<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/tag-feed.xsl" type="text/xsl"?><rss version="2.0"><channel><title>guisso.dev - security</title><description>This page is also an RSS feed. Subscribe to follow only the posts tagged security.</description><link>https://guisso.dev/en/</link><homeLink>/en/</homeLink><item><title>CVE-2024-29041 only works on Safari?</title><link>https://guisso.dev/en/blog/cve-2024-29041-browser-parsers/</link><guid isPermaLink="true">https://guisso.dev/en/blog/cve-2024-29041-browser-parsers/</guid><description>Digging into the Chromium and Firefox source code to understand why the payload navigates to the malicious host on Safari but not on other browsers.</description><pubDate>Mon, 02 Mar 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Browser</category><category>Node.js</category></item><item><title>Express.js Open Redirect</title><link>https://guisso.dev/en/blog/cve-2024-29041-express-open-redirect/</link><guid isPermaLink="true">https://guisso.dev/en/blog/cve-2024-29041-express-open-redirect/</guid><description>How a backslash in a URL bypasses allowlists and fools the browser. A full breakdown of CVE-2024-29041 in Express.js with an interactive demo.</description><pubDate>Thu, 26 Feb 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Node.js</category></item><item><title>Cursor Rules and Secure Code Review</title><link>https://guisso.dev/en/blog/secure-review-cursor-rules/</link><guid isPermaLink="true">https://guisso.dev/en/blog/secure-review-cursor-rules/</guid><description>How to use Cursor Rules and checklists adapted to the project context to optimize security reviews in modern applications.</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><category>security</category><category>code-review&quot;</category><category>cursor</category><category>appsec</category></item><item><title>Top 5 Rust Vulnerabilities Created with AI</title><link>https://guisso.dev/en/blog/top-5-rust/</link><guid isPermaLink="true">https://guisso.dev/en/blog/top-5-rust/</guid><description>Summary of the 5 most common vulnerabilities in Rust applications, generated with AI support and based on RustSec data.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><category>rust</category><category>security</category><category>devsecops</category><category>appsec</category></item><item><title>Creating KPIs for an AppSec Program</title><link>https://guisso.dev/en/blog/appsec-kpi/</link><guid isPermaLink="true">https://guisso.dev/en/blog/appsec-kpi/</guid><description>I share here my experiences and learnings about creating KPIs for application security, without magic formulas, but with practical insights that can help other professionals in the field.</description><pubDate>Thu, 30 Jan 2025 00:00:00 GMT</pubDate><category>security</category><category>KPI</category><category>appsec</category></item><item><title>Security for Developers</title><link>https://guisso.dev/en/blog/sec-dev-book/</link><guid isPermaLink="true">https://guisso.dev/en/blog/sec-dev-book/</guid><description>In 2020, I started developing a book about security for developers, inspired by other authors and aiming to help the community naturally incorporate security into the daily development workflow.</description><pubDate>Sun, 24 Nov 2024 13:44:55 GMT</pubDate><category>security</category><category>book</category><category>devsec</category><category>appsec</category></item><item><title>eBPF in Action</title><link>https://guisso.dev/en/blog/ebpf-and-security/</link><guid isPermaLink="true">https://guisso.dev/en/blog/ebpf-and-security/</guid><description>In this post, we’ll explore what eBPF is, why it’s ideal for Kubernetes clusters, and how it powers security and observability tools in DevOps.</description><pubDate>Fri, 08 Nov 2024 17:12:56 GMT</pubDate><category>ebpf</category><category>security</category><category>devsecops</category><category>k8s</category><category>kubernetes</category></item><item><title>Threat Modeling Express: a fast start</title><link>https://guisso.dev/en/blog/threat-modeling-intro/</link><guid isPermaLink="true">https://guisso.dev/en/blog/threat-modeling-intro/</guid><description>How to engage the team, map critical assets, and ship controls quickly with Threat Modeling Express.</description><pubDate>Sat, 28 Sep 2024 10:29:47 GMT</pubDate><category>Threat Modeling</category><category>Security</category><category>DevSecOps</category></item></channel></rss>