Ronald Pereira

231 posts

Ronald Pereira banner
Ronald Pereira

Ronald Pereira

@rondevz

Software Engineer, in short, I work making software. Gymrat, Drummer and Videogames lover.

Morioh Katılım Mayıs 2010
1.5K Takip Edilen122 Takipçiler
Ronald Pereira
Ronald Pereira@rondevz·
I struggled a bit with the text color (header) in the final composition but managed to solve it pretty quickly.
English
1
0
0
10
Ronald Pereira
Ronald Pereira@rondevz·
Was updating my own portfolio and I decided to try Hyperframes with GPT-5.4. It was a really fun experiment for today coding session.
English
1
0
1
25
Ronald Pereira retweetledi
Pablo Fredrikson
Pablo Fredrikson@PeladoNerd·
Hablemos de CVE-2026-31431 o "Copy Fail" es una vulnerabilidad que afecta TODOS los kernels de Linux desde 2017 en adelante y permite ganar acceso root con una línea de código:
Pablo Fredrikson tweet media
Español
19
217
1K
127.2K
Ronald Pereira retweetledi
The Hacker News
The Hacker News@TheHackersNews·
🛑 Gemini and Cursor vulnerabilities exposed direct code execution in dev workflows. #Gemini CLI (CVSS 10.0) auto-trusted folders in CI, letting malicious .gemini/ configs from PRs run on hosts. #Cursor bugs triggered hidden Git hooks and exposed local API keys via extensions. 🔗 Details → thehackernews.com/2026/04/google…
The Hacker News tweet media
English
13
99
322
42.3K
Ronald Pereira retweetledi
Jose Luis
Jose Luis@luicho9_·
@midudev cada día lo mismo
Jose Luis tweet media
Español
0
5
112
3.2K
Ronald Pereira retweetledi
Miguel Ángel Durán
Miguel Ángel Durán@midudev·
¡Mañana curso de OpenCode desde cero! El mejor agente de IA de código abierto. Horario por países: 18H 🇪🇸 17H 🇮🇨 13H 🇺🇾 🇦🇷 🇵🇾 12H 🇨🇱 🇹🇹 🇧🇴 🇻🇪 🇩🇴 🇨🇺 🇵🇷 11H 🇨🇴 🇵🇪 🇪🇨 🇵🇦 10H 🇲🇽 🇨🇷 🇳🇮 🇸🇻 🇭🇳 🇬🇹
Miguel Ángel Durán tweet media
Español
36
190
2.4K
130.8K
Ronald Pereira retweetledi
ぞくぞく@個人開発
ぞくぞく@個人開発@konekone2026·
猫ちゃんの強制休憩アプリを作りました! SNSをやりすぎると猫ちゃんがあらわれて画面を占領します🫪🐈
日本語
579
35.8K
153K
7M
Ronald Pereira
Ronald Pereira@rondevz·
A Roblox game exploit just caused a $2M data ransom for Vercel some days ago. Sounds like a joke, but it’s a textbook supply-chain attack. 🤯 It’s a massive wakeup call for how we handle OAuth and .env files. Here’s what happened, & how to secure your Laravel apps against it🧵
English
1
0
0
59
Fazt
Fazt@FaztTech·
Como que mi Claude Code anda rebelde hoy
Fazt tweet media
Español
18
18
528
25.5K
Ronald Pereira
Ronald Pereira@rondevz·
Aiming to release it next week! Until then, I’ll be posting some insights into the process and everything I've learned making Phant happen.
English
0
0
0
10
Ronald Pereira
Ronald Pereira@rondevz·
I’ve been working on Phant, my desktop app side project, for about 3 months now. It’s been an incredible journey of learning and building. 🚀
Ronald Pereira tweet media
English
1
0
0
41
Ronald Pereira retweetledi
El Programador Senior
El Programador Senior@5eniorDeveloper·
Si en un proceso de entrevista te piden ejecutar código de un repo de github 🚩🚩🚩
Español
22
41
2K
171.6K
Ronald Pereira
Ronald Pereira@rondevz·
Currently having fun on this Onboarding screen for Phant! Just plug and play!
Ronald Pereira tweet media
English
0
1
1
54
Ronald Pereira retweetledi
Miguel Ángel Durán
Miguel Ángel Durán@midudev·
¡Si usas Agentes de IA, necesitas usar Agent Skills! ¿El problema? Hay miles y es imposible estar al día. Esta herramienta detecta automáticamente las tecnologías de tu proyecto y te instala las mejores. $ npx autoskills
Miguel Ángel Durán tweet media
Español
40
314
2.6K
116.8K
Ronald Pereira retweetledi
fardeen
fardeen@fardeentwt·
every developer who ran npm install today just accidentally invited malware into their codebase and has no idea yet 💀
Feross@feross

🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.

English
33
123
2.3K
521.3K
Ronald Pereira retweetledi
Bun
Bun@bunjavascript·
`bun install` blocks postinstall scripts by default. This helps protect from supply-chain attacks, like today’s axios incident.
Bun tweet media
English
56
292
3K
193.1K