Fabio Cerullo

11K posts

Fabio Cerullo banner
Fabio Cerullo

Fabio Cerullo

@fcerullo

CEO @cycubix | Volunteer @owasp | Senior Instructor @isc2

Dublin, Ireland 가입일 Mayıs 2007
4.5K 팔로잉1.8K 팔로워
bzrp
bzrp@bizarrap·
🇦🇷🫶🏻
bzrp tweet media
QME
149
1.7K
30.3K
196.8K
The Legend Runner ⚓️🇳🇬
Marathons are addictive. I've ran seven marathons so far, and it's still hell after kilometer 32. If you've run a marathon, you are absolutely incredible. It is one of the greatest achievements you can reach in a lifetime.
English
41
61
1.1K
44K
Fabio Cerullo
Fabio Cerullo@fcerullo·
@elwatto Me encanto este post Miguel. Muy open hearted y a su vez inspirador. Enhorabuena!
Español
0
0
0
12
Miguel Carranza
Miguel Carranza@elwatto·
Year EIGHT as a founder CTO. 2025 felt like a decade. The year of vibe coding, Apple opening payments, almost getting acquired, saying no, scaling past 100 people, mistakes, cultural memes, and figuring out how to go long. miguelcarranza.es/cto-year-8
English
56
59
851
302.9K
Carolina
Carolina@Carolina773·
Salí a correr mientras hija estaba en entrenamiento. Soy una mezcla entre @hatetemporuns y @esole_gonzalez Foto a modo ilustrativo para mostrar el cielazo.
Carolina tweet media
Español
3
0
26
408
Julián
Julián@juliandeangeIis·
@fcerullo Local, una mac que tenia vieja
Español
1
0
1
49
Julián
Julián@juliandeangeIis·
Siendo que estoy todo el tiempo probando tools de AI, solo tuve pocos momentos 'wow': - Cursor (Feb 25) - Claude Code (Ag 25) - Cloud Agents + SDD + Automations (Sep-Oct 25) y sin dudas de las últimas semanas tengo uno nuevo: - Hermes + Obsidian + LLM Wiki (skill de karpathy)
Julián tweet media
Español
22
40
781
108.8K
Niamh 🇮🇪
Niamh 🇮🇪@irishnftgal·
Dublin Buildstation’s new intern
Niamh 🇮🇪 tweet mediaNiamh 🇮🇪 tweet media
English
9
2
46
1.5K
Fabio Cerullo
Fabio Cerullo@fcerullo·
Buen hilo 👏 Sumaría algo clave: en multi-tenant con shared schema, RLS en Postgres es una gran capa de defensa. Confiar en WHERE org_id = ? funciona… hasta que hay un bug o una SQL injection. Sin RLS → podés filtrar datos de todos los tenants Con RLS → la DB limita el acceso aunque la query esté comprometida No reemplaza buenas prácticas como parametrizacion de las queries pero reduce muchísimo el impacto.
Español
0
0
0
36
Tomás Malamud
Tomás Malamud@tomasmalamud·
Cuando estaba arrancando @lapyme_ar, me enfrenté a la pregunta de cómo manejar multi-tenancy en Postgres para las empresas. Hace unos días salió un artículo muy bueno de @PlanetScale explicando los 3 enfoques: - Shared schema: el más básico. Misma db, mismo schema, y en cada tabla un `tenant_id` u `org_id` como atributo que separa los datos de cada uno - Schema-per-tenant: en vez de tener `public` para todos los tenants, tenés un schema y tablas por cada uno - Database-per-tenant: donde cada tenant tiene su propia base de datos lógica, schema, y tablas El que recomiendan en @PlanetScale y el que usa La Pyme es el más simple: shared schema. Simplemente todas las queries llevan `WHERE org_id= ?`. Y sin RLS. Toda la lógica de "aislamiento" de tenants está en la aplicación, no en la db.
Tomás Malamud tweet media
Español
14
12
254
18.7K
Fabio Cerullo 리트윗함
Brendan Falk
Brendan Falk@BrendanFalk·
To check if your Google Workspace has been compromised by the same tool that compromised Vercel: 1. Go to admin.google.com/ac/owl/list?ta… - This is Google Admin Console > Security > Access and Data Control > API Controls > Manage app access > Accessed Apps 2. Filter by ID = …v79i7bbvqj.apps.googleusercontent.com - This is the ID of the compromised OAuth app If you see an app after filtering, you have potentially been compromised
Brendan Falk tweet media
English
62
747
4.5K
1M
Fabio Cerullo 리트윗함
Guillermo Rauch
Guillermo Rauch@rauchg·
