<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss.xsl" type="text/xsl"?><rss version="2.0"><channel><title>guisso.dev</title><description>Engineering &amp; Security</description><link>https://guisso.dev/</link><language>pt-BR</language><homeLink>/</homeLink><item><title>CVE-2024-29041 só funciona no Safari?</title><link>https://guisso.dev/blog/cve-2024-29041-browser-parsers/</link><guid isPermaLink="true">https://guisso.dev/blog/cve-2024-29041-browser-parsers/</guid><description>Indo a fundo no código-fonte do Chromium e do Firefox para entender por que o payload enquanto o Safari navega para o host malicioso.</description><pubDate>Mon, 02 Mar 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Browser</category><category>Node.js</category></item><item><title>Express.js Open Redirect</title><link>https://guisso.dev/blog/cve-2024-29041-express-open-redirect/</link><guid isPermaLink="true">https://guisso.dev/blog/cve-2024-29041-express-open-redirect/</guid><description>Como uma barra invertida em uma URL bypassa allowlists e engana o browser. Análise completa do CVE-2024-29041 no Express.js com demo interativo.</description><pubDate>Thu, 26 Feb 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Node.js</category></item><item><title>Atualização OWASP Top 10</title><link>https://guisso.dev/blog/owasp-top10-2025-details/</link><guid isPermaLink="true">https://guisso.dev/blog/owasp-top10-2025-details/</guid><description>O Top 10:2025 não é só uma lista: é um reflexo do mercado sobre misconfig, supply chain, exceções e o que realmente quebra negócios.</description><pubDate>Tue, 10 Feb 2026 15:00:00 GMT</pubDate><category>owasp</category><category>top10</category><category>appsec</category></item><item><title>Cmd+K para o Terminal com IA</title><link>https://guisso.dev/blog/terminal-cmd-k/</link><guid isPermaLink="true">https://guisso.dev/blog/terminal-cmd-k/</guid><description>Como trazer o fluxo Cmd+K do Cursor para qualquer shell usando um CLI de IA apenas como sugeridor.</description><pubDate>Thu, 18 Dec 2025 21:04:02 GMT</pubDate><category>ai</category><category>shell</category><category>zsh</category></item><item><title>Site analytics open source</title><link>https://guisso.dev/blog/tianji-2025/</link><guid isPermaLink="true">https://guisso.dev/blog/tianji-2025/</guid><description>O que aprendi com o Tianji self-hosted: PV/UV sem cookies, campanhas e lições de confiabilidade.</description><pubDate>Sat, 06 Dec 2025 12:00:00 GMT</pubDate><category>analytics</category><category>privacy</category><category>self-hosted</category></item><item><title>Explorable Explanations</title><link>https://guisso.dev/blog/explorable-explanations-infoviz/</link><guid isPermaLink="true">https://guisso.dev/blog/explorable-explanations-infoviz/</guid><description>Uma curadoria de artigos interativos com animações, simulações e visualizações que transformam assuntos complexos em algo visual, intuitivo e até divertido de aprender.</description><pubDate>Sat, 01 Nov 2025 13:00:00 GMT</pubDate><category>InfoViz</category><category>DataViz</category><category>Explorable Explanations</category><category>Educação</category><category>Interatividade</category></item><item><title>Cursor Rules para Secure Code Review</title><link>https://guisso.dev/blog/secure-review-cursor-rules/</link><guid isPermaLink="true">https://guisso.dev/blog/secure-review-cursor-rules/</guid><description>Como utilizar Cursor Rules e checklists adaptados ao contexto do projeto para otimizar revisões de segurança em aplicações modernas.</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><category>security</category><category>code-review</category><category>cursor</category><category>appsec</category></item><item><title>CodeQL vs Joern</title><link>https://guisso.dev/blog/codeql-joern/</link><guid isPermaLink="true">https://guisso.dev/blog/codeql-joern/</guid><description>Uma comparação técnica detalhada entre as ferramentas de análise estática de código CodeQL e Joern, abordando funcionamento interno, linguagens suportadas, desempenho, usabilidade e integração com CI/CD.</description><pubDate>Wed, 20 Aug 2025 00:00:00 GMT</pubDate><category>security</category><category>codeql</category><category>joern</category><category>sast</category></item><item><title>Top 5 Vulnerabilidades em Rust</title><link>https://guisso.dev/blog/top-5-rust/</link><guid isPermaLink="true">https://guisso.dev/blog/top-5-rust/</guid><description>Resumo das 5 vulnerabilidades mais comuns em aplicações Rust, gerado com apoio de IA e baseadas em dados do RustSec.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><category>security</category><category>rust</category><category>devsecops</category><category>appsec</category></item><item><title>Caso Event-Stream</title><link>https://guisso.dev/blog/podcast-codigo-suspeito-1/</link><guid isPermaLink="true">https://guisso.dev/blog/podcast-codigo-suspeito-1/</guid><description>Entenda o ataque que comprometeu um dos pacotes mais populares do ecossistema Node.js.