Advertisement · 728 × 90

Posts by Nicolò Fornari

Two conclusions from this - it's an incremental improvement, not a sea change. And $1k per attack won't easily scale. We probably not about to experience "THE VULNPOCALYPSE" but continued incremental improvements in vulnerabilities hunting.

5 days ago 0 2 0 0

This morning we got one of our pending #curl security flaws reported a **4th** time.

Everyone is using (the same) AI tools now.

1 week ago 11 9 3 0

What if Mythos is being overhyped so that Anthropic can develop a higher margin enterprise model instead of the high volume low margin one they’ve pursued until now? This is not to say we can disregard the claim - but let’s wait and see where the truth lies.

1 week ago 8 1 2 0
Are We Idiocracy Yet? Tracking how close reality is to Mike Judge's Idiocracy. It's got electrolytes.

TIL idiocracy.wtf

2 weeks ago 0 0 0 0

Totally worth reading.

3 weeks ago 2 1 0 0

LOL

2 weeks ago 0 0 0 0
Post image

🇨🇭 In Ticino, the open Swiss model Apertus powers in-house AI translation for the Cantonal Administration — boosting multilingual services with local, transparent control. A great example of sovereign AI in action bit.ly/4rzU0Og @epfl-ai-center.bsky.social @eth-ai-center.bsky.social

1 month ago 5 5 0 0
Post image

EntraFalcon update 🚀 The new Security Findings Report turns Entra ID enumeration into actionable findings with 60+ checks and colorful charts. Read Chrigi's @zh54321.bsky.social blog and try the tool now on your tenant!

blog.compass-security.com/2026/03/from...

#EntraID #CloudSecurity #EntraFalcon

1 month ago 3 3 0 0
Advertisement

The sheer strategic stupidity of bailing Russia out of its economic hole by launching a war that entirely foreseeably spikes the oil price - and then having no minesweepers in place to deal with the foreseeable fallout. Rank incompetence.

1 month ago 911 245 43 18
Preview
MXmap — Email Providers of Swiss Municipalities Interactive map showing where Swiss municipalities host their official email. DNS analysis of all ~2,100 municipalities, color-coded by provider.

mxmap.ch

1 month ago 0 0 0 0
Preview
Ukraine Reaches a Milestone: Making ‘China-Free’ Drones

This is a very good approach.
(And I say approach, rather than outcome, because the headline goes a bit far. But still: well done Ukraine!!)

#drone
www.nytimes.com/2026/03/11/w...

1 month ago 303 59 5 0
Original post on hachyderm.io

PSA: The Amazon wishlist doxing threat is much greater and more immediate than folks might realize. Attack works like this:

Stalker who wants your address opens an Amazon seller account and lists themselves as a third party seller for any item on your public wishlist. Then, they order the item […]

1 month ago 34 240 9 6

Paged Out zine #8


pagedout.institute ->


Original->

2 months ago 1 2 0 0
Post image

You can grab the latest copy of our quarterly security research roundup at thinkst.com/ts ¹

For this issue, we selected work from over 1,370 talks & 1,200 blog posts.

Available as PDF, ePUB (or audio highlights)

__
¹ As always, completely free

2 months ago 2 4 0 0

What is happening in the United States is horrible. Half the Americans is in the right side, and it is the side that can restore and make the country sane again. Act now (without getting killed), do what you can to fix this mess. Get back your country.

2 months ago 33 1 2 0

We have exciting news to share. Compass folks made the Alpine car infotainment system to run arbitrary code and earn a 10‘000 USD. 🎉🎉🎉

3 months ago 8 4 2 0
Post image Post image

Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) exploited one exposed dangerous method/function bug on the Alpine iLX-F511, winning Round 2 for $10,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto

3 months ago 3 5 0 1

[RSS] wtf is NS_ERROR_INVALID_CONTENT_ENCODING? investigating shared dictionaries and ChatGPT breakage in Firefox


joshua.hu ->


Original->

3 months ago 0 1 0 0
Advertisement
Preview
America’s Strategic Alliance with Denmark and NATO A statement by 14 former officials in Democratic and Republican Administrations—including four NATO Ambassadors, 3 Assistant Secretaries of State for Europe, and 3 NSC Senior Directors

Joint statement by 4 former officials in Democratic and Republican Administrations—including four NATO Ambassadors, 3 Assistant Secretaries of State for Europe, and 3 NSC Senior Directors.

Excellent opening in particular.

3 months ago 908 392 44 40

If Seatbelt Guidance Worked Like Cybersecurity Guidance


scribe.rip ->


Original->

3 months ago 1 1 0 0

Bloomberg's X account has more than 800k followers. Their most recent post was shared five times

It would basically come at close to zero cost for outlets like Bloomberg to delete their X accounts, and "We don't want to use a non-consensual deepfake abuse app as a comms platform" is a fine excuse

3 months ago 3156 822 33 24

I hope the Danes and the other European forces are training in guerrilla warfare as that always works against the USA, especially on hostile territory (cf. Greenland).

3 months ago 3 1 0 0
Preview
‘It’s surreal’: US sanctions lock International Criminal Court judge out of daily life Canadian judge Kimberly Prost is unable to use credit cards, transfer money or book everyday services in what she calls an attack on the independence of the judiciary

Why do I have to read an Irish paper for a feature about this?

3 months ago 1449 768 53 132
Preview
The European Cloud Situation at the end of 2025 - Bert Hubert As the year draws to an end now is a good time to review where we are with Europe’s cloud situation, and what has been achieved. One thing is certain, a lot has happened, and also quite a lot has beco...

So, what did we achieve for 🇪🇺's cloud situation in 2025? It is now crystal clear our governments can't continue to run on 🇺🇸 clouds. Yet even now, neither buyers or sellers of cloud tech in 🇪🇺 sense the urgency. Below I elaborate & discuss an unorthodox way out of this mess: berthub.eu/articles/pos...

3 months ago 56 29 2 1
Preview
MPs question UK Palantir contracts after investigation reveals security concerns Journalists find Swiss government rejected company over fears US intelligence might gain access to sensitive data

Our story in the GUARDIAN!!!

😎 😎
🎇 🎇 🎇
🔥🔥🔥🔥

www.theguardian.com/technology/2...

3 months ago 62 13 3 2
Fuzzing and AFL++
Fuzzing and AFL++ YouTube video by Compass Security

In a new video, Nicolò @rationalpsyche.bsky.social walks through how to fuzz with AFL++, how to pick targets, avoid common pitfalls, and boost effectiveness. Find performance tips, fuzzing theory, and AFL++ internals.

Watch here: youtu.be/L5Tin7m5sbE?...

#security #fuzzing #AFLplusplus #appsec

4 months ago 3 2 0 0
Advertisement

Super interesting and highly recommended.
There's so much to unpack that I bookmarked it for a second read.

4 months ago 4 2 1 0
4 months ago 0 0 0 0
Post image

NTLM relay works against HTTPS if channel binding is missing. Our new blog post explains why, shows how tooling evolved, and highlights defensive measures.

blog.compass-security.com/2025/11/ntlm...

4 months ago 3 3 0 0
Video

We still need to get from a situation where Russia pretends to negotiate to a situation where they need to negotiate.

Extract from my press remarks following today’s informal Foreign Affairs Council ↓

4 months ago 1835 547 63 50