62443 as an assessment framework. Part I of a two part series: blog.compass-security.com/2026/06/cybe...
Attending Area41 Security Conference in Dübendorf/Zurich (CH)? 🎯 Swing by our booth and check out RAPTR: our open-source collab platform for Purple Team ops. Plan, attack, detect, report. All in one place. See you there on Thursday/Friday! @defcon.bsky.social #Area41 #PurpleTeam
At Area41 Security Conference (CH) next week? Come to our booth to see EntraFalcon in action: our open-source tool for assessing Microsoft Entra ID security posture. Privileged objects, risky assignments, conditional access misconfigs: find what's hiding in your tenant. @defconch.bsky.social
AI agents in your Entra ID tenant? They come with new identities, permissions, fresh attack paths. Chrigi @zh54321.bsky.social breaks down Entra Agent ID security, capabilities, control paths, abuse scenarios, and how to review exposure with EntraFalcon. blog.compass-security.com/2026/06/entr...
The monkey is still curious 🐒 Teleboy has topped up its #bugbounty program with another CHF 10'000 in rewards. Explore a platform serving 400'000+ users across TV, internet, and telephony. Ready for another hunt? bugbounty.compass-security.com/bug-bounties... #ethicalhacking #cybersecurity
SSH everywhere, misconfigurations somewhere. Our new SSH Labs let you get your hands dirty: slides, video, and a Docker-based lab. Created by our Security Analyst @emanuelduss.ch, learn how SSH breaks and how to fix it: blog.compass-security.com/2026/05/ssh-... #SSH #InfoSec #Security
Excited to be on board as a Platinum Sponsor. Looking forward to connecting with the community on-site!
✨ We’re excited to welcome Compass Security as a Platinum Sponsor for the AREA41 security conference 2026 🛸 👽 Thank you for supporting the infosec community, we look forward to seeing you‼️ ➡️ Check them out at: compass-security.com @compass-security.com 📅 June 18-19. 2026, Zürich - area41.io
Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 & 2 Master of Pwn points. #Pwn2Own
Very nicely done! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit Anthropic Claude Code! They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin
4th place after two days of #pwn2own in Berlin. Fingers crossed for the 3rd day and our colleagues attempt on Claude Code.
That's a wrap on Day 2 of #Pwn2Own Berlin! Day Two added $385,750 and 15 unique 0-days, bringing event totals to $908,750 for 39 unique vulnerabilities. DEVCORE leads Master of Pwn with 40.5 points — but the fun ain't over yet, we've got one more day to go. See you tomorrow! #P2OBerlin
Big W!! 💪 Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit OpenAI Codex! Off to the disclosure room to spill the tea. #Pwn2Own #P2OBerlin
Compass vulnerability research identified code execution paths affecting AI coding assistants including Claude Code, OpenAI Codex and Cursor. The findings will be demonstrated live at @thezdi.bsky.social Initiative #Pwn2Own Berlin 2026, May 14 to 16. #AIsecurity #LLM
🦖 Meet RAPTR: our new open source platform for red and purple team collaboration. Plan engagements, document attacks and detections, evaluate results, and generate reports, all API-driven. Beta is live, feedback welcome! #PurpleTeam blog.compass-security.com/2026/05/intr...
Tabletop exercises show how incident response processes fall apart under pressure, far beyond what any plan suggests. In our blog post, we share key lessons from real TTX sessions: failures in communication, decision-making, structure, and human factors. blog.compass-security.com/2026/04/tabl...
The final part of our Entra ID blog series looks at common Conditional Access weaknesses, practical attack scenarios, and how to identify such issues with EntraFalcon. blog.compass-security.com/2026/04/comm...
Part 3 of our Entra ID blog series looks at common weak PIM configurations, practical abuse scenarios, and how to identify them with EntraFalcon: blog.compass-security.com/2026/04/comm...
🏃♂️ Time for a security workout. Sanitas is launching its #bugbounty program and inviting ethical hackers to help keep its digital healthcare services in peak condition. Hunt vulnerabilities and help protect critical healthcare systems: bugbounty.compass-security.com/bug-bounties...
Unprotected groups in Entra ID can lead to privilege escalation. Part 2 of our 4-part series shows how weakly protected groups can be abused to bypass controls, gain privileged access, and lead to full compromise - and how to detect this with EntraFalcon: blog.compass-security.com/2026/03/comm...
✨ We’re excited to welcome Compass Security as a Platinum Sponsor for the AREA41 security conference 2026 🛸 👽 Thank you for supporting the infosec community, we look forward to seeing you‼️ ➡️ Check them out at: compass-security.com @compass-security.com 📅 June 18-19. 2026, Zürich - area41.io
Foreign enterprise apps can expose your Entra ID tenant. Today, we release part 1 of our 4-part weekly series on common Entra ID pitfalls and how to detect them with EntraFalcon. Learn how external apps can lead to data access or worse: blog.compass-security.com/2026/03/comm...
EntraFalcon update 🚀 The new Security Findings Report turns Entra ID enumeration into actionable findings with 60+ checks and colorful charts. Read Chrigi's @zh54321.bsky.social blog and try the tool now on your tenant! blog.compass-security.com/2026/03/from... #EntraID #CloudSecurity #EntraFalcon
WinGet can be more than a package manager. We show how .𝚠𝚒𝚗𝚐𝚎𝚝 configs + a self-referencing LNK become a viable initial access payload when Microsoft Store is enabled. Includes detection queries & mitigation tips. blog.compass-security.com/2026/03/wing... #RedTeam #Windows #LOLBins #InitialAccess
John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to a working PoC. blog.compass-security.com/2026/02/from... #Windows #CVE #SecurityResearch #PrivEsc
A night full of exciting happenings. Compass #Pwn2Own team chained zero days to run code on the Canada built Grizzl-e Smart level 2 charger. Colleagues also demoed the manipulation of of the charging control protocol. Well earned 25‘000 USD!
We have a collision! Compass Security (@compasssecurity) earned $25,000 USD and 4 Master of Pwn points with the Charging Connector Protocol/Signal Manipulation add‑on against the Grizzl‑E Smart 40A, chaining an authentication bypass (CWE‑306) to remote code execution via CWE‑494. #Pwn2Own #P2OAuto
We have exciting news to share. Compass folks made the Alpine car infotainment system to run arbitrary code and earn a 10‘000 USD. 🎉🎉🎉
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) exploited one exposed dangerous method/function bug on the Alpine iLX-F511, winning Round 2 for $10,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto
How do we keep our security analysts up to date? Our latest blog post looks inside our internal training week, from Kubernetes security to red teaming and our annual Security Boot Camp. blog.compass-security.com/2026/01/cont... #CyberSecurity #Learning #Pentesting #Kubernetes