</description><pubDate>Mon, 12 May 2025 00:00:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>npm</category></item><item><title>CI/CDon&apos;t Lab</title><link>https://guisso.dev/blog/cicdont/</link><guid isPermaLink="true">https://guisso.dev/blog/cicdont/</guid><description>Explorando falhas em pipelines CI/CD usando GitLab e AWS.</description><pubDate>Thu, 10 Apr 2025 00:00:00 GMT</pubDate><category>security</category><category>cicd</category><category>aws</category></item><item><title>Config Git dos Core Devs</title><link>https://guisso.dev/blog/git-config-core-devs/</link><guid isPermaLink="true">https://guisso.dev/blog/git-config-core-devs/</guid><description>Uma analise das configuracoes recomendadas pelo time core do Git.</description><pubDate>Wed, 26 Feb 2025 13:42:45 GMT</pubDate><category>git</category><category>devtools</category></item><item><title>Avante.nvim + 1Password</title><link>https://guisso.dev/blog/avante-nvim-op/</link><guid isPermaLink="true">https://guisso.dev/blog/avante-nvim-op/</guid><description>Integrando o Avante.nvim com o 1Password.</description><pubDate>Tue, 18 Feb 2025 13:42:45 GMT</pubDate><category>vim</category><category>1password</category><category>ai</category></item><item><title>Criando KPIs para um Programa de AppSec</title><link>https://guisso.dev/blog/appsec-kpi/</link><guid isPermaLink="true">https://guisso.dev/blog/appsec-kpi/</guid><description>Compartilho aqui minhas experiências e aprendizados sobre a criação de KPIs para segurança de aplicações, sem fórmulas mágicas, mas com insights práticos que podem ajudar outros profissionais na área.</description><pubDate>Thu, 30 Jan 2025 00:00:00 GMT</pubDate><category>security</category><category>KPIs</category><category>appsec</category></item><item><title>Networking e Carreira em Eventos Tech</title><link>https://guisso.dev/blog/networking-events/</link><guid isPermaLink="true">https://guisso.dev/blog/networking-events/</guid><description>Dicas práticas para aproveitar eventos como a H2HC, expandir sua rede de contatos e abrir novas portas na sua carreira.</description><pubDate>Mon, 02 Dec 2024 00:00:00 GMT</pubDate><category>networking</category><category>carreira</category><category>h2hc</category></item><item><title>Livro Segurança para Pessoas Desenvolvedores</title><link>https://guisso.dev/blog/sec-dev-book/</link><guid isPermaLink="true">https://guisso.dev/blog/sec-dev-book/</guid><description>Em 2020, comecei a desenvolver um livro sobre segurança para desenvolvedores, inspirado em outros autores e buscando ajudar a comunidade a incorporar a segurança de forma natural no dia a dia de desenvolvimento.</description><pubDate>Sun, 24 Nov 2024 13:44:55 GMT</pubDate><category>security</category><category>book</category><category>devsec</category><category>appsec</category></item><item><title>Escrevendo com MDX</title><link>https://guisso.dev/blog/escrevendo-com-mdx/</link><guid isPermaLink="true">https://guisso.dev/blog/escrevendo-com-mdx/</guid><description>Combine Markdown e componentes Astro para posts mais ricos.</description><pubDate>Fri, 22 Nov 2024 00:00:00 GMT</pubDate><updated>Fri, 22 Nov 2024 00:00:00 GMT</updated><category>MDX</category><category>Conteúdo</category></item><item><title>eBPF em Ação</title><link>https://guisso.dev/blog/ebpf-and-security/</link><guid isPermaLink="true">https://guisso.dev/blog/ebpf-and-security/</guid><description>Neste post, vamos explorar o que é o eBPF, por que ele é ideal para clusters Kubernetes e como ele impulsiona ferramentas de segurança e observabilidade no DevOps.</description><pubDate>Fri, 08 Nov 2024 17:12:56 GMT</pubDate><category>ebpf</category><category>security</category><category>devsecops</category><category>k8s</category><category>kubernetes</category></item><item><title>Threat Modeling Express: guia prático</title><link>https://guisso.dev/blog/threat-modeling-intro/</link><guid isPermaLink="true">https://guisso.dev/blog/threat-modeling-intro/</guid><description>Como engajar o time, mapear ativos críticos e aplicar controles rápidos com Threat Modeling Express.</description><pubDate>Sat, 28 Sep 2024 10:29:47 GMT</pubDate><category>Threat Modeling</category><category>Segurança</category><category>DevSecOps</category></item><item><title>Checklist para Organizar Meetup</title><link>https://guisso.dev/blog/meetup-checklist/</link><guid isPermaLink="true">https://guisso.dev/blog/meetup-checklist/</guid><description>Os meetups de tecnologia são uma parte vital do ecossistema tech, oferecendo oportunidades únicas para aprendizado, networking e crescimento profissional. Seja você um profissional de TI experiente ou um estudante, organizar um meetup pode parecer desafiador, mas é mais acessível do que você imagina. Este guia vai te mostrar como é fácil criar esse tipo de evento quando tudo é organizado com antecedência.