#compasssecurity
Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 & 2 Master of Pwn points. #Pwn2Own
May 16, 2026 at 12:21 PM
Very nicely done! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit Anthropic Claude Code! They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin
May 16, 2026 at 11:36 AM
Hacking Tools Cheat Sheet from twitter.com/compasssecurity

Information Gathering
Network Scanning
Metasploit Framework
Cracking
Connection Triggering
Password Spraying
and much more.

High quality (3 pages):
github.com/CompassSecur...
September 20, 2023 at 10:24 PM
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security exploited Cursor in the second round, earning $15,000 and 3 Master of Pwn points. Full win! #Pwn2Own #P2OBerlin
May 15, 2026 at 3:36 PM
Big W!! 💪 Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit OpenAI Codex! Off to the disclosure room to spill the tea. #Pwn2Own #P2OBerlin
May 14, 2026 at 11:05 AM
Compass Security (@compasssecurity) ran into a collision in their attempt against the Ubiquiti AI bullet. Their exploit still wins them $3,750 and 1.5 Master of Pwn points. #Pwn2Own #P2OIreland
October 23, 2024 at 4:42 PM
Boom! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security was able to exploit Cursor! They're off to the disclosure room to explain how they did it. #Pwn2Own #P2OBerlin
May 15, 2026 at 3:01 PM
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) exploited one exposed dangerous method/function bug on the Alpine iLX-F511, winning Round 2 for $10,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto
January 21, 2026 at 4:17 AM
We are excited to have Compass Security again as a Platinum sponsor supporting the AREA41 conference - Thank you🥳
See you 6-7.June in Zürich
@compasssecurity
April 18, 2024 at 2:00 PM
It's official! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) used a single CWE-150 bug to exploit OpenAI Codex, earning $40,000 and 4 Master of Pwn points. #Pwn2Own #P2OBerlin
May 14, 2026 at 12:30 PM
We have a collision! Compass Security (@compasssecurity) earned $25,000 USD and 4 Master of Pwn points with the Charging Connector Protocol/Signal Manipulation add‑on against the Grizzl‑E Smart 40A, chaining an authentication bypass (CWE‑306) to remote code execution via CWE‑494. #Pwn2Own #P2OAuto
January 21, 2026 at 6:12 AM
Unfortunately, Compass Security (@compasssecurity) could not get their exploit of the Alpine iLX-507 working within the time allotted.
January 23, 2025 at 10:37 AM
Sweet! Compass Security (@compasssecurity) successfully exploited the Ubiquiti AI Bullet camera. They're off to the disclosure room to explain what happened. #Pwn2Own #P2OIreland
October 23, 2024 at 4:16 PM
Here's a tool by Compass Security which allows to download @burpsuite.bsky.social extensions. Very useful when you don't have Internet access during the assesment 🛠️
GitHub - CompassSecurity/bapp-downloader: Script for downloading Burp Suite extension files
Script for downloading Burp Suite extension files. Contribute to CompassSecurity/bapp-downloader development by creating an account on GitHub.
github.com
January 17, 2024 at 12:22 PM
TokenPhisher now forces recent MFA logins from victims which comes in handy when emulating these device code phishing tactics: github.com/CompassSecur...
Force recent MFA login by victim by martanne · Pull Request #5 · CompassSecurity/TokenPhisher
This adds the ngcmfa claim when initiating the device code flow. The underlying request should be identical to what Dirk-jan eventually implemented for roadtx auth --device-code --force-ngcmfa ... ...
github.com
February 17, 2025 at 9:00 AM
December 27, 2025 at 10:30 PM
There’s a new #compasssecurity blog post that dives into the very technical aspects of email frauds ( #bec and #ceofraud). Level-up your e-mail analysis game and beware of the scammers!

blog.compass-security.com
Compass Security Blog – Offensive Defense
blog.compass-security.com
October 30, 2024 at 5:44 AM
Today is the day. Tune in 6pm Swiss time to cheer #compasssecurity researchers to run their exploit 🤞
October 23, 2024 at 5:45 AM
I'll start off to bring stuff to bsky. Mainly, the cool work my fellow colleagues at #compasssecurity push out.

Hands-on guide to voice cloning using #AI. Learn how it's done and how to stay protected. #socialengineering #phishing #ML #hacking #ceofraud blog.compass-security.com/2024/10/voic...
October 18, 2024 at 8:32 AM
Time for another lesson taught by #compasssecurity
September 4, 2025 at 6:31 AM
John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to…

🔁 RT @compasssecurity | reposted by @HackingLZ
https://x.com/compasssecurity/status/2021140260676104564
February 11, 2026 at 9:29 AM