I read code, break assumptions and build open-source security tooling.
Code Review · Vulnerability Research · Static Analysis · Security Tooling
Security doesn't need more findings.
It needs better signal, better context and better engineering judgment.
I've spent more than two decades working where software engineering and security meet.
I like security when it gets close to the code: reviewing it, understanding how it can fail, validating vulnerabilities and building tools that help engineers make better security decisions.
My main interests are:
- 🔍 Application & Product Security
- 🧬 Security-focused code review
- 🎯 Vulnerability research
- 🌳 Static analysis and data-flow analysis
- 🛠️ Open-source security tooling
- 🤖 AI-assisted vulnerability research
- 🧠 Turning security noise into actionable signal
|
Follow untrusted data through real code. A multi-language static analysis engine focused on security-relevant data flows, inter-file taint tracking and contextual vulnerability analysis.
|
Turn security findings into signal. A security intelligence engine that normalizes, deduplicates, clusters and prioritizes findings from multiple security tools.
|
|
From suspicious traffic to validated findings. A mitmproxy-based security researcher's sidekick for passive analysis, targeted active testing, confidence scoring and reproducible PoCs.
|
Where my security tooling journey started. An open-source static analysis security scanner for Ruby web applications. Built years ago. Still one of the projects that best represents how I think about security: get close to the code and give developers useful information.
|
I'm particularly interested in the space between finding something suspicious and being able to say:
"Yes. This is actually a vulnerability, this is why it matters, and this is what we should do about it."
That means exploring areas such as:
- inter-procedural and inter-file source analysis
- vulnerability validation
- security finding correlation
- confidence scoring
- developer-centric security workflows
- AI-assisted security research
- reducing false positives without losing meaningful signal
My English-language technical home for:
Application Security · Vulnerability Research · Code Review · Security Tooling
A recurring theme in my work is simple:
Signal what matters. Ignore the rest.
My long-running Italian publication about secure development, code review, cybersecurity and software security.
I also host Security Walks, a short-form Italian cybersecurity podcast covering vulnerabilities, security news and technology without unnecessary noise.
I've been contributing to and building open-source software for a large part of my career.
I believe security tooling works best when engineers can:
- understand what the tool is doing;
- challenge its assumptions;
- reproduce its findings;
- improve it.
That's one of the reasons I keep building in public.
It's about understanding which ones matter.
Application Security · Vulnerability Research · Open Source
- Is Your Product Security Engineer Going to Be Replaced?
- NGINX PoolSlip & NGINX Rift: When the Internet’s Favorite Reverse Proxy Turns Against Itself
- Signal Engine 0.3.0: From Raw Findings to Real Signal
- Soak: Deep-Tissue Static Analysis as an Execution Layer
- Aggregating Semgrep Results: Top Rules, Files, and Clusters (MVP Demo)




