<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: ramiro quintana</title>
    <description>The latest articles on DEV Community by ramiro quintana (@ramiroquintana).</description>
    <link>https://dev.to/ramiroquintana</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4117623%2F469ab588-5c45-4448-93ea-24b0f4b1935b.png</url>
      <title>DEV Community: ramiro quintana</title>
      <link>https://dev.to/ramiroquintana</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/ramiroquintana"/>
    <language>en</language>
    <item>
      <title>GitHub Student Developer Pack: What You Can Get as a Student</title>
      <dc:creator>ramiro quintana</dc:creator>
      <pubDate>Fri, 25 Sep 2026 18:05:37 +0000</pubDate>
      <link>https://dev.to/ramiroquintana/github-student-developer-pack-what-you-can-get-as-a-student-4pj1</link>
      <guid>https://dev.to/ramiroquintana/github-student-developer-pack-what-you-can-get-as-a-student-4pj1</guid>
      <description>&lt;p&gt;If you're a student learning software development, the GitHub Student Developer Pack is something you should probably know about.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flb1avd5vfbn4om4k7kz0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Flb1avd5vfbn4om4k7kz0.png" alt="free github pro bag" width="634" height="267"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It gives eligible students access to GitHub and a collection of developer tools and services from different partners, with some offers available for up to two years.&lt;/p&gt;

&lt;p&gt;The interesting part is that it's much more than just GitHub Pro.&lt;/p&gt;

&lt;p&gt;Depending on the current offers, students can get access to tools related to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Cloud and infrastructure&lt;/li&gt;
&lt;li&gt;Development environments&lt;/li&gt;
&lt;li&gt;AI tools&lt;/li&gt;
&lt;li&gt;Domains and hosting&lt;/li&gt;
&lt;li&gt;Databases&lt;/li&gt;
&lt;li&gt;APIs&lt;/li&gt;
&lt;li&gt;Design&lt;/li&gt;
&lt;li&gt;Security&lt;/li&gt;
&lt;li&gt;Developer productivity&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;GitHub currently states that student verification lasts for two years, and students can re-verify their status afterward if they remain eligible.&lt;/p&gt;

&lt;p&gt;I recently organized the information I found into a small open-source project:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;GitHub Student Pack Guide&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;It's a guide to the benefits available through the Student Developer Pack, with the information organized by category to make it easier to find useful tools.&lt;/p&gt;

&lt;p&gt;The repository is available in English, Spanish and Portuguese:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/quintana-dev/github-student-pack-guide" rel="noopener noreferrer"&gt;https://github.com/quintana-dev/github-student-pack-guide&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;I built this mainly because when you're starting out as a developer, it's easy to pay for tools without realizing that some of them may already be available through your student status.&lt;/p&gt;

&lt;p&gt;If you're currently studying software development, it's worth checking what you have access to before paying for developer tools yourself.&lt;/p&gt;

&lt;h2&gt;
  
  
  About Me
&lt;/h2&gt;

&lt;p&gt;I'm &lt;strong&gt;Ramiro Quintana&lt;/strong&gt;, a Software Engineer &amp;amp; Full Stack Developer from Argentina.&lt;/p&gt;

&lt;p&gt;I build web applications, browser extensions, automation tools and other software projects under &lt;strong&gt;quintana.dev&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I'm currently focused on software development, automation, web technologies and building practical projects while continuing to learn and improve.&lt;/p&gt;

&lt;p&gt;You can find my projects and other work on my website:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://quintana.dev.ar" rel="noopener noreferrer"&gt;https://quintana.dev.ar&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;




</description>
      <category>github</category>
      <category>offers</category>
      <category>programming</category>
      <category>beginners</category>
    </item>
    <item>
      <title>How Hacktron Hacked OpenAI: What I Learned from an AI-Assisted Attack Chain</title>
      <dc:creator>ramiro quintana</dc:creator>
      <pubDate>Mon, 21 Sep 2026 15:46:13 +0000</pubDate>
      <link>https://dev.to/ramiroquintana/how-hacktron-hacked-openai-what-i-learned-from-an-ai-assisted-attack-chain-54p2</link>
      <guid>https://dev.to/ramiroquintana/how-hacktron-hacked-openai-what-i-learned-from-an-ai-assisted-attack-chain-54p2</guid>
      <description>&lt;p&gt;A few days ago, I came across a security research report from Hacktron that caught my attention.&lt;/p&gt;

