Compass Security Blog

Offensive Defense

CRA Reporting – What you need to know

While the full implementation of the Cyber Resilience Act (CRA) won’t take effect until December 2027, another critical milestone is already approaching much sooner. Starting from 11 September 2026, all manufacturers selling products with digital elements in countries of the European Union will be required to report actively exploited vulnerabilities in their digital products, as […]

Continue reading

Pipeleek v1 Release

Pipeleek 1.0 is here. What started as a GitLab pipeline secret scanner now covers seven CI/CD platforms and comes with helpers for runner exploitation, Renovate bot abuse, and lateral movement across repositories. This post walks through what is new, shows two real-world findings from the Tor Project and GitLab itself, and introduces the GitLab Attack Lab where you can try the full attack chain yourself.

Continue reading

The Hidden Privilege of Automation Platforms

Automation platforms such as n8n are often introduced as productivity tools: connect a few systems, automate repetitive work, maybe add some AI. Inside a corporate network, however, that framing is incomplete. A self-hosted workflow engine can reach internal systems, execute actions on behalf of users, and hold sensitive credentials. That puts it in the same […]

Continue reading

Cyber Resilience Act – Part II

In this second part, we demonstrate how a Cyber Resilience Act (CRA) assessment is performed in practice. Using a low-cost IP camera as an example, we show how a product is classified, how threats are modelled, how hardware and firmware are analysed, and how compliance gaps against IEC 62443-4-2 can be identified. You may want […]

Continue reading

Cyber Resilience Act – Part I

The Cyber Resilience Act (CRA) is a regulation introduced by the European Union to strengthen cybersecurity requirements for products with digital elements.In simple terms, the CRA sets mandatory cybersecurity rules for hardware and software sold in the EU. This includes everything from connected devices (IoT) to operating systems and even stand-alone software. Very important, this […]

Continue reading