Compass Security

1.3K posts

Compass Security banner
Compass Security

Compass Security

@compasssecurity

Penetration Testing, Red Teaming, Incident Response, Bug Bounty, Security Training, Cyber Range

Rapperswil-Jona, Schweiz Katılım Ekim 2009
113 Takip Edilen3.4K Takipçiler
Compass Security
Compass Security@compasssecurity·
Tabletop exercises show how incident response processes fall apart under pressure, far beyond what any plan suggests. Here we share key lessons from real TTX sessions: failures in communication, decision-making, structure, and human factors. blog.compass-security.com/2026/04/tablet…
Compass Security tweet media
English
1
4
17
4.7K
Compass Security
Compass Security@compasssecurity·
Your CI/CD pipeline might be your weakest link. @marcandretanner shows how exposed secrets, misconfigured runners and cross-cloud trust relationships can be abused to pivot from GitLab into AD and Entra ID. Don't miss it 👉April 14, 1:15 pm at @SpecterOps' #SOCON2026
SpecterOps@SpecterOps

GitLab is a prime DevOps target for attackers—IP, supply chain risk, & access to connected systems. 🎯 At #SOCON2026, @marcandretanner shows how an OpenGraph GitLab collector uncovers hybrid attack paths across CI/CD, service accounts, AD & Entra ID. ➡️ ghst.ly/socon26-tw

English
1
0
5
742
Compass Security retweetledi
Area41 Security Con
Area41 Security Con@a41con·
✨ We’re excited to welcome @compasssecurity as a Platinum Sponsor for the AREA41 security conference 2026 🛸 👽 Thank you for supporting the infosec community‼️ ➡️ Check them out at: compass-security.com 📅 June 18-19. 2026, Zürich - area41.io
Area41 Security Con tweet media
English
0
3
9
544
Compass Security
Compass Security@compasssecurity·
Unprotected groups in Entra ID can lead to privilege escalation. Part 2 of our 4-part series shows how weakly protected groups can be abused to bypass controls, gain privileged access, and lead to full compromise—and how to detect this with EntraFalcon: blog.compass-security.com/2026/03/common…
Compass Security tweet media
English
0
35
158
42.1K
Compass Security
Compass Security@compasssecurity·
Foreign enterprise apps can expose your Entra ID tenant. Today, we release part 1 of our 4-part weekly series on common Entra ID pitfalls and how to detect them with EntraFalcon. Learn how external apps can lead to data access or worse: blog.compass-security.com/2026/03/common…
Compass Security tweet media
English
0
40
157
9K
Compass Security
Compass Security@compasssecurity·
2-for-2! 🏆 Huge shoutout to @yves_bieri and Lukasz for clean exploits on the Alpine iLX-F511 and Grizzl-E Smart 40A systems with the Charging Connector Protocol/Signal Manipulation add-on. Couldn’t be prouder of the team for executing perfectly today. Congrats! #Pwn2Own
TrendAI Zero Day Initiative@thezdi

Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) exploited one exposed dangerous method/function bug on the Alpine iLX-F511, winning Round 2 for $10,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto

English
0
1
12
1.7K
Compass Security
Compass Security@compasssecurity·
Here we are again! Finally on the ground for #Pwn2Own Automotive in Tokyo. 🏎️💻 Our team is ready, and we’re just waiting for the Tuesday draw to see when we’re up. Big week ahead! Stay tuned! 🛠️🔥
Compass Security tweet media
English
1
1
12
735
Compass Security
Compass Security@compasssecurity·
Thank you #BugHunters for your relentless curiosity and clean reports that keep our customers #BugBountyProgram sharp. Soon to announce: Switzerland's highest max. #bounty EVER, new programs and budget refills. Stay tuned! For now: shutdown, enjoy the festive season and recharge
Compass Security tweet media
English
0
1
0
352