&lt;p&gt;The researchers described how they chained multiple vulnerabilities to compromise OpenAI employee accounts and reach internal GitHub repositories.&lt;/p&gt;

&lt;p&gt;What makes the story particularly interesting isn't just the final impact.&lt;/p&gt;

&lt;p&gt;It's the &lt;strong&gt;attack chain&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The initial vulnerability involved image processing. From there, the researchers were able to move through Discourse, OpenAI's authentication infrastructure, employee accounts, and connected GitHub integrations.&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fu0p081lwpdvwyhkqx1cy.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fu0p081lwpdvwyhkqx1cy.png" alt=" " width="800" height="552"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Even more interestingly, AI models were used throughout parts of the research process.&lt;/p&gt;

&lt;p&gt;This made me want to break down the attack at a high level and understand what developers can learn from it.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Disclaimer:&lt;/strong&gt; This is my analysis of publicly reported security research by Hacktron. I'm intentionally not reproducing exploit code, credentials, or instructions that could be used to compromise real systems.&lt;/p&gt;
&lt;/blockquote&gt;


&lt;h2&gt;
  
  
  The attack chain
&lt;/h2&gt;

&lt;p&gt;The entire chain can be simplified to:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;HEIF / HEIC image
        ↓
   ImageMagick
        ↓
     libheif
        ↓
Remote Code Execution
        ↓
     Discourse
        ↓
 OpenAI SSO issue
        ↓
Employee ChatGPT / Codex account
        ↓
 Connected GitHub integration
        ↓
 Internal repositories
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The important part is that this wasn't a single vulnerability magically giving researchers access to OpenAI's internal repositories.&lt;/p&gt;

&lt;p&gt;It was a &lt;strong&gt;chain of different trust boundaries&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Hacktron's published research describes the chain as involving a &lt;code&gt;libheif&lt;/code&gt; image-decoding vulnerability, Debian's security backport situation, ImageMagick, Discourse image uploads, an OpenAI SSO issue, and eventually connected GitHub access. (&lt;a href="https://news.routley.io/posts/a-heap-overflow-and-sso-misconfiguration-to-compromise-openai-internal-repos.html" rel="noopener noreferrer"&gt;Routley News&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;And that's probably the biggest lesson from the whole story.&lt;/p&gt;




&lt;h2&gt;
  
  
  1. It started with an image upload
&lt;/h2&gt;

&lt;p&gt;Image uploads are something developers deal with constantly.&lt;/p&gt;

&lt;p&gt;You upload an image.&lt;/p&gt;

&lt;p&gt;The application validates it.&lt;/p&gt;

&lt;p&gt;Maybe it generates a thumbnail.&lt;/p&gt;

&lt;p&gt;Maybe it converts the format.&lt;/p&gt;

&lt;p&gt;Maybe it extracts metadata.&lt;/p&gt;

&lt;p&gt;From the application's perspective, it can look like a simple feature.&lt;/p&gt;

&lt;p&gt;But behind the scenes, an image might pass through several native libraries.&lt;/p&gt;

&lt;p&gt;In this case, Hacktron focused on the processing of HEIF/HEIC images and the native libraries involved in decoding them.&lt;/p&gt;

&lt;p&gt;The important detail is that &lt;strong&gt;the application itself didn't necessarily contain the vulnerable code&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;A web application can depend on:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Application
    ↓
ImageMagick
    ↓
libheif
    ↓
libde265
    ↓
native C/C++ code
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This creates a dependency chain that developers don't always think about when looking at their own source code.&lt;/p&gt;

&lt;p&gt;According to Hacktron's research, the vulnerability in &lt;code&gt;libheif&lt;/code&gt; could be leveraged during image processing to obtain remote code execution in the affected environment. (&lt;a href="https://news.routley.io/posts/a-heap-overflow-and-sso-misconfiguration-to-compromise-openai-internal-repos.html" rel="noopener noreferrer"&gt;Routley News&lt;/a&gt;)&lt;/p&gt;




&lt;h2&gt;
  
  
  2. The dependency problem
&lt;/h2&gt;

&lt;p&gt;This is one of the parts I found most interesting.&lt;/p&gt;

&lt;p&gt;When we think about dependency security, we usually think about:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;npm install package
        ↓
package vulnerability
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;But production software is often much deeper than that.&lt;/p&gt;

