Rodrigo Moreno

10K posts

Rodrigo Moreno banner
Rodrigo Moreno

Rodrigo Moreno

@RodMoreno_

Head of Engineering @FluxQR; Node.js + DevOps;

🇲🇽 شامل ہوئے Mayıs 2008
349 فالونگ316 فالوورز
Rodrigo Moreno ری ٹویٹ کیا
Feross
Feross@feross·
🚨 CRITICAL: Active supply chain attack on axios -- one of npm's most depended-on packages. The latest axios@1.14.1 now pulls in plain-crypto-js@4.2.1, a package that did not exist before today. This is a live compromise. This is textbook supply chain installer malware. axios has 100M+ weekly downloads. Every npm install pulling the latest version is potentially compromised right now. Socket AI analysis confirms this is malware. plain-crypto-js is an obfuscated dropper/loader that: • Deobfuscates embedded payloads and operational strings at runtime • Dynamically loads fs, os, and execSync to evade static analysis • Executes decoded shell commands • Stages and copies payload files into OS temp and Windows ProgramData directories • Deletes and renames artifacts post-execution to destroy forensic evidence If you use axios, pin your version immediately and audit your lockfiles. Do not upgrade.
English
545
4.1K
16.3K
12.2M
sudox
sudox@kmcnam1·
sudox tweet media
ZXX
113
72
1.3K
54.2K
Rodrigo Moreno ری ٹویٹ کیا
Mercado Pago México
Mercado Pago México@MercadoPagoMex·
Tap to Pay en iPhone ya está disponible con Mercado Pago México 💳 Acepta pagos sin contacto en tu iPhone, sin terminal.
Mercado Pago México tweet media
Español
10
22
193
8.9K
Rodrigo Moreno ری ٹویٹ کیا
Iddar Olivares
Iddar Olivares@iddar·
🚀 Estamos contratando en CDMX Busco 2 perfiles Sr: 📊 Científico de Datos 🔧 Ingeniero de Datos ✅ Python + SQL ✅ Pipelines y automatización ✅ Experiencia en retail o consumo masivo ✅ Contratación inmediata CV a 👉 iddar@dbug.mx RT apreciado 🙏
Español
3
26
68
6K
Rodrigo Moreno ری ٹویٹ کیا
The Hacker News
The Hacker News@TheHackersNews·
🛑 ALERT - Trivy, a popular open-source vulnerability scanner, was compromised after attackers hijacked 75 version tags in #GitHub Actions to deliver an infostealer. It ran in CI pipelines, stealing creds and tokens, then exfiltrating data or staging it via stolen GitHub PATs. 🔗 Attack flow, impacted versions, fixes → thehackernews.com/2026/03/trivy-…
The Hacker News tweet media
English
11
159
505
122.8K
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
Hey @grafana team! 👋 Have you considered building an MCP server for Claude? Would be incredibly powerful to query dashboards, analyze metrics, suggest improvements, and even generate PromQL/LogQL queries through natural language. The observability + AI combo would be 🔥
English
1
0
0
41
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
Hey @namecom! 💡 An MCP server integration would be incredibly useful - imagine brainstorming project names with Claude and instantly checking domain availability, getting suggestions, and even registering them without leaving the conversation 🚀
English
0
0
0
30
Telefonias Unlimited
Telefonias Unlimited@TelefoniasU·
Buenas noticias para los usuarios de @Telmex @Telnor Al parecer estan aumentando la velocidad de los paquetes (Esperemos que el costo siga igual) 80 -> 120 100 -> 150 150 -> 250 350 -> 500 Falta confirmacion de los demas planes, gracias a @Tecnologo_909 por el aviso
Español
64
46
730
45.7K
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
@agucciverse @meatball_132 The ROM itself couldn’t do it, but the Emulator (Sloop) could. The ROM could write logs, which the Emulator then sent to Nintendo’s services.
English
0
0
0
44
Meatball132
Meatball132@meatball_132·
OK, here's my "the (English) Pokemon FireRed game for the Nintendo Switch system" cursory analysis. First of all, I dumped the game to immediately discover the most sad romfs ever:
Meatball132 tweet media
English
72
757
10.4K
899.8K
Meatball132
Meatball132@meatball_132·
@RodMoreno_ This is handled by the Switch OS, not the game, so I don't know exactly, but homebrewers have come up with a list of Nintendo addresses to block when running custom Switch firmware, so you could take a look at that: switch.hacks.guide/files/emummc.t…
English
1
1
37
10.8K
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
@meatball_132 What’s the URL used to collect that data? It would be interesting to block it through AdGuard or Pi-Hole.
English
2
0
5
12.4K
Meatball132
Meatball132@meatball_132·
Here's something from the emulator code: it sends telemetry about your game progress to Nintendo. There's quite a lot, including some things that aren't pictured, like which Pokemon you have and what level they're each at.
Meatball132 tweet media
English
46
164
2.5K
1.1M
Rodrigo Moreno ری ٹویٹ کیا
Cristian Córdova 🐧
Cristian Córdova 🐧@barckcode·
Vercel quejándose de que Cloudflare está poniendo “en peligro Internet” cuando en los últimos 3 meses hemos tenido que actualizar 400 veces NextJS por vulnerabilidades críticas 🙃 El chiste se cuenta solo…
Español
7
7
332
16.7K
Rodrigo Moreno ری ٹویٹ کیا
Azteca 7
Azteca 7@AztecaSiete·
30 años de aventuras, batallas y recuerdos 💛 Guarda la fecha y revive tus combates favoritos ⚡️🎉 ¡No te lo pierdas en #PokémonPorEl7
Azteca 7 tweet media
Español
33
306
2.3K
69.8K
Rodrigo Moreno
Rodrigo Moreno@RodMoreno_·
• CVE-2025-55183 — Source code exposure. • CVE-2026-23864 — Another DoS, CVSS 7.5, January 2026. The glass house was yours, @rauchg.
English
0
0
0
69
Rodrigo Moreno ری ٹویٹ کیا
Fernando de la Rosa 👨🏽‍💻🚀
¿Ya vieron que si era posible usar Vite en NextJS? Sólo no lo han hecho de forma oficial por que empresa del triangulo los quiere seguir sacando dinero.
Español
5
3
55
5.7K
Rodrigo Moreno ری ٹویٹ کیا
【公式】ポケモン情報局
@RodMoreno_ あなたが出会ったのは、このポケモン! キャンペーンへのご参加ありがとうございました! 30周年ロゴアイコンをランダムでプレゼント🎁
【公式】ポケモン情報局 tweet media
日本語
0
1
1
40
Abbey Kingsley ?🎃
Abbey Kingsley ?🎃@AbbeyKingsley·
Si la alcaldía @BJAlcaldia puede pedir apoyo de Subsecretaria de transito para quitar autos viejos, puede pedir apoyo para liberar banquetas de autos estacionados, no se yo digo, o aqui no porque a quien estorban es a peatones y no a automovilistas? 🤔
Abbey Kingsley ?🎃 tweet media
Español
3
18
50
1.3K