Compass Security Offensive Defense
Compass Security Blog Offensive Defense
- CRA Reporting – What you need to knowby Andreas Brombach on September 3, 2026 at 8:02 am
While the full implementation of the Cyber Resilience Act (CRA) won’t take effect until December 2027, another critical milestone is already approaching much sooner. Starting from 11 September 2026, all manufacturers selling products with digital elements in countries of the European Union will be required to report actively exploited vulnerabilities in their digital products, as
- A Note on Pentesting Passkeysby Emanuel Duss on August 25, 2026 at 7:00 am
Some months ago, I performed a web application penetration test on an application that used passkey for authentication. As part of the assessment, I also tested the passkey implementation and noticed some unusual behavior. During the debugging process, I created two short JavaScript helper functions that can be used to hook the browser APIs involved in passkey operations, allowing the passkey configuration to be inspected and manipulated. This gave me the ability to reliably perform some passkey tests and assess the configuration and implementation.
- Pipeleek v1 Releaseby Jan Friedli on August 4, 2026 at 7:00 am
Pipeleek 1.0 is here. What started as a GitLab pipeline secret scanner now covers seven CI/CD platforms and comes with helpers for runner exploitation, Renovate bot abuse, and lateral movement across repositories. This post walks through what is new, shows two real-world findings from the Tor Project and GitLab itself, and introduces the GitLab Attack Lab where you can try the full attack chain yourself.
- The Hidden Privilege of Automation Platformsby Sebastian Malin on July 21, 2026 at 7:00 am
Automation platforms such as n8n are often introduced as productivity tools: connect a few systems, automate repetitive work, maybe add some AI. Inside a corporate network, however, that framing is incomplete. A self-hosted workflow engine can reach internal systems, execute actions on behalf of users, and hold sensitive credentials. That puts it in the same
- Cyber Resilience Act – Part IIby Tobias Hort-Giess on July 7, 2026 at 7:00 am
In this second part, we demonstrate how a Cyber Resilience Act (CRA) assessment is performed in practice. Using a low-cost IP camera as an example, we show how a product is classified, how threats are modelled, how hardware and firmware are analysed, and how compliance gaps against IEC 62443-4-2 can be identified. You may want
- Cyber Resilience Act – Part Iby Tobias Hort-Giess on June 26, 2026 at 6:40 am
The Cyber Resilience Act (CRA) is a regulation introduced by the European Union to strengthen cybersecurity requirements for products with digital elements.In simple terms, the CRA sets mandatory cybersecurity rules for hardware and software sold in the EU. This includes everything from connected devices (IoT) to operating systems and even stand-alone software. Very important, this
- Entra Agent ID from a Security Perspectiveby Christian Feuchter on June 9, 2026 at 7:00 am
AI agents in your Entra ID tenant? They come with new identities, permissions, and fresh attack paths. Christian Feuchter breaks down Entra Agent ID security, security-relevant capabilities, control paths, abuse scenarios, and how to review your exposure with EntraFalcon.
- SSH Labsby Emanuel Duss on May 27, 2026 at 7:00 am
SSH is a widely used protocol that provides secure access to remote systems. It enables encrypted communication, file transfers, command execution and shell access for system administration. Visit https://sshlabs.compass-security.training to learn more about SSH security.
- Introducing RAPTRby Felix Aeppli on May 11, 2026 at 7:00 am
I’m happy to announce that we are releasing the beta version of RAPTR, a fully open source, API driven collaboration platform built specifically for red and purple team engagements.
- Tabletop Simulations: Where Theory Meets Realityby Andreas Arnold on April 28, 2026 at 7:00 am
On paper, the vast majority of crisis plans look reasonable, actionable and complete. Once the rubber hits the road, however, chaos emerges quickly.
