&lt;p&gt;A project might use:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;React
  ↓
Node package
  ↓
Native dependency
  ↓
System package
  ↓
C/C++ library
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;And vulnerabilities can exist several layers below the code we're actually writing.&lt;/p&gt;

&lt;p&gt;Hacktron reported that the underlying &lt;code&gt;libheif&lt;/code&gt; issue had previously been fixed upstream but had not gone through the usual security advisory process, meaning the vulnerable version could remain present in downstream environments. (&lt;a href="https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/" rel="noopener noreferrer"&gt;SecurityWeek&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;That creates an important distinction:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;"The latest version of my application dependencies" doesn't necessarily mean "every component in my execution environment is secure."&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;Dependency management has to include the operating system, container images, native libraries and transitive dependencies.&lt;/p&gt;




&lt;h2&gt;
  
  
  3. Why Discourse mattered
&lt;/h2&gt;

&lt;p&gt;The vulnerable image-processing path was exposed through &lt;strong&gt;Discourse&lt;/strong&gt;, the software used by OpenAI's community forum.&lt;/p&gt;

&lt;p&gt;That changed the situation significantly.&lt;/p&gt;

&lt;p&gt;The vulnerability wasn't sitting on an isolated research machine.&lt;/p&gt;

&lt;p&gt;It was reachable through a real application processing user-uploaded content.&lt;/p&gt;

&lt;p&gt;The simplified model was:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Attacker-controlled file
        ↓
Discourse
        ↓
Image processing
        ↓
Vulnerable native library
        ↓
Code execution
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This is a classic example of why &lt;strong&gt;file uploads should be treated as an attack surface&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;An image isn't necessarily "just an image."&lt;/p&gt;

&lt;p&gt;It's an input that may eventually be interpreted by complex native software.&lt;/p&gt;




&lt;h2&gt;
  
  
  4. RCE wasn't the end of the attack
&lt;/h2&gt;

&lt;p&gt;This is where the research gets particularly interesting.&lt;/p&gt;

&lt;p&gt;Getting remote code execution on one component doesn't automatically mean you have access to everything.&lt;/p&gt;

&lt;p&gt;There are supposed to be boundaries:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Compromised server
       ✕
OpenAI employee account
       ✕
GitHub
       ✕
Internal repositories
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The researchers found another weakness involving OpenAI's SSO flow.&lt;/p&gt;

&lt;p&gt;According to Hacktron, this allowed the attack to move from the compromised forum environment toward employee ChatGPT/Codex accounts. (&lt;a href="https://news.routley.io/posts/a-heap-overflow-and-sso-misconfiguration-to-compromise-openai-internal-repos.html" rel="noopener noreferrer"&gt;Routley News&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;This is a good example of why &lt;strong&gt;identity systems are part of an application's security perimeter&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;A vulnerability in one service can become much more serious if that service has a trusted relationship with an identity provider.&lt;/p&gt;




&lt;h2&gt;
  
  
  5. The importance of trust relationships
&lt;/h2&gt;

&lt;p&gt;Imagine a system like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Community Forum
       │
       │ SSO
       ↓
OpenAI Account
       │
       │ OAuth / integration
       ↓
GitHub
       │
       ↓
Internal repositories
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Every arrow represents a trust relationship.&lt;/p&gt;

&lt;p&gt;If the first component is compromised, the attacker may try to abuse the trust relationships that follow.&lt;/p&gt;

&lt;p&gt;This is why security reviews shouldn't only ask:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Can an attacker compromise this application?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;They should also ask:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"What can an attacker reach if this application is compromised?"&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That's a very different question.&lt;/p&gt;




&lt;h2&gt;
  
  
  6. Where AI entered the picture
&lt;/h2&gt;

&lt;p&gt;Another part of the research received a lot of attention: the researchers used AI models during the investigation.&lt;/p&gt;

&lt;p&gt;According to reporting on the research, Hacktron used Anthropic's Claude models to assist with analyzing the vulnerability and developing parts of the exploit. The researchers still performed the security research themselves, including adapting and validating the results. (&lt;a href="https://www.theverge.com/ai-artificial-intelligence/997444/openai-hack-claude-heif-heist" rel="noopener noreferrer"&gt;The Verge&lt;/a&gt;)&lt;/p&gt;

&lt;p&gt;This distinction matters.&lt;/p&gt;

