SSH everywhere, misconfigurations somewhere. Our new SSH Labs let you get your hands dirty: slides, video, and a Docker-based lab. Created by our Security Analyst @emanuelduss, learn how SSH breaks and how to fix it: https://t.co/2jxuEK8N4i
#SSH#InfoSec#Security
Collision! Although successful on stage, Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security targeted Anthropic Claude Code, hitting a one-vulnerability collision with a previous attempt and earning $20,000 and 2 Master of Pwn points. #Pwn2Own #P2OBerlin
Very nicely done! Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit Anthropic Claude Code! They're off to the disclosure room to explain how they did it. #Pwn2Own#P2OBerlin
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security exploited Cursor in the second round, earning $15,000 and 3 Master of Pwn points. Full win! #Pwn2Own#P2OBerlin
That's a wrap on Day 2 of #Pwn2Own Berlin! Day Two added $385,750 and 15 unique 0-days, bringing event totals to $908,750 for 39 unique vulnerabilities. DEVCORE leads Master of Pwn with 40.5 points — but the fun ain't over yet, we've got one more day to go. See you tomorrow! #P2OBerlin
Big W!! 💪 Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security were able to exploit OpenAI Codex! Off to the disclosure room to spill the tea. #Pwn2Own#P2OBerlin
Compass vulnerability research identified code execution paths affecting AI coding assistants including @claudeai , @cursor_ai and @OpenAI#Codex. The findings will be demonstrated live at @thezdi Initiative #Pwn2Own Berlin 2026, May 14 to 16. #AIsecurity#LLM
People know I am all crazy about electricity and electronics. So, I am specially excited about the wall charger exploit and I must admit I am very tempted to try my luck on European models. Unfortunately, there is no vacation in sight yet 🤪. This is a huge achievement! Congratz!
2-for-2! 🏆 Huge shoutout to @yves_bieri and Lukasz for clean exploits on the Alpine iLX-F511 and Grizzl-E Smart 40A systems with the Charging Connector Protocol/Signal Manipulation add-on. Couldn’t be prouder of the team for executing perfectly today. Congrats! #Pwn2Own
Here we are again! Finally on the ground for #Pwn2Own Automotive in Tokyo. 🏎️💻 Our team is ready, and we’re just waiting for the Tuesday draw to see when we’re up. Big week ahead! Stay tuned! 🛠️🔥
Thank you #BugHunters for your relentless curiosity and clean reports that keep our customers #BugBountyProgram sharp.
Soon to announce: Switzerland's highest max. #bounty EVER, new programs and budget refills. Stay tuned! For now: shutdown, enjoy the festive season and recharge
Thank you #BugHunters for your relentless curiosity and clean reports that keep our customers #BugBountyProgram sharp.
Soon to announce: Switzerland's highest max. #bounty EVER, new programs and budget refills. Stay tuned! For now: shutdown, enjoy the festive season and recharge
. #Pentest of gRPC-Web apps is tricky due to the binary format. We are releasing bRPC-Web, a @PortSwigger@Burp_Suite extension developed by our @muukong that makes #gRPC-Web traffic readable and editable, even in the absence of #protobuf schema files. https://t.co/xSYHr3yvWU
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: https://t.co/jD6EaGtsn3
Episode 5 of our Kerberos deep dive is live.
Constrained delegation isn’t bulletproof. See how attackers exploit it, and how to defend with monitoring & best practices.
https://t.co/wIqDBT5gnH
#Kerberos#ActiveDirectory
Calling all bug hunters! schulNetz by Centerboard AG is now in scope! Help protect over 100k users in schools. Are you ready to make the grade and earn bounties? Program: https://t.co/peIfkXFTCd #bugbounty
Excited to present at #TROOPERS25 this week! On Thursday, our #cybersecurity analysts Emanuele and @yves_bieri will present our latest #Pwn2Own research on #surveillance cameras covering methodology, breakthroughs, and hard-won lessons. Come by, pick our brains, and swap stories. See you there!
#talk details: https://t.co/NjBQAlFHiz
#iot #pentest capabilities: https://t.co/dBqjn0KkVg