<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>mugiblue</title><link>https://bluemugi.dev/</link><description>Recent content on mugiblue</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 00:00:00 +0900</lastBuildDate><atom:link href="https://bluemugi.dev/index.xml" rel="self" type="application/rss+xml"/><item><title>Hello</title><link>https://bluemugi.dev/p/hello/</link><pubDate>Thu, 27 Aug 2026 00:00:00 +0900</pubDate><guid>https://bluemugi.dev/p/hello/</guid><description>&lt;p&gt;I work as a product security engineer. This is where I keep notes that are too&#10;long for a scratchpad and not polished enough to be anything else.&lt;/p&gt;&#10;&lt;p&gt;I came to security through systems rather than the other way around. Operating&#10;systems, networks, build pipelines — I like them because they behave like&#10;puzzles: a fixed set of rules, a pile of pieces, and some arrangement nobody&#10;quite intended. Security turned out to be the most direct way to keep pulling on&#10;that thread. Watching how something fails tells you more about its design than&#10;the documentation usually does, and it gives you an honest view of both the&#10;strengths and the weak points.&lt;/p&gt;&#10;&lt;p&gt;Most of my day-to-day is DevSecOps: getting security checks to live inside build&#10;and deployment pipelines without making them miserable to use. Around that, the&#10;things I find myself reading and writing about are:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Cloud security&lt;/li&gt;&#10;&lt;li&gt;Web application security&lt;/li&gt;&#10;&lt;li&gt;Malware analysis and reverse engineering&lt;/li&gt;&#10;&lt;li&gt;CTF notes&lt;/li&gt;&#10;&lt;li&gt;The occasional bit of vulnerability research&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;No schedule, no completeness guarantee. These are working notes, so some of them&#10;will age badly. Anything hands-on here is written from a defensive or&#10;educational angle — run it only against systems you own or are authorised to&#10;test.&lt;/p&gt;&#10;&lt;p&gt;Views are my own and not those of any employer.&lt;/p&gt;&#10;</description></item></channel></rss>