<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss.xsl" type="text/xsl"?><rss version="2.0"><channel><title>guisso.dev</title><description>Engineering &amp; Security</description><link>https://guisso.dev/en/</link><language>en-US</language><homeLink>/en/</homeLink><item><title>Phone Phreaking</title><link>https://guisso.dev/en/blog/phone-phreaking/</link><guid isPermaLink="true">https://guisso.dev/en/blog/phone-phreaking/</guid><description>Before the internet, a giant network already connected the world. From the 2600 Hz whistle to SS7 attacks and rogue cell sites in São Paulo apartments: the technical manual of phreaking, from classic to modern.</description><pubDate>Sat, 02 May 2026 13:00:00 GMT</pubDate><category>History</category><category>Hacking</category><category>Telecom</category></item><item><title>CVE-2024-29041 only works on Safari?</title><link>https://guisso.dev/en/blog/cve-2024-29041-browser-parsers/</link><guid isPermaLink="true">https://guisso.dev/en/blog/cve-2024-29041-browser-parsers/</guid><description>Digging into the Chromium and Firefox source code to understand why the payload navigates to the malicious host on Safari but not on other browsers.</description><pubDate>Mon, 02 Mar 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Browser</category><category>Node.js</category></item><item><title>Express.js Open Redirect</title><link>https://guisso.dev/en/blog/cve-2024-29041-express-open-redirect/</link><guid isPermaLink="true">https://guisso.dev/en/blog/cve-2024-29041-express-open-redirect/</guid><description>How a backslash in a URL bypasses allowlists and fools the browser. A full breakdown of CVE-2024-29041 in Express.js with an interactive demo.</description><pubDate>Thu, 26 Feb 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Node.js</category></item><item><title>OWASP Top 10 Update</title><link>https://guisso.dev/en/blog/owasp-top10-2025-details/</link><guid isPermaLink="true">https://guisso.dev/en/blog/owasp-top10-2025-details/</guid><description>Top 10:2025 is not just a list. It reflects how misconfigurations, supply chain, exception handling, and operational failures are breaking real businesses.</description><pubDate>Tue, 10 Feb 2026 15:00:00 GMT</pubDate><category>owasp</category><category>top10</category><category>appsec</category></item><item><title>Cmd+K for the IA Terminal</title><link>https://guisso.dev/en/blog/terminal-cmd-k/</link><guid isPermaLink="true">https://guisso.dev/en/blog/terminal-cmd-k/</guid><description>How to bring Cursor-style Cmd+K to any shell using an AI CLI as a suggester only.</description><pubDate>Thu, 18 Dec 2025 21:04:02 GMT</pubDate><category>ai</category><category>shell</category><category>zsh</category></item><item><title>Open source site analytics</title><link>https://guisso.dev/en/blog/tianji-2025/</link><guid isPermaLink="true">https://guisso.dev/en/blog/tianji-2025/</guid><description>What I learned from self-hosting Tianji: PV/UV without cookies, campaigns, and reliability lessons.</description><pubDate>Sat, 06 Dec 2025 12:00:00 GMT</pubDate><category>analytics</category><category>privacy</category><category>self-hosted</category></item><item><title>Explorable Explanations</title><link>https://guisso.dev/en/blog/explorable-explanations-infoviz/</link><guid isPermaLink="true">https://guisso.dev/en/blog/explorable-explanations-infoviz/</guid><description>A curated list of interactive articles with animations, simulations, and visualizations that make complex topics visual, intuitive, and even fun to learn.</description><pubDate>Sat, 01 Nov 2025 13:00:00 GMT</pubDate><category>InfoViz</category><category>DataViz</category><category>Explorable Explanations</category><category>Education</category><category>Interactivity</category></item><item><title>Cursor Rules and Secure Code Review</title><link>https://guisso.dev/en/blog/secure-review-cursor-rules/</link><guid isPermaLink="true">https://guisso.dev/en/blog/secure-review-cursor-rules/</guid><description>How to use Cursor Rules and checklists adapted to the project context to optimize security reviews in modern applications.</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><category>security</category><category>code-review&quot;</category><category>cursor</category><category>appsec</category></item><item><title>Top 5 Rust Vulnerabilities Created with AI</title><link>https://guisso.dev/en/blog/top-5-rust/</link><guid isPermaLink="true">https://guisso.dev/en/blog/top-5-rust/</guid><description>Summary of the 5 most common vulnerabilities in Rust applications, generated with AI support and based on RustSec data.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><category>rust</category><category>security</category><category>devsecops</category><category>appsec</category></item><item><title>Git Config by Core Devs</title><link>https://guisso.dev/en/blog/git-config-core-devs/</link><guid isPermaLink="true">https://guisso.dev/en/blog/git-config-core-devs/</guid><description>How core Git developers configure their defaults.