Ingeniero de Software 💻 - Senior Backend Developer en @secture_com 🏴‍☠️ - Podcaster en @LeyendoSciFi 🎤- Escribo en medium.com/all-you-need-i

Joined April 2010
531 Photos and videos
Pinned Tweet
Nuevo post sobre Microservicios. Daremos un "breve" repaso a algunos conceptos sobre microservicios, cómo funcionan, cómo se comunican entre ellos, ventajas, inconvenientes... y mucho más! link.medium.com/rSNRZQngU7 #arquitectura #software #microservicios #programación
1
7
14
Si fue imposible saber quién era M. Rajoy estás tú que descubren quién es P. S.
13
Mangel Sánchez retweeted
🤩
115
472
7,927
606,450
Mangel Sánchez retweeted
Es que lo dejais a huevo. Hace 1 semana, una manifestación de derechas se saltó el recorrido autorizado e invadió una autopista, no solo es que no pegarais un porrazo, es que os empujaron ellos y ni os pusisteis los cascos.

Jun 1
Más vídeos de la actuación policial en Valencia Manifestantes tratando de invadir la calzada y la UIP lo evita El contexto en cualquier intervención policial es fundamental
167
8,483
21,407
461,277
Mangel Sánchez retweeted
mythos find all the laws that google, meta and openai break so we can fine them, make no mistakes
JUST IN: Anthropic offers EU access to Claude Mythos.
73
596
10,587
347,804
Mangel Sánchez retweeted
‼️🚨 UPDATE: The TanStack npm attack is now a full campaign. 'Mini' Shai-Hulud has hit: - OpenSearch - Mistral AI - Guardrails AI -UiPath - Squawk packages across npm and PyPI The malware specifically targets AI developer tooling. It hooks into Claude Code (.claude/settings.json) and VS Code (.vscode/tasks.json) to re-execute on every tool event, long after the infected package is gone. npm uninstall does not fix this.
‼️🚨 BREAKING: A new npm supply-chain attack uses a dead-man's switch. The payload plants a watcher on your machine that nukes your home directory the second you revoke the GitHub token it stole from you. The compromise happened today, across 42 official tanstack npm packages, 84 malicious versions in total. tanstack/react-router alone pulls more than 12 million weekly downloads. The attacker forked TanStack's repository and pushed a single hidden commit. From there, they tricked TanStack's own release system into signing the malicious packages as if they were the real thing. To npm, and to anyone checking the cryptographic proof of origin (SLSA provenance), the poisoned versions looked 100% legitimate. Maintainer Tanner Linsley confirmed the whole team had 2FA enabled. It didn't matter. This is the first documented npm worm in history that ships with a valid, signed certificate of authenticity, the same one defenders rely on to know a package wasn't tampered with.
128
742
3,967
2,666,241
Mangel Sánchez retweeted
Not exactly the type of nurse you would want to find in the fog.... Happy International Nurse Day! #SILENTHILL
26
495
3,046
60,554
Mangel Sánchez retweeted
❗️ Linux is having a brutal week. Another local to root privilege escalation vulnerability just dropped: "Copy Fail 2: Electric Boogaloo." This is the third Linux LPE in a row, after Copy Fail and Dirty Frag. The PoC is public on GitHub. There is still no coordinated patch. openwall.com/lists/oss-secur…

