Hi, I'm
Gianluca Caruso
I try to take cybersecurity out of the slides and into real things: code, pipelines, processes and all the places where "we'll fix it later" becomes a problem. This is where I keep notes on security,development and the automations I use in the field. New around here? Check out What I do.
Recent notes

Why my security blog looks like a chalkboard
In an industry that dresses in dark blue and padlocks, I picked markers and chalk. It's not a provocation, it's the concept.

LLM guardrails: defending AI apps without fooling yourself
Whitelists, semantic filters and LLM-as-a-judge each solve a different problem. None of them alone is enough.

Blind command injection: automating the exploit with Nuclei
No direct feedback from the server doesn't mean no feedback at all. A timing attack turns silence into a side channel.