@compasssecurityi
iAccount based inSwitzerland
About this account
- Account based in
- Switzerland
- Connected via
- Web
Account-level information from X, not a live location or the device used for a specific post.
Penetration Testing, Red Teaming, Incident Response, Bug Bounty, Security Training, Cyber Range
Rapperswil-Jona, Schweiz
Joined October 2009
- Tweets1.3K
- Following111
- Followers3.4K
- Likes241
What’s for dessert? Root. 😈
After lunch at #BruCON0x12: Emanuele and @yves_bieri present Pwn the Hub, Own the Home
One vulnerable add-on → RCE → container escape → full Home Assistant compromise.
From 11 September 2026, manufacturers selling digital products in the EU have 24 hours to report actively exploited vulnerabilities. ⏱️ Andreas Brombach explains what is reportable, and how to actually make those deadlines: blog.compass-security.com/20…
#CRA #ProductSecurity
Pentesting passkeys? Security analyst @emanuelduss shows two JS snippets for tampering with the WebAuthn APIs. Handy for checking if you can login using a security key without knowing the PIN.
Check out the technical details and how he got there: blog.compass-security.com/20…
Pipeleek 1.0 is out 💧 Secret scanning across 7 CI/CD platforms, plus runner and Renovate bot exploitation.
Want to see one leaked job log turn into repo takeover? Try our deliberately vulnerable GitLab Attack Lab. Happy leeking!
blog.compass-security.com/20…
#DevSecOps #CICD
Your team evaluated that automation platform as a productivity tool. Attackers see a jump host with SSH access, stored credentials, and a path around your network segmentation.
Read our latest blog post before deploying any automation platform: blog.compass-security.com/20…
How do you translate the Cyber Resilience Act into technical testing? Part II of our #CRA series follows a cheap IP camera, from STRIDE threat modelling and firmware analysis to compliance with IEC 62443-4-2.
blog.compass-security.com/20…
#CyberSecurity #CyberResilienceAct #IEC62443
How do you prepare a product for the Cyber Resilience Act? Our latest article covers #CRA scope, product classification, threat modelling, technical security testing, and why we use IEC 62443 as an assessment framework. Part I of a two part series: blog.compass-security.com/20…
Attending @a41con in Dübendorf (CH)? 🎯 Swing by our booth and check out RAPTR: our open-source collab platform for Purple Team ops. Plan, attack, detect, report. All in one place.
See you there on Thursday/Friday!
#Area41 #PurpleTeam
At @a41con next week?👋
Come to our booth to see EntraFalcon in action: our open-source tool for assessing Microsoft Entra ID security posture. Privileged objects, risky assignments, conditional access misconfigs: find what's hiding in your tenant.
AI agents in your Entra ID tenant? They come with new identities, permissions, fresh attack paths.
Chrigi @ZH938472 breaks down Entra Agent ID security, their capabilities, control paths, abuse scenarios, and how to review your exposure with EntraFalcon.
blog.compass-security.com/20…
The monkey is still curious 🐒 Teleboy has topped up its bug bounty program with another CHF 10'000 in rewards. Explore a platform serving 400'000+ users across TV, internet, and telephony. Ready for another hunt? #bugbounty #ethicalhacking #cybersecurity
bugbounty.compass-security.c…
SSH everywhere, misconfigurations somewhere. Our new SSH Labs let you get your hands dirty: slides, video, and a Docker-based lab. Created by our Security Analyst @emanuelduss, learn how SSH breaks and how to fix it: blog.compass-security.com/20…
#SSH #InfoSec #Security
🤖 Made with AI
Thank you, @a41con ! Excited to be on board as a Platinum Sponsor. Looking forward to connecting with the community on-site!
✨ We’re excited to welcome @compasssecurity as a Platinum Sponsor for the AREA41 security conference 2026 🛸 👽
Thank you for supporting the infosec community‼️
➡️ Check them out at: compass-security.com
📅 June 18-19. 2026, Zürich - area41.io
Compass vulnerability research identified code execution paths affecting AI coding assistants including @claudeai , @cursor_ai and @OpenAI #Codex. The findings will be demonstrated live at @thezdi Initiative #Pwn2Own Berlin 2026, May 14 to 16. #AIsecurity #LLM
🤖 Made with AI
🦖 Meet RAPTR: our new open source platform for red and purple team collaboration. Plan engagements, document attacks and detections, evaluate results, and generate reports, all API-driven. Beta is live, feedback welcome! #PurpleTeam
blog.compass-security.com/20…
Tabletop exercises show how incident response processes fall apart under pressure, far beyond what any plan suggests. Here we share key lessons from real TTX sessions: failures in communication, decision-making, structure, and human factors.
blog.compass-security.com/20…
The final part of our Entra ID blog series looks at common Conditional Access weaknesses, practical attack scenarios, and how to identify such issues with EntraFalcon.
blog.compass-security.com/20…
Your CI/CD pipeline might be your weakest link. @marcandretanner shows how exposed secrets, misconfigured runners and cross-cloud trust relationships can be abused to pivot from GitLab into AD and Entra ID.
Don't miss it 👉April 14, 1:15 pm at @SpecterOps' #SOCON2026
GitLab is a prime DevOps target for attackers—IP, supply chain risk, & access to connected systems. 🎯
At #SOCON2026, @marcandretanner shows how an OpenGraph GitLab collector uncovers hybrid attack paths across CI/CD, service accounts, AD & Entra ID.
➡️ ghst.ly/socon26-tw
Part 3 of our Entra ID blog series looks at common weak PIM configurations, practical abuse scenarios, and how to identify them with EntraFalcon: blog.compass-security.com/20…