</description><pubDate>Tue, 17 Sep 2024 14:03:17 GMT</pubDate><category>meetup</category><category>community</category><category>events</category></item><item><title>Vulnerabilidades de Configuração Incorreta em Proxies Reversos</title><link>https://guisso.dev/blog/x-forwarded-for/</link><guid isPermaLink="true">https://guisso.dev/blog/x-forwarded-for/</guid><description>Reverse proxies are essential for managing client-server interactions, but improper handling of headers like X-Forwarded-For and X-Real-IP can introduce significant security vulnerabilities.</description><pubDate>Mon, 02 Sep 2024 13:44:55 GMT</pubDate><category>reverse proxy</category><category>X-Forwarded-For</category><category>X-Real-IP</category><category>security vulnerabilities</category><category>header management</category><category>network security</category><category>NGINX</category><category>Apache</category><category>Kong</category><category>Apigee</category><category>load balancer</category><category>application security</category><category>misconfiguration</category><category>API security</category><category>Forwarded header</category><category>security best practices</category></item><item><title>Proxmox e Homelab</title><link>https://guisso.dev/blog/proxmox-debian-day/</link><guid isPermaLink="true">https://guisso.dev/blog/proxmox-debian-day/</guid><description>Como transformei um mini PC em um servidor de homelab completo usando Proxmox.</description><pubDate>Sat, 17 Aug 2024 00:00:00 GMT</pubDate><category>Homelab</category><category>Proxmox</category><category>Debian</category></item><item><title>Markdown Style Guide</title><link>https://guisso.dev/blog/markdown-style-guide/</link><guid isPermaLink="true">https://guisso.dev/blog/markdown-style-guide/</guid><description>Here is a sample of some basic Markdown syntax that can be used when writing Markdown content in Astro.</description><pubDate>Wed, 19 Jun 2024 00:00:00 GMT</pubDate><category>Markdown</category><category>Docs</category></item><item><title>Using MDX</title><link>https://guisso.dev/blog/using-mdx/</link><guid isPermaLink="true">https://guisso.dev/blog/using-mdx/</guid><description>Lorem ipsum dolor sit amet</description><pubDate>Sat, 01 Jun 2024 00:00:00 GMT</pubDate><category>MDX</category><category>Playground</category></item><item><title>Python Injection</title><link>https://guisso.dev/blog/python-injection/</link><guid isPermaLink="true">https://guisso.dev/blog/python-injection/</guid><description>Demostração de um bot para telegram feito em python com vulnerabilidade de injection</description><pubDate>Sat, 23 Mar 2024 13:42:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>python</category><category>injection</category><category>pt-br</category></item><item><title>Devsec Links #10</title><link>https://guisso.dev/blog/devsec-links-2/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-2/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Fri, 01 Dec 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>secrets</category><category>ci/cd</category><category>chatgpt</category><category>copilot</category></item><item><title>Devsec Links #09</title><link>https://guisso.dev/blog/devsec-links-10/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-10/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Wed, 01 Nov 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>oauth</category><category>postman</category><category>okta</category><category>git</category></item><item><title>Devsec Links #08</title><link>https://guisso.dev/blog/devsec-links-9/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-9/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Sun, 01 Oct 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>pypi</category><category>npm</category><category>openapi</category><category>api</category><category>imds</category></item><item><title>Devsec Links #07</title><link>https://guisso.dev/blog/devsec-links-8/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-8/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Fri, 01 Sep 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>gcp</category><category>defcon</category><category>ci/cd</category><category>secrets</category></item><item><title>Devsec Links #06</title><link>https://guisso.dev/blog/devsec-links-7/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-7/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Tue, 01 Aug 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>slsa</category><category>csrf</category><category>cors</category><category>api</category><category>csp</category></item><item><title>Devsec Links #05</title><link>https://guisso.dev/blog/devsec-links-6/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-6/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Sat, 