</description><pubDate>Wed, 26 Feb 2025 13:42:45 GMT</pubDate><category>git</category><category>devtools</category></item><item><title>Avante.nvim + 1Password</title><link>https://guisso.dev/en/blog/avante-nvim-op/</link><guid isPermaLink="true">https://guisso.dev/en/blog/avante-nvim-op/</guid><description>Integrating Avante.nvim with 1Password.</description><pubDate>Tue, 18 Feb 2025 13:42:45 GMT</pubDate><category>vim</category><category>1password</category><category>ai</category></item><item><title>Creating KPIs for an AppSec Program</title><link>https://guisso.dev/en/blog/appsec-kpi/</link><guid isPermaLink="true">https://guisso.dev/en/blog/appsec-kpi/</guid><description>I share here my experiences and learnings about creating KPIs for application security, without magic formulas, but with practical insights that can help other professionals in the field.</description><pubDate>Thu, 30 Jan 2025 00:00:00 GMT</pubDate><category>security</category><category>KPI</category><category>appsec</category></item><item><title>Security for Developers</title><link>https://guisso.dev/en/blog/sec-dev-book/</link><guid isPermaLink="true">https://guisso.dev/en/blog/sec-dev-book/</guid><description>In 2020, I started developing a book about security for developers, inspired by other authors and aiming to help the community naturally incorporate security into the daily development workflow.</description><pubDate>Sun, 24 Nov 2024 13:44:55 GMT</pubDate><category>security</category><category>book</category><category>devsec</category><category>appsec</category></item><item><title>eBPF in Action</title><link>https://guisso.dev/en/blog/ebpf-and-security/</link><guid isPermaLink="true">https://guisso.dev/en/blog/ebpf-and-security/</guid><description>In this post, we’ll explore what eBPF is, why it’s ideal for Kubernetes clusters, and how it powers security and observability tools in DevOps.</description><pubDate>Fri, 08 Nov 2024 17:12:56 GMT</pubDate><category>ebpf</category><category>security</category><category>devsecops</category><category>k8s</category><category>kubernetes</category></item><item><title>Threat Modeling Express: a fast start</title><link>https://guisso.dev/en/blog/threat-modeling-intro/</link><guid isPermaLink="true">https://guisso.dev/en/blog/threat-modeling-intro/</guid><description>How to engage the team, map critical assets, and ship controls quickly with Threat Modeling Express.</description><pubDate>Sat, 28 Sep 2024 10:29:47 GMT</pubDate><category>Threat Modeling</category><category>Security</category><category>DevSecOps</category></item><item><title>Misconfiguration Vulnerabilities in Reverse Proxies: A Comprehensive Guide</title><link>https://guisso.dev/en/blog/x-forwarded-for/</link><guid isPermaLink="true">https://guisso.dev/en/blog/x-forwarded-for/</guid><description>One of the technologies revolutionizing various markets that you need to know.</description><pubDate>Mon, 02 Sep 2024 13:44:55 GMT</pubDate><category>reverse proxy</category><category>X-Forwarded-For</category><category>X-Real-IP</category><category>NGINX</category><category>Apache</category><category>Kong</category><category>Apigee</category><category>misconfiguration</category></item><item><title>Proxmox and Homelab</title><link>https://guisso.dev/en/blog/proxmox-debian-day/</link><guid isPermaLink="true">https://guisso.dev/en/blog/proxmox-debian-day/</guid><description>How I Transformed a Mini PC into a Respectable Server</description><pubDate>Sat, 17 Aug 2024 13:42:45 GMT</pubDate><category>proxmox</category><category>debian</category><category>adguard</category><category>tailscale</category><category>homelab</category></item><item><title>Python Injection</title><link>https://guisso.dev/en/blog/python-injection/</link><guid isPermaLink="true">https://guisso.dev/en/blog/python-injection/</guid><description>Demonstration of a Telegram bot made in Python with injection vulnerability</description><pubDate>Sat, 23 Mar 2024 13:42:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>python</category><category>injection</category><category>en</category></item><item><title>Devsec Links #10</title><link>https://guisso.dev/en/blog/devsec-links-2/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-2/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Fri, 01 Dec 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>secrets</category><category>ci/cd</category><category>chatgpt</category><category>copilot</category></item><item><title>Devsec Links #09</title><link>https://guisso.dev/en/blog/devsec-links-10/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-10/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Wed, 01 Nov 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>oauth</category><category>postman</category><category>okta</category><category>git</category></item><item><title>Devsec Links #08</title><link>https://guisso.dev/en/blog/devsec-links-9/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-9/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Sun, 01 Oct 