Founder @ Kuro Security · Application Security Analyst · Software Developer
I build applications, investigate how they break, and turn findings into fixes.
I'm a software developer and application security analyst from Brazil, and the founder of Kuro Security.
My work connects software development with offensive security: reading code, testing assumptions, reproducing vulnerabilities, and helping developers address their root causes.
I'm especially interested in authorization flaws, business logic vulnerabilities, and the gap between how an application is designed and how it actually behaves.
- Application security: web and API testing, secure code review, and remediation.
- Security research: vulnerability analysis, reproducible proofs of concept, and responsible disclosure.
- Software development: building applications and practical security tools.
- DevSecOps: bringing security into development workflows and Linux environments.
At Kuro Security, I work on pentesting, Red Team, and AppSec, with a focus on clear evidence, practical impact, and actionable remediation.
A falha já existe. A gente chega antes.
CVE-2026-102261 — Camaleon CMS authorization bypass
I identified an authorization flaw in the media crop workflow that allowed an authenticated user with media management permissions to modify another user's avatar through the saved_avatar parameter.
The repository includes a non-destructive checker for the authorization control introduced in version 2.9.3.
Reproductions and technical explorations of publicly disclosed vulnerabilities. Original discovery credit belongs to the respective researchers.
| Repository | Focus |
|---|---|
| CVE-2025-2304 | Camaleon CMS vulnerability PoC |
| CVE-2024-41570 | Havoc C2 SSRF PoC |
| Project | What it does |
|---|---|
| minimal-waf | An HTTP reverse proxy written in Go that inspects requests, with monitoring and blocking modes. |
- Omakub — Contributions to the Ubuntu development environment setup.
- br-acc — Open data and technology for making Brazilian public information more accessible.
For AppSec work, security research, or open-source collaboration:


