Compass Security

Compass Security Offensive Defense

Compass Security Blog Offensive Defense

  • CRA Reporting – What you need to know
    by Andreas Brombach on September 3, 2026 at 8:02 am

    While the full implementation of the Cyber Resilience Act (CRA) won’t take effect until December 2027, another critical milestone is already approaching much sooner. Starting from 11 September 2026, all manufacturers selling products with digital elements in countries of the European Union will be required to report actively exploited vulnerabilities in their digital products, as

  • A Note on Pentesting Passkeys
    by Emanuel Duss on August 25, 2026 at 7:00 am

    Some months ago, I performed a web application penetration test on an application that used passkey for authentication. As part of the assessment, I also tested the passkey implementation and noticed some unusual behavior. During the debugging process, I created two short JavaScript helper functions that can be used to hook the browser APIs involved in passkey operations, allowing the passkey configuration to be inspected and manipulated. This gave me the ability to reliably perform some passkey tests and assess the configuration and implementation.

  • Pipeleek v1 Release
    by Jan Friedli on August 4, 2026 at 7:00 am

    Pipeleek 1.0 is here. What started as a GitLab pipeline secret scanner now covers seven CI/CD platforms and comes with helpers for runner exploitation, Renovate bot abuse, and lateral movement across repositories. This post walks through what is new, shows two real-world findings from the Tor Project and GitLab itself, and introduces the GitLab Attack Lab where you can try the full attack chain yourself.

  • The Hidden Privilege of Automation Platforms
    by Sebastian Malin on July 21, 2026 at 7:00 am

    Automation platforms such as n8n are often introduced as productivity tools: connect a few systems, automate repetitive work, maybe add some AI. Inside a corporate network, however, that framing is incomplete. A self-hosted workflow engine can reach internal systems, execute actions on behalf of users, and hold sensitive credentials. That puts it in the same

  • Cyber Resilience Act – Part II
    by Tobias Hort-Giess on July 7, 2026 at 7:00 am

    In this second part, we demonstrate how a Cyber Resilience Act (CRA) assessment is performed in practice. Using a low-cost IP camera as an example, we show how a product is classified, how threats are modelled, how hardware and firmware are analysed, and how compliance gaps against IEC 62443-4-2 can be identified. You may want

  • Cyber Resilience Act – Part I
    by Tobias Hort-Giess on June 26, 2026 at 6:40 am

    The Cyber Resilience Act (CRA) is a regulation introduced by the European Union to strengthen cybersecurity requirements for products with digital elements.In simple terms, the CRA sets mandatory cybersecurity rules for hardware and software sold in the EU. This includes everything from connected devices (IoT) to operating systems and even stand-alone software. Very important, this

  • Entra Agent ID from a Security Perspective
    by Christian Feuchter on June 9, 2026 at 7:00 am

    AI agents in your Entra ID tenant? They come with new identities, permissions, and fresh attack paths. Christian Feuchter breaks down Entra Agent ID security, security-relevant capabilities, control paths, abuse scenarios, and how to review your exposure with EntraFalcon.

  • SSH Labs
    by Emanuel Duss on May 27, 2026 at 7:00 am

    SSH is a widely used protocol that provides secure access to remote systems. It enables encrypted communication, file transfers, command execution and shell access for system administration. Visit https://sshlabs.compass-security.training to learn more about SSH security.

  • Introducing RAPTR
    by Felix Aeppli on May 11, 2026 at 7:00 am

    I’m happy to announce that we are releasing the beta version of RAPTR, a fully open source, API driven collaboration platform built specifically for red and purple team engagements.

  • Tabletop Simulations: Where Theory Meets Reality
    by Andreas Arnold on April 28, 2026 at 7:00 am

    On paper, the vast majority of crisis plans look reasonable, actionable and complete. Once the rubber hits the road, however, chaos emerges quickly.

Share Websitecyber
We are an ethical website cyber security team and we perform security assessments to protect our clients.