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>pypi</category><category>npm</category><category>openapi</category><category>api</category><category>imds</category></item><item><title>Devsec Links #07</title><link>https://guisso.dev/en/blog/devsec-links-8/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-8/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Fri, 01 Sep 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>gcp</category><category>defcon</category><category>ci/cd</category><category>secrets</category></item><item><title>Devsec Links #06</title><link>https://guisso.dev/en/blog/devsec-links-7/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-7/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Tue, 01 Aug 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>slsa</category><category>csrf</category><category>cors</category><category>api</category><category>csp</category></item><item><title>Devsec Links #05</title><link>https://guisso.dev/en/blog/devsec-links-6/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-6/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Sat, 01 Jul 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>slsa</category><category>supply chain</category><category>api</category><category>auth</category><category>terraform</category></item><item><title>Devsec Links #04</title><link>https://guisso.dev/en/blog/devsec-links-5/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-5/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Thu, 01 Jun 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>keycloak</category><category>gcp</category><category>s3</category><category>redos</category><category>ransomware</category></item><item><title>Devsec Links #03</title><link>https://guisso.dev/en/blog/devsec-links-4/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-4/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Mon, 01 May 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>golang</category><category>oidc</category><category>lambda</category><category>redos</category></item><item><title>Devsec Links #02</title><link>https://guisso.dev/en/blog/devsec-links-3/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-3/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Sat, 01 Apr 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>oauth</category><category>oidc</category><category>passwordless</category><category>iam</category><category>terraform</category></item><item><title>Devsec Links #01</title><link>https://guisso.dev/en/blog/devsec-links-1/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-1/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Wed, 01 Mar 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>chatgpt</category><category>api</category><category>cors</category><category>tls</category><category>git</category><category>secrets</category></item><item><title>Basic Recon Automation Using Github Actions</title><link>https://guisso.dev/en/blog/github-actions-recon/</link><guid isPermaLink="true">https://guisso.dev/en/blog/github-actions-recon/</guid><description>Demonstration of how to use Github Actions to automate a Recon</description><pubDate>Wed, 16 Mar 2022 03:00:46 GMT</pubDate><category>owasp</category><category>appsec</category><category>recon</category><category>en</category><category>amass</category><category>naabu</category><category>nuclei</category></item><item><title>Hacktoberfest Owasp</title><link>https://guisso.dev/en/blog/hacktoberfest-owasp/</link><guid isPermaLink="true">https://guisso.dev/en/blog/hacktoberfest-owasp/</guid><description>Quick guide to contribute to OWASP projects during Hacktoberfest and secure your PRs.</description><pubDate>Sat, 05 Oct 2019 14:26:27 GMT</pubDate><category>owasp</category><category>appsec</category><category>hacktoberfest</category></item><item><title>Getting to Know OWASP</title><link>https://guisso.dev/en/blog/conhecendo-a-owasp/</link><guid isPermaLink="true">https://guisso.dev/en/blog/conhecendo-a-owasp/</guid><description>A brief introduction to OWASP and its projects</description><pubDate>Wed, 20 Mar 2019 23:42:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>en</category></item><item><title>Writing Talks</title><link>https://guisso.dev/en/blog/escrevendo-artigos-e-palestras/</link><guid isPermaLink="true">https://guisso.dev/en/blog/escrevendo-artigos-e-palestras/</guid><description>Tips on structuring talks and turning them into articles.</description><pubDate>Fri, 22 Feb 2019 23:42:45 GMT</pubDate><category>storytelling</category><category>communication</category><category>career</category></item><item><title>Unraveling Blockchain</title><link>https://guisso.dev/en/blog/desvendando-o-blockchain/</link><guid isPermaLink="true">https://guisso.dev/en/blog/desvendando-o-blockchain/</guid><description>One of the technologies revolutionizing various markets that you need to know.</description><pubDate>Sat, 01 Sep 2018 23:42:45 GMT</pubDate><category>blockchain</category><category>bitcoin</category></item></channel></rss>