&lt;p&gt;This wasn't:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;AI
 ↓
"hack OpenAI"
 ↓
done
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;It was closer to:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Security researchers
        ↓
AI-assisted analysis
        ↓
Hypotheses
        ↓
Testing
        ↓
Debugging
        ↓
Human validation
        ↓
Working research
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;AI can dramatically reduce the amount of time required to understand unfamiliar code, generate hypotheses, investigate libraries and iterate on technical problems.&lt;/p&gt;

&lt;p&gt;But the researcher still needs to know &lt;strong&gt;what to ask, what to test and whether the result actually makes sense&lt;/strong&gt;.&lt;/p&gt;




&lt;h2&gt;
  
  
  7. The most interesting lesson: attack chains
&lt;/h2&gt;

&lt;p&gt;For me, this is the biggest takeaway.&lt;/p&gt;

&lt;p&gt;If you looked at the individual components separately, the final impact would be difficult to predict.&lt;/p&gt;

&lt;p&gt;You had:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Image processing vulnerability
+
Application exposure
+
SSO configuration issue
+
Employee account
+
GitHub integration
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Together, they created something much more significant.&lt;/p&gt;

&lt;p&gt;This is why vulnerability severity shouldn't always be considered in isolation.&lt;/p&gt;

&lt;p&gt;A vulnerability that looks limited when viewed independently can become much more serious when combined with another weakness.&lt;/p&gt;




&lt;h2&gt;
  
  
  8. What developers can learn from this
&lt;/h2&gt;

&lt;p&gt;There are several practical lessons here that apply far beyond OpenAI.&lt;/p&gt;

&lt;h3&gt;
  
  
  Treat file uploads as hostile input
&lt;/h3&gt;

&lt;p&gt;Images, PDFs, archives and other files can trigger complex parsers.&lt;/p&gt;

&lt;p&gt;Don't assume that because a file has a familiar extension, processing it is harmless.&lt;/p&gt;




&lt;h3&gt;
  
  
  Understand your dependency tree
&lt;/h3&gt;

&lt;p&gt;Don't only track the libraries you explicitly installed.&lt;/p&gt;

&lt;p&gt;Understand what your application ultimately depends on:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Application
    ↓
Framework
    ↓
Package
    ↓
Native library
    ↓
Operating system
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h3&gt;
  
  
  Keep native dependencies updated
&lt;/h3&gt;

&lt;p&gt;Libraries written in C/C++ are often extremely powerful because they operate close to the system.&lt;/p&gt;

&lt;p&gt;They're also capable of memory-safety vulnerabilities.&lt;/p&gt;

&lt;p&gt;Keeping them updated and isolating their execution can significantly reduce the impact of a compromise.&lt;/p&gt;




&lt;h3&gt;
  
  
  Minimize trust between services
&lt;/h3&gt;

&lt;p&gt;If a community forum can somehow become a path toward employee accounts, that's a sign that the boundaries between systems deserve careful review.&lt;/p&gt;

&lt;p&gt;Every integration should have the minimum privileges necessary.&lt;/p&gt;




&lt;h3&gt;
  
  
  Review SSO configurations carefully
&lt;/h3&gt;

&lt;p&gt;Authentication isn't just about passwords.&lt;/p&gt;

&lt;p&gt;SSO introduces relationships between different systems.&lt;/p&gt;

&lt;p&gt;Those relationships need to be treated as security boundaries.&lt;/p&gt;




&lt;h3&gt;
  
  
  Assume compromised components will be used as stepping stones
&lt;/h3&gt;

&lt;p&gt;A useful security question is:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;"If this component is completely compromised, what can the attacker do next?"&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That question can reveal problems that aren't obvious when reviewing each application independently.&lt;/p&gt;




&lt;h2&gt;
  
  
  9. AI changes the economics of security research
&lt;/h2&gt;

&lt;p&gt;The part I find most interesting isn't necessarily that AI can write exploit code.&lt;/p&gt;

&lt;p&gt;We've known for a while that models can generate code.&lt;/p&gt;

&lt;p&gt;The bigger change is the &lt;strong&gt;speed of iteration&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Security research often involves:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Read code
   ↓
Understand behavior
   ↓
Form hypothesis
   ↓
Write test
   ↓
Observe result
   ↓
Debug
   ↓
Try again
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;AI can accelerate several of these steps.&lt;/p&gt;

&lt;p&gt;That doesn't eliminate the need for expertise.&lt;/p&gt;

&lt;p&gt;Instead, it potentially allows a small team to explore a much larger technical surface in a shorter amount of time.&lt;/p&gt;

