Hi there π
I'm Paolo, a senior application security engineer. After some time spent doing penetration tests, I'm now focused on security code reviews and software architectural audit for Kong. I love writing code and applying TDD and BDD with secure bonding principle and I wrote also a static code analyzer for ruby written applications, dawnscanner.
- NGINX PoolSlip & NGINX Rift: When the Internetβs Favorite Reverse Proxy Turns Against Itself
- Signal Engine 0.3.0: From Raw Findings to Real Signal
- Soak: Deep-Tissue Static Analysis as an Execution Layer
- Aggregating Semgrep Results: Top Rules, Files, and Clusters (MVP Demo)
- Why Most Security Findings Are Misunderstood



