<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/tag-feed.xsl" type="text/xsl"?><rss version="2.0"><channel><title>guisso.dev - AppSec</title><description>O endereço desta página também é um RSS feed. Use no seu leitor favorito para seguir apenas meus posts sobre AppSec.</description><link>https://guisso.dev/</link><homeLink>/</homeLink><item><title>CVE-2024-29041 só funciona no Safari?</title><link>https://guisso.dev/blog/cve-2024-29041-browser-parsers/</link><guid isPermaLink="true">https://guisso.dev/blog/cve-2024-29041-browser-parsers/</guid><description>Indo a fundo no código-fonte do Chromium e do Firefox para entender por que o payload enquanto o Safari navega para o host malicioso.</description><pubDate>Mon, 02 Mar 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Browser</category><category>Node.js</category></item><item><title>Express.js Open Redirect</title><link>https://guisso.dev/blog/cve-2024-29041-express-open-redirect/</link><guid isPermaLink="true">https://guisso.dev/blog/cve-2024-29041-express-open-redirect/</guid><description>Como uma barra invertida em uma URL bypassa allowlists e engana o browser. Análise completa do CVE-2024-29041 no Express.js com demo interativo.</description><pubDate>Thu, 26 Feb 2026 13:00:00 GMT</pubDate><category>CVE</category><category>Express.js</category><category>AppSec</category><category>Security</category><category>Node.js</category></item><item><title>Atualização OWASP Top 10</title><link>https://guisso.dev/blog/owasp-top10-2025-details/</link><guid isPermaLink="true">https://guisso.dev/blog/owasp-top10-2025-details/</guid><description>O Top 10:2025 não é só uma lista: é um reflexo do mercado sobre misconfig, supply chain, exceções e o que realmente quebra negócios.</description><pubDate>Tue, 10 Feb 2026 15:00:00 GMT</pubDate><category>owasp</category><category>top10</category><category>appsec</category></item><item><title>Cursor Rules para Secure Code Review</title><link>https://guisso.dev/blog/secure-review-cursor-rules/</link><guid isPermaLink="true">https://guisso.dev/blog/secure-review-cursor-rules/</guid><description>Como utilizar Cursor Rules e checklists adaptados ao contexto do projeto para otimizar revisões de segurança em aplicações modernas.</description><pubDate>Tue, 26 Aug 2025 00:00:00 GMT</pubDate><category>security</category><category>code-review</category><category>cursor</category><category>appsec</category></item><item><title>Top 5 Vulnerabilidades em Rust</title><link>https://guisso.dev/blog/top-5-rust/</link><guid isPermaLink="true">https://guisso.dev/blog/top-5-rust/</guid><description>Resumo das 5 vulnerabilidades mais comuns em aplicações Rust, gerado com apoio de IA e baseadas em dados do RustSec.</description><pubDate>Tue, 10 Jun 2025 00:00:00 GMT</pubDate><category>security</category><category>rust</category><category>devsecops</category><category>appsec</category></item><item><title>Criando KPIs para um Programa de AppSec</title><link>https://guisso.dev/blog/appsec-kpi/</link><guid isPermaLink="true">https://guisso.dev/blog/appsec-kpi/</guid><description>Compartilho aqui minhas experiências e aprendizados sobre a criação de KPIs para segurança de aplicações, sem fórmulas mágicas, mas com insights práticos que podem ajudar outros profissionais na área.</description><pubDate>Thu, 30 Jan 2025 00:00:00 GMT</pubDate><category>security</category><category>KPIs</category><category>appsec</category></item><item><title>Livro Segurança para Pessoas Desenvolvedores</title><link>https://guisso.dev/blog/sec-dev-book/</link><guid isPermaLink="true">https://guisso.dev/blog/sec-dev-book/</guid><description>Em 2020, comecei a desenvolver um livro sobre segurança para desenvolvedores, inspirado em outros autores e buscando ajudar a comunidade a incorporar a segurança de forma natural no dia a dia de desenvolvimento.</description><pubDate>Sun, 24 Nov 2024 13:44:55 GMT</pubDate><category>security</category><category>book</category><category>devsec</category><category>appsec</category></item><item><title>Python Injection</title><link>https://guisso.dev/blog/python-injection/</link><guid isPermaLink="true">https://guisso.dev/blog/python-injection/</guid><description>Demostração de um bot para telegram feito em python com vulnerabilidade de injection</description><pubDate>Sat, 23 Mar 2024 13:42:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>python</category><category>injection</category><category>pt-br</category></item><item><title>Devsec Links #10</title><link>https://guisso.dev/blog/devsec-links-2/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-2/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Fri, 01 Dec 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>secrets</category><category>ci/cd</category><category>chatgpt</category><category>copilot</category></item><item><title>Devsec Links #09</title><link>https://guisso.dev/blog/devsec-links-10/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-10/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Wed, 