01 Jul 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>slsa</category><category>supply chain</category><category>api</category><category>auth</category><category>terraform</category></item><item><title>Devsec Links #04</title><link>https://guisso.dev/blog/devsec-links-5/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-5/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Thu, 01 Jun 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>keycloack</category><category>gcp</category><category>s3</category><category>redos</category><category>ransomware</category></item><item><title>Devsec Links #03</title><link>https://guisso.dev/blog/devsec-links-4/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-4/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Mon, 01 May 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>golang</category><category>oidc</category><category>lambda</category><category>redos</category></item><item><title>Devsec Links #02</title><link>https://guisso.dev/blog/devsec-links-3/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-3/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Sat, 01 Apr 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>oauth</category><category>oidc</category><category>passwordless</category><category>iam</category><category>terraform</category></item><item><title>Devsec Links #01</title><link>https://guisso.dev/blog/devsec-links-1/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-1/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Wed, 01 Mar 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>chagpt</category><category>api</category><category>cors</category><category>tls</category><category>git</category><category>secrets</category></item><item><title>Third post</title><link>https://guisso.dev/blog/third-post/</link><guid isPermaLink="true">https://guisso.dev/blog/third-post/</guid><description>Lorem ipsum dolor sit amet</description><pubDate>Fri, 22 Jul 2022 00:00:00 GMT</pubDate><category>Playlists</category><category>Lifestyle</category></item><item><title>Second post</title><link>https://guisso.dev/blog/second-post/</link><guid isPermaLink="true">https://guisso.dev/blog/second-post/</guid><description>Lorem ipsum dolor sit amet</description><pubDate>Fri, 15 Jul 2022 00:00:00 GMT</pubDate><category>Home Lab</category><category>Infra</category></item><item><title>First post</title><link>https://guisso.dev/blog/first-post/</link><guid isPermaLink="true">https://guisso.dev/blog/first-post/</guid><description>Lorem ipsum dolor sit amet</description><pubDate>Fri, 08 Jul 2022 00:00:00 GMT</pubDate><category>AppSec</category><category>Reflexões</category></item><item><title>Automação básica de Recon utilizando o Github Actions</title><link>https://guisso.dev/blog/github-actions-recon/</link><guid isPermaLink="true">https://guisso.dev/blog/github-actions-recon/</guid><description>Demostração de como utilizar o Github Actions para automatizar um Recon</description><pubDate>Wed, 16 Mar 2022 03:00:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>recon</category><category>pt-br</category><category>amass</category><category>naabu</category><category>nuclei</category></item><item><title>Hacktoberfest Owasp</title><link>https://guisso.dev/blog/hacktoberfest-owasp/</link><guid isPermaLink="true">https://guisso.dev/blog/hacktoberfest-owasp/</guid><description>Guia rápido para contribuir com projetos OWASP no Hacktoberfest e garantir seus PRs.</description><pubDate>Sat, 05 Oct 2019 14:26:27 GMT</pubDate><category>owasp</category><category>appsec</category><category>hacktoberfest</category><category>pt-br</category></item><item><title>Conhecendo a OWASP</title><link>https://guisso.dev/blog/conhecendo-a-owasp/</link><guid isPermaLink="true">https://guisso.dev/blog/conhecendo-a-owasp/</guid><description>Uma breve apresentação da OWASP e seus projetos</description><pubDate>Wed, 20 Mar 2019 23:42:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>pt-br</category></item><item><title>Artigos e Palestras</title><link>https://guisso.dev/blog/escrevendo-artigos-e-palestras/</link><guid isPermaLink="true">https://guisso.dev/blog/escrevendo-artigos-e-palestras/</guid><description>Algumas dicas de como montar uma boa palestra e de quebra já escrever um artigo.</description><pubDate>Fri, 22 Feb 2019 23:42:45 GMT</pubDate><category>storytelling</category><category>comunicacao</category><category>carreira</category></item><item><title>Desvendando Blockchain</title><link>https://guisso.dev/blog/desvendando-o-blockchain/</link><guid isPermaLink="true">https://guisso.dev/blog/desvendando-o-blockchain/</guid><description>Uma das tecnologias que estão revolucionando varios mercados que você precisa conhecer.</description><pubDate>Sat, 01 Sep 2018 23:42:45 GMT</pubDate><category>blockchain</category><category>bitcoin</category></item></channel></rss>