&lt;p&gt;And that applies to both sides.&lt;/p&gt;

&lt;p&gt;The same tools can help defenders understand vulnerabilities, audit dependencies and investigate suspicious behavior.&lt;/p&gt;




&lt;h2&gt;
  
  
  Final thoughts
&lt;/h2&gt;

&lt;p&gt;What started as an image-processing vulnerability ultimately became a much larger security problem because it could be chained across multiple systems.&lt;/p&gt;

&lt;p&gt;That's what I found most interesting about Hacktron's research.&lt;/p&gt;

&lt;p&gt;The lesson isn't simply:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Image processing is dangerous."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;It's:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Security is often about the connections between systems, not just the systems themselves.&lt;/strong&gt;&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;A vulnerable library, a web application, an identity provider and a third-party integration might each look manageable on their own.&lt;/p&gt;

&lt;p&gt;When they're connected, the security properties of the entire chain matter.&lt;/p&gt;

&lt;p&gt;And as AI becomes better at assisting security researchers, understanding those chains may become even more important.&lt;/p&gt;




&lt;h2&gt;
  
  
  About me
&lt;/h2&gt;

&lt;p&gt;I'm &lt;strong&gt;Ramiro Quintana&lt;/strong&gt;, a Software Engineer &amp;amp; Full Stack Developer from Argentina.&lt;/p&gt;

&lt;p&gt;I build web applications, browser extensions and software projects under &lt;strong&gt;quintana.dev&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;I'm particularly interested in software engineering, automation, reverse engineering and cybersecurity.&lt;/p&gt;

&lt;p&gt;You can find my projects and other technical posts on my website:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://quintana.dev.ar" rel="noopener noreferrer"&gt;https://quintana.dev.ar&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;




&lt;h3&gt;
  
  
  Sources
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Hacktron's original security research on the OpenAI attack chain. (&lt;a href="https://news.routley.io/posts/a-heap-overflow-and-sso-misconfiguration-to-compromise-openai-internal-repos.html" rel="noopener noreferrer"&gt;Routley News&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;SecurityWeek's technical summary of the vulnerability chain and AI-assisted research. (&lt;a href="https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/" rel="noopener noreferrer"&gt;SecurityWeek&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;The Verge's reporting on Hacktron's research and the role of Claude. (&lt;a href="https://www.theverge.com/ai-artificial-intelligence/997444/openai-hack-claude-heif-heist" rel="noopener noreferrer"&gt;The Verge&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>ai</category>
      <category>openai</category>
      <category>programming</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>How I Built Calculadora SIU CrediUPE: Automating Credit Calculation in SIU Guaraní</title>
      <dc:creator>ramiro quintana</dc:creator>
      <pubDate>Mon, 14 Sep 2026 15:26:45 +0000</pubDate>
      <link>https://dev.to/ramiroquintana/how-i-built-calculadora-siu-crediupe-automating-credit-calculation-in-siu-guarani-11i9</link>
      <guid>https://dev.to/ramiroquintana/how-i-built-calculadora-siu-crediupe-automating-credit-calculation-in-siu-guarani-11i9</guid>
      <description>&lt;p&gt;I'm Ramiro Quintana, a Software Engineer &amp;amp; Full Stack Developer. I built Calculadora SIU CrediUPE to solve a small but repetitive problem I encountered while using SIU Guaraní at Universidad Provincial de Ezeiza (UPE).&lt;/p&gt;

&lt;p&gt;When checking my study plan, I wanted an easier way to keep track of how many free credits I had accumulated. The information was already available in the system, but calculating and filtering it manually was unnecessary work.&lt;/p&gt;

&lt;p&gt;So I decided to automate it.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1g0lad75vlx7ya36e02u.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1g0lad75vlx7ya36e02u.png" alt="Calculadora SIU CrediUPE menu" width="800" height="571"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The idea
&lt;/h2&gt;

&lt;p&gt;Calculadora SIU CrediUPE is a Chrome extension that works directly on the SIU Guaraní study plan. Its main purpose is to automatically calculate the number of free credits based on the information already displayed by the system.&lt;/p&gt;

&lt;p&gt;What started as a small tool to solve a problem I had myself ended up being used by other students as well. Today, Calculadora SIU CrediUPE has surpassed 800 downloads and has more than 250 users.&lt;/p&gt;

