John Ostrowski (Compass Security) and Manuel Kiesel (Cyllective AG) worked together on CVE-2025-13154, a Lenovo Vantage LPE. Even after Microsoft closed a known primitive, collaboration led to a working PoC.
blog.compass-security.com/2026/02/from...
#Windows #CVE #SecurityResearch #PrivEsc
10.02.2026 08:33 — 👍 6 🔁 4 💬 0 📌 0
There are probably more vulns to be found, especially in the parts that I did not look at. Passing the torch to all the other researcherz.
09.02.2026 10:59 — 👍 0 🔁 0 💬 0 📌 0
roll with advantage: hacking lenovo vantage | mkiesel.ch
A technical deep dive into the lands of Lenovo Vantage and its add-ins, including tooling to help you hunt for vulnerabilities
First research in a while! Here's my brain dump on reverse-engineering and auditing Lenovo Vantage. In total, I found four (4) vulns. Check out the post and my custom tooling if you're interested.
mkiesel.ch/posts/lenovo...
09.02.2026 10:59 — 👍 2 🔁 1 💬 1 📌 0
How To Audit Plugin Ecosystems
How we audit plugin ecosystems, using (Nextcloud|ownCloud) as an example
🚀 New blog post: How to Audit Plugin Ecosystems 🔧🔥
Our reusable 4‑step method helped us navigate 600+ Nextcloud/ownCloud plugins & find some vulns.
cyllective.com/blog/posts/h...
#CyberSecurity #AppSec #Nextcloud #ownCloud #infosec #pentest #SAST
03.02.2026 13:12 — 👍 2 🔁 2 💬 0 📌 0
uBlock Origin rules to slim down/minimalize Twitter/X, Bluesky, and Mastodon
uBlock Origin rules to slim down/minimalize Twitter/X, Bluesky, and Mastodon - anti_social_media_ublock_rules.txt
Nobody asked for them, but here are my uBlock rules to slim down Twitter/X, Bluesky, and Mastodon. They disable fancy features and make it so that basically there are only the options to post and to view your "following" feed. No more distractions!
gist.github.com/rtfmkiesel/1...
02.02.2026 15:37 — 👍 0 🔁 0 💬 0 📌 0
We have a collision! Compass Security (@compasssecurity) earned $25,000 USD and 4 Master of Pwn points with the Charging Connector Protocol/Signal Manipulation add‑on against the Grizzl‑E Smart 40A, chaining an authentication bypass (CWE‑306) to remote code execution via CWE‑494. #Pwn2Own #P2OAuto
21.01.2026 06:12 — 👍 2 🔁 1 💬 0 📌 1
Confirmed! Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., and Urs Mueller of Compass Security (@compasssecurity) exploited one exposed dangerous method/function bug on the Alpine iLX-F511, winning Round 2 for $10,000 USD and 2 Master of Pwn points. #Pwn2Own #P2OAuto
21.01.2026 04:16 — 👍 3 🔁 5 💬 0 📌 1
co//aboration…ftw! Thanks for the kudos!
17.01.2026 21:05 — 👍 1 🔁 1 💬 0 📌 0
The final stage would not have been possible without John Ostrowski from @compass-security.com thanks for the Swiss infosec collaboration! 🫕🤝
17.01.2026 13:36 — 👍 3 🔁 2 💬 1 📌 0
Lenovo Vantage LPE/EoP (CVE-2025-13154)
A write-up of CVE-2025-13154, a privilege escalation vulnerability in Lenovo Vantage.
🚨 New blog post!
Read about CVE-2025-13154, a privilege-escalation vulnerability in a Lenovo Vantage add-in called SmartPerformance.
cyllective.com/blog/posts/l...
#windows #cve #infosec #pentest
17.01.2026 13:36 — 👍 1 🔁 2 💬 1 📌 1
co//aboration… ftw. Thanks for the Kudos!
16.01.2026 15:03 — 👍 2 🔁 1 💬 0 📌 0
matelab.ch - The Swiss Mate Index
Compare mate-based beverages
🇨🇭 With El Tony's new Mate Zero and Coop's New Prix Garantie Mate, matelab is now at 60 mate-based beverages 🧉
matelab.ch
16.01.2026 08:44 — 👍 0 🔁 0 💬 0 📌 0
TrendAI Zero Day Initiative™ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
sorry, computer
https://please.donothack.us/
https://github.com/ofasgard
IT security. Linux & network protocols. Pentesting web applications, networks & AD infrastructures. Mostly technical stuff here. https://emanuelduss.ch
Information & Cybersecurity Student
IT Security Engineer @ cyllective.com
Memes and Shitposts Expert
Pentagrid performs technically solid IT security assessments.
Website: https://www.pentagrid.ch/
Mastodon: https://infosec.exchange/@pentagrid
Imprint: https://www.pentagrid.ch/en/pages/imprint-and-contact/
Penetration Testing, Red Teaming, Incident Response, Managed Detection, Digital Forensics, Security Training, Managed Bug Bounty, Cyber Training Range
Master of Disaster @compass-security.com 🔥 for all sorts crises, scada, chunk hacking, electronics, cryptography and cyber all the things.
Leading Google's web security team.
Passionate about web security and making secure-by-default web development the norm. Contributed to web platfom security features like CSP, Fetch Metadata, COOP and Trusted Types.
Hacking stuff at https://www.redguard.ch/
Web application security guy with a passion for OWASP's open source WAF projects and National Cyber Strategy.
Maintains "Swiss Cyber Security" starter pack and cherishes his small collection of medieval helmets.
Self-XSS connoisseur. Elite Hacker. MVH H11337UPBash. One-Percent Man. Creator of CSPBypass.com. (he/him)
javascript:/*--></title></style></textarea></script></xmp><svg/onload='-/"/-/onmouseover=1/-/[*/[]/-alert(1)//'>
https://garethheyes.co.uk/#latestBook
Open-source tool maker/hacker. Author of gron, anew, and a dozen dinky security tools. He/him. Tools: http://github.com/tomnomnom
Security researcher with a focus on hardware & firmware. I occasionally publish stuff on YouTube. Co-founder of
hextree.io. Contact: contact@stacksmashing.net
wannabe hacker... he/him
🌱 grow your hacking skills https://hextree.io