Application Security · Vulnerability Research · Security Tooling

Signal what matters.
Ignore the rest.

Practical research on how software breaks—and how to build it safer.

By Paolo Perego, Product Security Engineer and open-source security tooling builder.

Featured

Is Your Product Security Engineer Going to Be Replaced?

AI will automate a significant part of Product Security work, but it will not eliminate the need for security engineers. The real shift is from scanner-driven vulnerability management toward architecture, exploitability, mitigation design, secure tooling, and engineering guardrails.

Read insight

Editorial focus

Where software and security meet

Security Research

Deep analysis of vulnerabilities, exploitability and real attack surfaces.

Explore this area

Secure Software Engineering

Code review, threat modeling, secure design and practical engineering guardrails.

Explore this area

Security Tooling

Open-source tools that reduce noise and turn findings into actionable signal.

Explore this area

Python · security findings analysis

Signal Engine

Normalizes, deduplicates, clusters, and scores findings from multiple security tools to surface actionable risk.

View project

Source-code security scanner

dr_source

A source-code analysis tool whose results can be ingested and normalized by Signal Engine.

View project

Python · web application testing

Nightcrawler-mitm

A mitmproxy-based research tool for scoped crawling, passive analysis, and focused active security checks.

View project

Ruby · static analysis

Dawnscanner

A source-code security scanner for Ruby web applications, with checks for vulnerable dependencies and unsafe code patterns.

View project

About the author

Security work grounded in engineering.

Paolo Perego works at the intersection of software engineering and security. He reviews code, researches vulnerabilities and builds open-source tools that help engineering teams separate meaningful risk from security noise.