&lt;p&gt;Seeing other people use something I built to solve a specific problem has been one of the most rewarding parts of the project.&lt;/p&gt;

&lt;h2&gt;
  
  
  How it works
&lt;/h2&gt;

&lt;p&gt;The extension works by interacting with the existing DOM of the SIU Guaraní page.&lt;/p&gt;

&lt;p&gt;The general flow is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;SIU Guaraní
     │
     ▼
Read the study plan
     │
     ▼
Find relevant subjects
     │
     ▼
Extract credit information
     │
     ▼
Filter the required subjects
     │
     ▼
Calculate total free credits
     │
     ▼
Display the result
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;Instead of asking the user to manually copy information into another calculator, the extension uses the data already present on the page.&lt;/p&gt;

&lt;h2&gt;
  
  
  Working with the DOM
&lt;/h2&gt;

&lt;p&gt;One of the most interesting parts of the project was figuring out how the information was structured inside SIU Guaraní.&lt;/p&gt;

&lt;p&gt;The extension needs to locate the relevant elements, read their content and determine which subjects should be included in the calculation.&lt;/p&gt;

&lt;p&gt;This required working with JavaScript DOM APIs and making the extraction logic specific enough to recognize the information I needed without interfering with the rest of the page.&lt;/p&gt;

&lt;p&gt;The goal wasn't to modify how SIU Guaraní works.&lt;/p&gt;

&lt;p&gt;It was simply to add a small layer of functionality on top of the existing interface.&lt;/p&gt;

&lt;h2&gt;
  
  
  Keeping the extension simple
&lt;/h2&gt;

&lt;p&gt;Since the extension is designed for students who are already using SIU Guaraní, I wanted the interaction to require as few steps as possible.&lt;/p&gt;

&lt;p&gt;The user shouldn't have to:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Open another website.&lt;/li&gt;
&lt;li&gt;Copy their subjects.&lt;/li&gt;
&lt;li&gt;Enter credits manually.&lt;/li&gt;
&lt;li&gt;Calculate the result.&lt;/li&gt;
&lt;li&gt;Go back to SIU Guaraní.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Instead, the extension handles those steps automatically.&lt;/p&gt;

&lt;p&gt;The result is displayed directly within the existing workflow.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why I built it
&lt;/h2&gt;

&lt;p&gt;This project started from a very specific problem.&lt;/p&gt;

&lt;p&gt;Sometimes the most useful software projects aren't large applications. They can be small tools that remove a repetitive task from someone's daily routine.&lt;/p&gt;

&lt;p&gt;For me, this was also an opportunity to apply what I was learning about JavaScript, browser extensions and DOM manipulation to a real problem.&lt;/p&gt;

&lt;p&gt;Rather than building another tutorial project, I wanted to create something that I could actually use.&lt;/p&gt;

&lt;h2&gt;
  
  
  From personal tool to published extension
&lt;/h2&gt;

&lt;p&gt;After getting the extension working for my own use, I decided to publish it so other students could use it as well.&lt;/p&gt;

&lt;p&gt;That changed the project from a small local experiment into a real browser extension that had to be packaged, tested and prepared for distribution through the Chrome Web Store.&lt;/p&gt;

&lt;p&gt;That process also taught me more about the practical side of browser extension development and publishing.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I learned
&lt;/h2&gt;

&lt;p&gt;Working on Calculadora SIU CrediUPE helped me understand several concepts that aren't always obvious when learning web development through isolated exercises.&lt;/p&gt;

&lt;p&gt;Some of the main things I worked with were:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;JavaScript DOM manipulation&lt;/li&gt;
&lt;li&gt;Browser extension development&lt;/li&gt;
&lt;li&gt;Reading and processing information from an existing web interface&lt;/li&gt;
&lt;li&gt;Data filtering and calculation&lt;/li&gt;
&lt;li&gt;Injecting UI elements into an existing page&lt;/li&gt;
&lt;li&gt;Handling different states of a web application&lt;/li&gt;
&lt;li&gt;Testing the extension against the real SIU Guaraní interface&lt;/li&gt;
&lt;li&gt;Packaging and publishing a Chrome extension&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;More importantly, it reinforced something I find important about software development:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;A useful project doesn't have to be complicated.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Sometimes a few hundred lines of code can eliminate a repetitive task for an entire group of people.&lt;/p&gt;

&lt;h2&gt;
  
  
  What's next?
&lt;/h2&gt;

