<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/tag-feed.xsl" type="text/xsl"?><rss version="2.0"><channel><title>guisso.dev - AppSec</title><description>This page is also an RSS feed. Subscribe to follow only the posts tagged AppSec.</description><link>https://guisso.dev/en/</link><homeLink>/en/</homeLink><item><title>CVE-2024-29041 only works on Safari?</title><link>https://guisso.dev/en/blog/cve-2024-29041-browser-parsers/</link><guid isPermaLink="true">https://guisso.dev/en/blog/cve-2024-29041-browser-parsers/</guid><description>Digging into the Chromium and Firefox source code to understand why the payload navigates to the malicious host on Safari but not on other browsers.</description><pubDate>Mon, 02 Mar 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Browser</category><category>Node.js</category></item><item><title>Express.js Open Redirect</title><link>https://guisso.dev/en/blog/cve-2024-29041-express-open-redirect/</link><guid isPermaLink="true">https://guisso.dev/en/blog/cve-2024-29041-express-open-redirect/</guid><description>How a backslash in a URL bypasses allowlists and fools the browser. A full breakdown of CVE-2024-29041 in Express.js with an interactive demo.</description><pubDate>Thu, 26 Feb 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Node.js</category></item><item><title>OWASP Top 10 Update</title><link>https://guisso.dev/en/blog/owasp-top10-2025-details/</link><guid isPermaLink="true">https://guisso.dev/en/blog/owasp-top10-2025-details/</guid><description>Top 10:2025 is not just a list. It reflects how misconfigurations, supply chain, exception handling, and operational failures are breaking real businesses.</description><pubDate>Tue, 10 Feb 2026 15:00:00 GMT</pubDate><category>owasp</category><category>top10</category><category>appsec</category></item><item><title>Cursor Rules and Secure Code Review</title><link>https://guisso.dev/en/blog/secure-review-cursor-rules/</link><guid isPermaLink="true">https://guisso.dev/en/blog/secure-review-cursor-rules/</guid><description>How to use Cursor Rules and checklists adapted to the project context to optimize security reviews in modern applications.</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><category>security</category><category>code-review&quot;</category><category>cursor</category><category>appsec</category></item><item><title>Top 5 Rust Vulnerabilities Created with AI</title><link>https://guisso.dev/en/blog/top-5-rust/</link><guid isPermaLink="true">https://guisso.dev/en/blog/top-5-rust/</guid><description>Summary of the 5 most common vulnerabilities in Rust applications, generated with AI support and based on RustSec data.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><category>rust</category><category>security</category><category>devsecops</category><category>appsec</category></item><item><title>Creating KPIs for an AppSec Program</title><link>https://guisso.dev/en/blog/appsec-kpi/</link><guid isPermaLink="true">https://guisso.dev/en/blog/appsec-kpi/</guid><description>I share here my experiences and learnings about creating KPIs for application security, without magic formulas, but with practical insights that can help other professionals in the field.</description><pubDate>Thu, 30 Jan 2025 00:00:00 GMT</pubDate><category>security</category><category>KPI</category><category>appsec</category></item><item><title>Security for Developers</title><link>https://guisso.dev/en/blog/sec-dev-book/</link><guid isPermaLink="true">https://guisso.dev/en/blog/sec-dev-book/</guid><description>In 2020, I started developing a book about security for developers, inspired by other authors and aiming to help the community naturally incorporate security into the daily development workflow.</description><pubDate>Sun, 24 Nov 2024 13:44:55 GMT</pubDate><category>security</category><category>book</category><category>devsec</category><category>appsec</category></item><item><title>Python Injection</title><link>https://guisso.dev/en/blog/python-injection/</link><guid isPermaLink="true">https://guisso.dev/en/blog/python-injection/</guid><description>Demonstration of a Telegram bot made in Python with injection vulnerability</description><pubDate>Sat, 23 Mar 2024 13:42:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>python</category><category>injection</category><category>en</category></item><item><title>Devsec Links #10</title><link>https://guisso.dev/en/blog/devsec-links-2/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-2/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Fri, 01 Dec 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>secrets</category><category>ci/cd</category><category>chatgpt</category><category>copilot</category></item><item><title>Devsec Links #09</title><link>https://guisso.dev/en/blog/devsec-links-10/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-10/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Wed, 01 Nov 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>oauth</category><category>postman</category><category>okta</category><category>git</category></item><item><title>Devsec Links #08</title><link>https://guisso.dev/en/blog/devsec-links-9/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-9/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Sun, 01 Oct 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>pypi</category><category>npm</category><category>openapi</category><category>api</category><category>imds</category></item><item><title>Devsec Links #07</title><link>https://guisso.dev/en/blog/devsec-links-8/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-8/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Fri, 01 Sep 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>gcp</category><category>defcon</category><category>ci/cd</category><category>secrets</category></item><item><title>Devsec Links #06</title><link>https://guisso.dev/en/blog/devsec-links-7/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-7/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Tue, 01 Aug 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>slsa</category><category>csrf</category><category>cors</category><category>api</category><category>csp</category></item><item><title>Devsec Links #05</title><link>https://guisso.dev/en/blog/devsec-links-6/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-6/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Sat, 01 Jul 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>slsa</category><category>supply chain</category><category>api</category><category>auth</category><category>terraform</category></item><item><title>Devsec Links #04</title><link>https://guisso.dev/en/blog/devsec-links-5/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-5/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Thu, 01 Jun 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>keycloak</category><category>gcp</category><category>s3</category><category>redos</category><category>ransomware</category></item><item><title>Devsec Links #03</title><link>https://guisso.dev/en/blog/devsec-links-4/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-4/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Mon, 01 May 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>golang</category><category>oidc</category><category>lambda</category><category>redos</category></item><item><title>Devsec Links #02</title><link>https://guisso.dev/en/blog/devsec-links-3/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-3/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Sat, 01 Apr 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>oauth</category><category>oidc</category><category>passwordless</category><category>iam</category><category>terraform</category></item><item><title>Devsec Links #01</title><link>https://guisso.dev/en/blog/devsec-links-1/</link><guid isPermaLink="true">https://guisso.dev/en/blog/devsec-links-1/</guid><description>Interesting links on the topic of secure development.</description><pubDate>Wed, 01 Mar 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>chatgpt</category><category>api</category><category>cors</category><category>tls</category><category>git</category><category>secrets</category></item><item><title>Basic Recon Automation Using Github Actions</title><link>https://guisso.dev/en/blog/github-actions-recon/</link><guid isPermaLink="true">https://guisso.dev/en/blog/github-actions-recon/</guid><description>Demonstration of how to use Github Actions to automate a Recon</description><pubDate>Wed, 16 Mar 2022 03:00:46 GMT</pubDate><category>owasp</category><category>appsec</category><category>recon</category><category>en</category><category>amass</category><category>naabu</category><category>nuclei</category></item><item><title>Hacktoberfest Owasp</title><link>https://guisso.dev/en/blog/hacktoberfest-owasp/</link><guid isPermaLink="true">https://guisso.dev/en/blog/hacktoberfest-owasp/</guid><description>Quick guide to contribute to OWASP projects during Hacktoberfest and secure your PRs.</description><pubDate>Sat, 05 Oct 2019 14:26:27 GMT</pubDate><category>owasp</category><category>appsec</category><category>hacktoberfest</category></item><item><title>Getting to Know OWASP</title><link>https://guisso.dev/en/blog/conhecendo-a-owasp/</link><guid isPermaLink="true">https://guisso.dev/en/blog/conhecendo-a-owasp/</guid><description>A brief introduction to OWASP and its projects</description><pubDate>Wed, 20 Mar 2019 23:42:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>en</category></item></channel></rss>