🚨 BREAKING: New Linux zero-day "Dirty Frag" lets ANY local user become root on most major distros. The PoC is already public, half of it isn't patched yet. Discovered by researcher Hyunwoo Kim, the exploit chains two kernel bugs and sits in the same family as Dirty Pipe and Copy Fail. ▪️ CVE-2026-43284 (xfrm-ESP Page-Cache Write): patched in mainline Linux. ▪️ CVE-2026-43500 (RxRPC Page-Cache Write): NO PATCH yet. The exploit is reliable by design. Attackers don't have to win a timing race, the system won't crash and alert anyone if it fails, and it succeeds nearly every run. The embargo got broken before distros could ship fixes, so the working code is now sitting on GitHub. Confirmed working on: Ubuntu 24.04.4, RHEL 10.1, openSUSE Tumbleweed, CentOS Stream 10, AlmaLinux 10, Fedora 44.
47
434
1,824
228,768
Mangel Sánchez retweeted
⚠️ El "313 Team" tiene Ubuntu.com fuera de servicio con un DDoS y un intento de extorsión a Canonical. A la vez, circula un exploit público de Copy Fail: 732 bytes de Python para conseguir root en casi cualquier Linux. Sin repos no hay parche. Y el reloj corre.
9
32
88
9,755
Mangel Sánchez retweeted
Es tan real que hasta molesta 😂
19
867
4,196
110,917
Mangel Sánchez retweeted
‼️🚨 BREAKING: An AI found a Linux kernel zero-day that roots every distribution since 2017. The exploit fits in 732 bytes of Python. Patch your kernel ASAP. The vulnerability is CVE-2026-31431, nicknamed "Copy Fail," disclosed today by Theori. It has been sitting quietly in the Linux kernel for nine years. Most Linux privilege-escalation bugs are picky. They need a precise timing window (a "race"), or specific kernel addresses leaked from somewhere, or careful tuning per distribution. Copy Fail needs none of that. It is a straight-line logic mistake that works on the first try, every time, on every mainstream Linux box. The attacker just needs a normal user account on the machine. From there, the script asks the kernel to do some encryption work, abuses how that work is wired up, and ends up writing 4 bytes into a memory area called the "page cache" (Linux's high-speed copy of files in RAM). Those 4 bytes can be aimed at any program the system trusts, like /usr/bin/su, the shortcut to becoming root. Result: the next time anyone runs that program, it lets the attacker in as root. What should worry most: the corruption never touches the file on disk. It only exists in Linux's in-memory copy of that file. If you imaged the hard drive afterwards, the on-disk file would match the official package hash exactly. Reboot the machine, or just put it under memory pressure (any normal system load that needs the RAM), and the cached copy reloads fresh from disk. Containers do not help either. The page cache is shared across the whole host, so a process inside a container can use this bug to compromise the underlying server and reach into other tenants. The original sin was a 2017 "in-place optimization" in a kernel crypto module called algif_aead. It was meant to make encryption slightly faster. The change broke a critical safety assumption, and nobody noticed for nine years. That bug then rode every kernel update from 2017 to today. This vulnerability affects the following: 🔴 Shared servers (dev boxes, jump hosts, build servers): any user becomes root 🔴 Kubernetes and container clusters: one compromised pod escapes to the host 🔴 CI runners (GitHub Actions, GitLab, Jenkins): a malicious pull request becomes root on the runner 🔴 Cloud platforms running user code (notebooks, agent sandboxes, serverless functions): a tenant becomes host root Timeline: 🔴 March 23, 2026: reported to the Linux kernel security team 🔴 April 1: patch committed to mainline (commit a664bf3d603d) 🔴 April 22: CVE assigned 🔴 April 29: public disclosure Mitigation: update your kernel to a build that includes mainline commit a664bf3d603d. If you cannot patch immediately, turn off the vulnerable module: echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf rmmod algif_aead 2>/dev/null || true For environments that run untrusted code (containers, sandboxes, CI runners), block access to the kernel's AF_ALG crypto interface entirely, even after patching. Almost nothing legitimate needs it, and blocking it shuts the door on this whole class of bug...
229
2,668
11,581
2,428,626
Mangel Sánchez retweeted
INFILTRADO EN EL REAL STATE Ayer se emitió “Se Nos Ha Ido De Las Manos”, un programa documental donde retratamos desde dentro la locura del mercado inmobiliario, donde el beneficio económico manda por encima de todo. #TamayoVivienda
293
3,803
13,343
1,899,523
Mangel Sánchez retweeted
Replying to @SocketSecurity
This is a daily occurrence at this point
1
36
812
41,973
Mangel Sánchez retweeted
🚨 Bitwarden CLI 2026.4.0 was compromised as part of the ongoing Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline. We’ll continue updating our coverage as more details are confirmed. socket.dev/blog/bitwarden-cl…
80
531
2,447
1,744,879
Mangel Sánchez retweeted
Lovable has a mass data breach affecting every project created before november 2025. I made a lovable account today and was able to access another users source code, database credentials, AI chat histories, and customer data are all readable by any free account. nvidia, microsoft, uber, and spotify employees all have accounts. the bug was reported 48 days ago. its not fixed. They marked it as duplicate and left it open.
269
712
5,670
1,415,374
Mangel Sánchez retweeted
Jose Ramon Perez Aguera, CTO/CPO de @Mercadona Tech, sobre cómo reemplazaron Algolia (€9-15k/mes) por un desarrollo propio para la web de Mercadona 29 decisiones técnicas que la IA no tomó. Las tomó un equipo con experiencia. El resultado: 85% de mejora en ranking, 0% búsquedas sin resultados (antes 4%), y de $9-15K/mes a menos de $900/mes.
27
121
988
152,956
Mangel Sánchez retweeted
Desde que EEUU tomó el control del petróleo venezolano, ya no te acuerdas de Maduro. Hoy, de la nada, no sabes cómo ni por qué te comenzó a caer mal Petro; en un tiempo odiarás a Lula de la nada. Tranquilo, no es que seas un idiota manipulable, sólo eres un librepensador 👍
187
4,678
18,705
192,229
Mangel Sánchez retweeted
Apr 6
Que pena que no quiera asistir a la tradicional declaración de la renta
El rey Juan Carlos asistió a la tradicional corrida del Domingo de Resurrección en Sevilla, acompañado por la infanta Elena.
270
9,679
42,709
708,413
Mangel Sánchez retweeted
> rebase
16
677
5,242
174,349
Ya echaba yo de menos a esta gente!!!
Programa especial de urgencia sobre el lanzamiento de la misión Artemisa 2, la primera tripulada con destino a la Luna desde hace mas de 50 años. Radio Skylab no podía perder esta ocasión y cuenta con la plantilla al completo. Todo listo, ¡Despegamos! radioskylab.es/2026/04/04/2x…
8