Compass Security Blog

Offensive Defense

CRA Reporting – What you need to know

While the full implementation of the Cyber Resilience Act (CRA) won’t take effect until December 2027, another critical milestone is already approaching much sooner. Starting from 11 September 2026, all manufacturers selling products with digital elements in countries of the European Union will be required to report actively exploited vulnerabilities in their digital products, as […]

Continue reading

A Note on Pentesting Passkeys

Some months ago, I performed a web application penetration test on an application that used passkey for authentication. As part of the assessment, I also tested the passkey implementation and noticed some unusual behavior. During the debugging process, I created two short JavaScript helper functions that can be used to hook the browser APIs involved in passkey operations, allowing the passkey configuration to be inspected and manipulated. This gave me the ability to reliably perform some passkey tests and assess the configuration and implementation.

Continue reading

Pipeleek v1 Release

Pipeleek 1.0 is here. What started as a GitLab pipeline secret scanner now covers seven CI/CD platforms and comes with helpers for runner exploitation, Renovate bot abuse, and lateral movement across repositories. This post walks through what is new, shows two real-world findings from the Tor Project and GitLab itself, and introduces the GitLab Attack Lab where you can try the full attack chain yourself.

Continue reading

The Hidden Privilege of Automation Platforms

Automation platforms such as n8n are often introduced as productivity tools: connect a few systems, automate repetitive work, maybe add some AI. Inside a corporate network, however, that framing is incomplete. A self-hosted workflow engine can reach internal systems, execute actions on behalf of users, and hold sensitive credentials. That puts it in the same […]

Continue reading

Cyber Resilience Act – Part II

In this second part, we demonstrate how a Cyber Resilience Act (CRA) assessment is performed in practice. Using a low-cost IP camera as an example, we show how a product is classified, how threats are modelled, how hardware and firmware are analysed, and how compliance gaps against IEC 62443-4-2 can be identified. You may want […]

Continue reading

Cyber Resilience Act – Part I

The Cyber Resilience Act (CRA) is a regulation introduced by the European Union to strengthen cybersecurity requirements for products with digital elements.In simple terms, the CRA sets mandatory cybersecurity rules for hardware and software sold in the EU. This includes everything from connected devices (IoT) to operating systems and even stand-alone software. Very important, this […]

Continue reading

Entra Agent ID from a Security Perspective

AI agents in your Entra ID tenant? They come with new identities, permissions, and fresh attack paths.

Christian Feuchter breaks down Entra Agent ID security, security-relevant capabilities, control paths, abuse scenarios, and how to review your exposure with EntraFalcon.

Continue reading

SSH Labs

SSH is a widely used protocol that provides secure access to remote systems. It enables encrypted communication, file transfers, command execution and shell access for system administration.

Visit https://sshlabs.compass-security.training to learn more about SSH security.

Continue reading

Introducing RAPTR

I’m happy to announce that we are releasing the beta version of RAPTR, a fully open source, API driven collaboration platform built specifically for red and purple team engagements.

Continue reading

Tabletop Simulations: Where Theory Meets Reality

On paper, the vast majority of crisis plans look reasonable, actionable and complete. Once the rubber hits the road, however, chaos emerges quickly.

Continue reading

« Older posts