Here's my update to the broader community about the ongoing incident investigation. I want to give you the rundown of the situation directly. A Vercel employee got compromised via the breach of an AI platform customer called Context.ai that he was using. The details are being fully investigated. Through a series of maneuvers that escalated from our colleague’s compromised Vercel Google Workspace account, the attacker got further access to Vercel environments. Vercel stores all customer environment variables fully encrypted at rest. We have numerous defense-in-depth mechanisms to protect core systems and customer data. We do have a capability however to designate environment variables as “non-sensitive”. Unfortunately, the attacker got further access through their enumeration. We believe the attacking group to be highly sophisticated and, I strongly suspect, significantly accelerated by AI. They moved with surprising velocity and in-depth understanding of Vercel. At the moment, we believe the number of customers with security impact to be quite limited. We’ve reached out with utmost priority to the ones we have concerns about. All of our focus right now is on investigation, communication to customers, enhancement of security measures, and sanitization of our environments. We’ve deployed extensive protection measures and monitoring. We’ve analyzed our supply chain, ensuring Next.js, Turbopack, and our many open source projects remain safe for our community. The recommendation for all Vercel customers is to follow the Security Bulletin closely (vercel.com/kb/bulletin/ve…). My advice to everyone is to follow the best practices of security response: secret rotation, monitoring access to your Vercel environments and linked services, and ensuring the proper use of the sensitive env variables feature. In response to this, and to aid in the improvement of all of our customers’ security postures, we’ve already rolled out new capabilities in the dashboard, including an overview page of environment variables, and a better user interface for sensitive env var creation and management. As always, I’m totally open to your feedback. We’re working with elite cybersecurity firms, industry peers, and law enforcement. We’ve reached out to Context to assist in understanding the full scale of the incident, in an effort to protect other organizations and the broader internet. I also want to thank the Google Mandiant team for their active engagement and assistance. It’s my mission to turn this attack into the most formidable security response imaginable. It’s always been a top priority for me. Vercel employs some of the most dedicated security researchers and security-minded engineers in the world. I commit to keeping you updated and rolling out extensive improvements and defenses so you, our customers and community, can have the peace of mind that Vercel always has your back.
English
448
1K
7.2K
2.6M
Fabio Cerullo 리트윗함
Vercel
Vercel@vercel·
Our investigation has revealed that the incident originated from a third-party AI tool with hundreds of users whose Google Workspace OAuth app was compromised. We recommend that Google Workspace Administrators check for usage of this app immediately. #indicators-of-compromise-iocs" target="_blank" rel="nofollow noopener">vercel.com/kb/bulletin/ve…
English
94
377
1.7K
1.5M
Fabio Cerullo
Fabio Cerullo@fcerullo·
@patomolina Pato, te aconsejaria revisar los logs si tienen un teams account porque por ahi hubo algun skill instalado x alguien que disparo las alertas
Español
0
0
2
346
Pato Molina
Pato Molina@patomolina·
Anthropic decidió dar de baja a toda nuestra organización por una supuesta infracción de sus condiciones de uso. Qué política específica infringimos no tengo ni la menor idea: simplemente recibimos un mail y listo, adiós Claude. Si querés apelar la medida hay que completar un Google Form, así de ridículo como suena. De golpe más de 60 personas se quedaron sin una herramienta fundamental para trabajar. Integraciones, skills, historial de conversaciones: todo perdido o, en el mejor de los casos, parado por tiempo indeterminado. Enorme aprendizaje para cualquier empresa de software que dependa de herramientas de IA en procesos críticos. Nunca hay que poner todos los huevos en una canasta.
Pato Molina@patomolina

@claudeai you took down our entire organization with 60+ accounts belonging to a legitimate company for no apparent reason, without any explanations. The only way to appeal the decision is by filling out a Google Form? Very bad UX and customer service.

Español
788
1.4K
9.6K
5.2M
Valentina Luciana 🇦🇷🇮🇪
Quiero creer que esto será verdad, después de casi 4 meses sin dos días seguidos de sol ahora viene UNA SEMANA SOLEADA? 🥹🥹🥹🌞🌞🌞
Valentina Luciana 🇦🇷🇮🇪 tweet media
Español
9
0
27
1.7K