News

Vulnerability in Mailster

8.07.2020 ‒ Thierry Viaccoz identified an XSS vulnerability in Mailster (email newsletter plugin for WordPress). Read more

Secure Payments on th Internet

6.07.2020 ‒ More and more goods and services are bought and paid on the internet. Ivan Bütler summarizes security relevant information on online shopping and... Read more

Vulnerability in Froala WYSIWYG HTML Editor

2.07.2020 ‒ Security Analyst Emanuel Duss identified a DOM XSS vulnerability in the Froala WYSIWYG HTML Editor Read more

Vulnerability in JEditor Jira Plugin

26.06.2020 ‒ Lukasz D. identified an XSS vulnerability in the JEditor Jira Plugin. Read more

Hacking-Lab als Prüfungsplattform

25.06.2020 ‒ Im November findet die erste Berufsprüfung zum Cyber Security Specialist statt: praxisnah und handlungsorientiert dank der von Compass Security und... Read more

Compass Security is strengthening its presence in cyber education

10.06.2020 ‒ Offered at the HSR University of Applied Science in Rapperswil (Switzerland), the new degree programm is targeted at experienced IT professionals who... Read more

Vulnerability in Abacus

9.03.2020 ‒ Ville Koch identified a Cross-Site Scripting vulnerability in Abacus. Read more

Rein kommen wir meistens

5.03.2020 ‒ In einem Interview in der Wirtschaftszeitung «Finanz und Wirtschaft» spricht Walter Sprenger über die Motivationsgründe und Methoden der Hacker. Read more

KMU im Visier von Cyberkriminellen

10.02.2020 ‒ In der Sendung «Fokus KMU» erzählt ein Betroffener über die Auswirkungen der Cyber Attacke auf sein Unternehmen. Cyrill Brunschwiler von Compass... Read more

Daten als Wettbewerbsvorteil

20.12.2019 ‒ Das Basel Economic Forum ist das Wirtschaftsforum für die trinationale Metropolitanregion Basel und die Nordwestschweiz. Im November fand die 6.... Read more

Vulnerability in Apache Olingo OData 4.0

6.12.2019 ‒ Compass analysts identified an XXE vulnerability in Apache Olingo OData 4.0. Read more

Vulnerability in totemodata

21.10.2019 ‒ Fabio Poloni identified an XSS vulnerability in totemodata®. Read more

CALENDAR

Security Training: Secure Mobile Apps

In the 2-day course (in German) from October 20/21, 2020, you will learn about the most important security problems of mobile apps. Read more

Security Training: Social Engineering

In the 2-day course (in German) from December 1/2, 2020, you will get to know and understand the methods, tools and tricks of social engineering. Read more

ALL DATES

Compass Security Blog

Yet Another Froala 0-Day XSS

Compass found a DOM-based cross-site scripting (XSS) in the Froala WYSIWYG HTML Editor. HTML code in the editor is not correctly sanitized when inserted into the DOM. This allows an attacker that can... mehr

Relaying NTLM authentication over RPC

Since a few years, we - as pentesters - (and probably bad guys as well) make use of NTLM relaying a lot for privilege escalation in Windows networks. In this article, we propose adding support for... mehr

ZUM BLOG