&lt;p&gt;I want to continue improving the extension as the SIU Guaraní interface evolves and based on feedback from students who use it.&lt;/p&gt;

&lt;p&gt;I'm also interested in building more small tools that solve specific problems instead of creating software simply for the sake of adding another project to a portfolio.&lt;/p&gt;

&lt;h2&gt;
  
  
  About me
&lt;/h2&gt;

&lt;p&gt;I'm &lt;strong&gt;Ramiro Quintana&lt;/strong&gt;, a Software Engineer &amp;amp; Full Stack Developer focused on building web applications, browser extensions, SaaS projects and software solutions under &lt;strong&gt;quintana.dev&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Calculadora SIU CrediUPE is one of the projects I've built as part of that work.&lt;/p&gt;

&lt;p&gt;You can see more about my projects at:&lt;br&gt;
&lt;strong&gt;&lt;a href="https://quintana.dev.ar/" rel="noopener noreferrer"&gt;https://quintana.dev.ar/&lt;/a&gt;&lt;/strong&gt;&lt;br&gt;
CrediUPE:&lt;br&gt;
&lt;strong&gt;&lt;a href="https://quintana.dev.ar/library/siu-upe" rel="noopener noreferrer"&gt;https://quintana.dev.ar/library/siu-upe&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;And the extension is available through the Chrome Web Store.&lt;/p&gt;

</description>
      <category>automation</category>
      <category>javascript</category>
      <category>sideprojects</category>
      <category>webdev</category>
    </item>
    <item>
      <title>How I Built SQUIAM: A Steam-Inspired Interactive Developer Portfolio</title>
      <dc:creator>ramiro quintana</dc:creator>
      <pubDate>Wed, 09 Sep 2026 13:42:22 +0000</pubDate>
      <link>https://dev.to/ramiroquintana/how-i-built-squiam-a-steam-inspired-interactive-developer-portfolio-5674</link>
      <guid>https://dev.to/ramiroquintana/how-i-built-squiam-a-steam-inspired-interactive-developer-portfolio-5674</guid>
      <description>&lt;p&gt;I'm Ramiro Quintana, a Software Engineer &amp;amp; Full Stack Developer building software projects under quintana.dev.&lt;/p&gt;

&lt;p&gt;Most developer portfolios follow the same structure: a short introduction, a list of skills, some projects, and a contact section.&lt;/p&gt;

&lt;p&gt;I wanted to try something different.&lt;/p&gt;

&lt;p&gt;Instead of building another traditional portfolio, I decided to turn mine into an interactive experience inspired by Steam's interface and the way it organizes games, libraries, profiles, and communities.&lt;/p&gt;

&lt;p&gt;That project became SQUIAM.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqwgolxev9aczpgy3fp35.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fqwgolxev9aczpgy3fp35.png" alt=" " width="799" height="380"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The idea behind SQUIAM
&lt;/h2&gt;

&lt;p&gt;SQUIAM is an interactive developer portfolio designed around the idea of exploring projects rather than simply scrolling through a page.&lt;/p&gt;

&lt;p&gt;The main interface is organized into different sections, including:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A project library&lt;/li&gt;
&lt;li&gt;A technical services store&lt;/li&gt;
&lt;li&gt;A developer profile&lt;/li&gt;
&lt;li&gt;A technology inventory&lt;/li&gt;
&lt;li&gt;Community features&lt;/li&gt;
&lt;li&gt;Statistics&lt;/li&gt;
&lt;li&gt;Real-time chat&lt;/li&gt;
&lt;li&gt;Individual project pages&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The Steam-inspired design is mostly a starting point. The goal was to take some familiar concepts from the platform and adapt them to a developer portfolio.&lt;/p&gt;

&lt;h2&gt;
  
  
  The technology stack
&lt;/h2&gt;

&lt;p&gt;SQUIAM is built with React, TypeScript and Vite.&lt;/p&gt;

&lt;p&gt;For styling, I use Tailwind CSS together with custom styles to recreate the dark interface and desktop-application feel.&lt;/p&gt;

&lt;p&gt;Animations are handled with Motion, mainly for transitions between views and UI elements.&lt;/p&gt;

&lt;p&gt;For charts and statistics, I use Recharts.&lt;/p&gt;

&lt;p&gt;The application is deployed on Cloudflare Pages and uses serverless functions for backend functionality.&lt;/p&gt;