01 Nov 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>oauth</category><category>postman</category><category>okta</category><category>git</category></item><item><title>Devsec Links #08</title><link>https://guisso.dev/blog/devsec-links-9/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-9/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Sun, 01 Oct 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>pypi</category><category>npm</category><category>openapi</category><category>api</category><category>imds</category></item><item><title>Devsec Links #07</title><link>https://guisso.dev/blog/devsec-links-8/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-8/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Fri, 01 Sep 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>gcp</category><category>defcon</category><category>ci/cd</category><category>secrets</category></item><item><title>Devsec Links #06</title><link>https://guisso.dev/blog/devsec-links-7/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-7/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Tue, 01 Aug 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>slsa</category><category>csrf</category><category>cors</category><category>api</category><category>csp</category></item><item><title>Devsec Links #05</title><link>https://guisso.dev/blog/devsec-links-6/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-6/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Sat, 01 Jul 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>slsa</category><category>supply chain</category><category>api</category><category>auth</category><category>terraform</category></item><item><title>Devsec Links #04</title><link>https://guisso.dev/blog/devsec-links-5/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-5/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Thu, 01 Jun 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>keycloack</category><category>gcp</category><category>s3</category><category>redos</category><category>ransomware</category></item><item><title>Devsec Links #03</title><link>https://guisso.dev/blog/devsec-links-4/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-4/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Mon, 01 May 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>golang</category><category>oidc</category><category>lambda</category><category>redos</category></item><item><title>Devsec Links #02</title><link>https://guisso.dev/blog/devsec-links-3/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-3/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Sat, 01 Apr 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>oauth</category><category>oidc</category><category>passwordless</category><category>iam</category><category>terraform</category></item><item><title>Devsec Links #01</title><link>https://guisso.dev/blog/devsec-links-1/</link><guid isPermaLink="true">https://guisso.dev/blog/devsec-links-1/</guid><description>Links interessantes no tema de desenvolvimento seguro.</description><pubDate>Wed, 01 Mar 2023 12:45:33 GMT</pubDate><category>DevSec</category><category>AppSec</category><category>Links</category><category>chagpt</category><category>api</category><category>cors</category><category>tls</category><category>git</category><category>secrets</category></item><item><title>First post</title><link>https://guisso.dev/blog/first-post/</link><guid isPermaLink="true">https://guisso.dev/blog/first-post/</guid><description>Lorem ipsum dolor sit amet</description><pubDate>Fri, 08 Jul 2022 00:00:00 GMT</pubDate><category>AppSec</category><category>Reflexões</category></item><item><title>Automação básica de Recon utilizando o Github Actions</title><link>https://guisso.dev/blog/github-actions-recon/</link><guid isPermaLink="true">https://guisso.dev/blog/github-actions-recon/</guid><description>Demostração de como utilizar o Github Actions para automatizar um Recon</description><pubDate>Wed, 16 Mar 2022 03:00:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>recon</category><category>pt-br</category><category>amass</category><category>naabu</category><category>nuclei</category></item><item><title>Hacktoberfest Owasp</title><link>https://guisso.dev/blog/hacktoberfest-owasp/</link><guid isPermaLink="true">https://guisso.dev/blog/hacktoberfest-owasp/</guid><description>Guia rápido para contribuir com projetos OWASP no Hacktoberfest e garantir seus PRs.</description><pubDate>Sat, 05 Oct 2019 14:26:27 GMT</pubDate><category>owasp</category><category>appsec</category><category>hacktoberfest</category><category>pt-br</category></item><item><title>Conhecendo a OWASP</title><link>https://guisso.dev/blog/conhecendo-a-owasp/</link><guid isPermaLink="true">https://guisso.dev/blog/conhecendo-a-owasp/</guid><description>Uma breve apresentação da OWASP e seus projetos</description><pubDate>Wed, 20 Mar 2019 23:42:45 GMT</pubDate><category>owasp</category><category>appsec</category><category>pt-br</category></item></channel></rss>