Rodrigo Moreno

10K posts

Rodrigo Moreno banner
Rodrigo Moreno

Rodrigo Moreno

@RodMoreno_

Head of Engineering @FluxQR; Node.js + DevOps;

🇲🇽 Entrou em Mayıs 2008
349 Seguindo316 Seguidores
Rodrigo Moreno retweetou
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
545
4.1K
16.3K
12.2M
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
113
72
1.3K
54.2K
Rodrigo Moreno retweetou
Mercado Pago México
Mercado Pago México@MercadoPagoMex·
Tap to Pay en iPhone ya está disponible con Mercado Pago México 💳 Acepta pagos sin contacto en tu iPhone, sin terminal.
Mercado Pago México tweet media
Español
10
22
193
9K
Rodrigo Moreno retweetou
Iddar Olivares
Iddar Olivares@iddar·
🚀 Estamos contratando en CDMX Busco 2 perfiles Sr: 📊 Científico de Datos 🔧 Ingeniero de Datos ✅ Python + SQL ✅ Pipelines y automatización ✅ Experiencia en retail o consumo masivo ✅ Contratación inmediata CV a 👉 iddar@dbug.mx RT apreciado 🙏
Español
3
26
68
6K
Rodrigo Moreno retweetou
The Hacker News
The Hacker News@TheHackersNews·
🛑 ALERT - Trivy, a popular open-source vulnerability scanner, was compromised after attackers hijacked 75 version tags in #GitHub Actions to deliver an infostealer. It ran in CI pipelines, stealing creds and tokens, then exfiltrating data or staging it via stolen GitHub PATs. 🔗 Attack flow, impacted versions, fixes → thehackernews.com/2026/03/trivy-…
The Hacker News tweet media
English
11
159
505
122.9K
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
Hey @grafana team! 👋 Have you considered building an MCP server for Claude? Would be incredibly powerful to query dashboards, analyze metrics, suggest improvements, and even generate PromQL/LogQL queries through natural language. The observability + AI combo would be 🔥
English
1
0
0
41
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
Hey @namecom! 💡 An MCP server integration would be incredibly useful - imagine brainstorming project names with Claude and instantly checking domain availability, getting suggestions, and even registering them without leaving the conversation 🚀
English
0
0
0
30
Telefonias Unlimited
Telefonias Unlimited@TelefoniasU·
Buenas noticias para los usuarios de @Telmex @Telnor Al parecer estan aumentando la velocidad de los paquetes (Esperemos que el costo siga igual) 80 -> 120 100 -> 150 150 -> 250 350 -> 500 Falta confirmacion de los demas planes, gracias a @Tecnologo_909 por el aviso
Español
64
46
730
45.7K
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
@agucciverse @meatball_132 The ROM itself couldn’t do it, but the Emulator (Sloop) could. The ROM could write logs, which the Emulator then sent to Nintendo’s services.
English
0
0
0
44
Meatball132
Meatball132@meatball_132·
OK, here's my "the (English) Pokemon FireRed game for the Nintendo Switch system" cursory analysis. First of all, I dumped the game to immediately discover the most sad romfs ever:
Meatball132 tweet media
English
72
757
10.4K
899.8K
Meatball132
Meatball132@meatball_132·
@RodMoreno_ This is handled by the Switch OS, not the game, so I don't know exactly, but homebrewers have come up with a list of Nintendo addresses to block when running custom Switch firmware, so you could take a look at that: switch.hacks.guide/files/emummc.t…
English
1
1
37
10.8K
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
@meatball_132 What’s the URL used to collect that data? It would be interesting to block it through AdGuard or Pi-Hole.
English
2
0
5
12.4K
Meatball132
Meatball132@meatball_132·
Here's something from the emulator code: it sends telemetry about your game progress to Nintendo. There's quite a lot, including some things that aren't pictured, like which Pokemon you have and what level they're each at.
Meatball132 tweet media
English
46
164
2.5K
1.1M
Rodrigo Moreno retweetou
Cristian Córdova 🐧
Cristian Córdova 🐧@barckcode·
Vercel quejándose de que Cloudflare está poniendo “en peligro Internet” cuando en los últimos 3 meses hemos tenido que actualizar 400 veces NextJS por vulnerabilidades críticas 🙃 El chiste se cuenta solo…
Español
7
7
332
16.7K
Rodrigo Moreno retweetou
Azteca 7
Azteca 7@AztecaSiete·
30 años de aventuras, batallas y recuerdos 💛 Guarda la fecha y revive tus combates favoritos ⚡️🎉 ¡No te lo pierdas en #PokémonPorEl7
Azteca 7 tweet media
Español
33
306
2.3K
69.8K
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
• CVE-2025-55183 — Source code exposure. • CVE-2026-23864 — Another DoS, CVSS 7.5, January 2026. The glass house was yours, @rauchg.
English
0
0
0
69
Rodrigo Moreno retweetou
Fernando de la Rosa 👨🏽‍💻🚀
¿Ya vieron que si era posible usar Vite en NextJS? Sólo no lo han hecho de forma oficial por que empresa del triangulo los quiere seguir sacando dinero.
Español
5
3
55
5.7K
Rodrigo Moreno retweetou
【公式】ポケモン情報局
@RodMoreno_ あなたが出会ったのは、このポケモン! キャンペーンへのご参加ありがとうございました! 30周年ロゴアイコンをランダムでプレゼント🎁
【公式】ポケモン情報局 tweet media
日本語
0
1
1
40
Abbey Kingsley ?🎃
Abbey Kingsley ?🎃@AbbeyKingsley·
Si la alcaldía @BJAlcaldia puede pedir apoyo de Subsecretaria de transito para quitar autos viejos, puede pedir apoyo para liberar banquetas de autos estacionados, no se yo digo, o aqui no porque a quien estorban es a peatones y no a automovilistas? 🤔
Abbey Kingsley ?🎃 tweet media
Español
3
18
50
1.3K