&lt;p&gt;The main stack is:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;React
TypeScript
Vite
Tailwind CSS
Motion
Recharts
Cloudflare Pages
Serverless Functions
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;h2&gt;
  
  
  Designing the interface
&lt;/h2&gt;

&lt;p&gt;One of the most interesting parts of the project was figuring out how to make a portfolio feel like an application.&lt;/p&gt;

&lt;p&gt;Instead of having every section visible at once, the interface is built around navigation and discovery.&lt;/p&gt;

&lt;p&gt;Projects have their own pages, technologies are presented as part of an inventory, and services are presented through a store-like interface.&lt;/p&gt;

&lt;p&gt;This also meant paying more attention to small details such as transitions, navigation states, loading behavior, and responsive layouts.&lt;/p&gt;

&lt;h2&gt;
  
  
  The project library
&lt;/h2&gt;

&lt;p&gt;The library is one of the main parts of SQUIAM.&lt;/p&gt;

&lt;p&gt;Each project can have its own page containing information about what it does, which technologies were used, its current state, and relevant links.&lt;/p&gt;

&lt;p&gt;This structure also makes it easier to keep adding new projects without redesigning the entire portfolio every time.&lt;/p&gt;

&lt;h2&gt;
  
  
  A different approach to services
&lt;/h2&gt;

&lt;p&gt;I also wanted the services section to fit into the same concept.&lt;/p&gt;

&lt;p&gt;Instead of presenting a traditional list of services, I designed it as a small software store.&lt;/p&gt;

&lt;p&gt;The idea is to make technical services easier to understand while keeping the visual language consistent with the rest of the application.&lt;/p&gt;

&lt;p&gt;My work mainly focuses on software development, web applications, browser extensions, SaaS projects and automation.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why build something this complicated for a portfolio?
&lt;/h2&gt;

&lt;p&gt;A portfolio is already a software project, so I decided to treat it that way.&lt;/p&gt;

&lt;p&gt;Rather than only using the portfolio to demonstrate my work, I wanted the portfolio itself to demonstrate how I approach software development.&lt;/p&gt;

&lt;p&gt;That meant dealing with the same kinds of problems that appear in larger applications: component architecture, routing, state management, UI consistency, performance, deployment and maintainability.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I learned
&lt;/h2&gt;

&lt;p&gt;Building SQUIAM has been a useful way to experiment with both frontend development and product design.&lt;/p&gt;

&lt;p&gt;Some of the things I've worked with throughout the project include:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Structuring a larger React application&lt;/li&gt;
&lt;li&gt;Building reusable UI components&lt;/li&gt;
&lt;li&gt;Creating complex interfaces&lt;/li&gt;
&lt;li&gt;Working with animations and transitions&lt;/li&gt;
&lt;li&gt;Visualizing project data&lt;/li&gt;
&lt;li&gt;Connecting frontend features with serverless functions&lt;/li&gt;
&lt;li&gt;Deploying applications with Cloudflare Pages&lt;/li&gt;
&lt;li&gt;Improving SEO for a JavaScript application&lt;/li&gt;
&lt;li&gt;Designing an interface around user interaction rather than a traditional page structure&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The biggest lesson for me has been that a portfolio doesn't have to be just a presentation of your work.&lt;/p&gt;

&lt;p&gt;It can be one of your projects.&lt;/p&gt;

&lt;h2&gt;
  
  
  What's next?
&lt;/h2&gt;

&lt;p&gt;SQUIAM is still an evolving project.&lt;/p&gt;

&lt;p&gt;As I build new software, I want the portfolio to evolve with it rather than remaining a static collection of projects.&lt;/p&gt;

&lt;p&gt;The long-term idea behind quintana.dev is to have a single place where I can publish and showcase the software I build, from experiments and browser extensions to larger applications.&lt;/p&gt;

&lt;h2&gt;
  
  
  About me
&lt;/h2&gt;

&lt;p&gt;I'm &lt;strong&gt;Ramiro Quintana&lt;/strong&gt;, a Software Engineer &amp;amp; Full Stack Developer focused on building web applications, browser extensions, SaaS projects and software solutions under &lt;strong&gt;quintana.dev&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;You can explore SQUIAM and my other projects at:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;a href="https://quintana.dev.ar/" rel="noopener noreferrer"&gt;https://quintana.dev.ar/&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>react</category>
      <category>portfolio</category>
      <category>devops</category>
    </item>
  </channel>
</rss>
