Toggle light / dark theme

Fake Google Security site uses PWA app to steal credentials, MFA codes

A phishing campaign is using a fake Google Account security page to deliver a web-based app capable of stealing one-time passcodes, harvesting cryptocurrency wallet addresses, and proxying attacker traffic through victims’ browsers.

The attack leverages Progressive Web App (PWA) features and social engineering to deceive users into believing they are interacting with a legitimate Google Security web page and inadvertently installing the malware.

PWAs run in the browser and can be installed from a website, just like a standalone regular application, which is displayed in its own window without any visible browser controls.

Malicious npm Packages Harvest Crypto Keys, CI Secrets, and API Tokens

Cybersecurity researchers have disclosed what they say is an active “Shai-Hulud-like” supply chain worm campaign that has leveraged a cluster of at least 19 malicious npm packages to enable credential harvesting and cryptocurrency key theft.

The campaign has been codenamed SANDWORM_MODE by supply chain security company Socket. As with prior Shai-Hulud attack waves, the malicious code embedded into the packages comes with capabilities to siphon system information, access tokens, environment secrets, and API keys from developer environments and automatically propagate by abusing stolen npm and GitHub identities to extend its reach.

“The sample retains Shai-Hulud hallmarks and adds GitHub API exfiltration with DNS fallback, hook-based persistence, SSH propagation fallback, MCP server injection with embedded prompt injection targeting AI coding assistants, and LLM API Key harvesting,” the company said.

The Deflationary Singularity: Why Everything is Going to ZERO w/ Salim Ismail

The rapid advancement of technologies, particularly AI, is driving the world towards an economic singularity where the marginal cost of essentials approaches zero, leading to a deflationary future and a potential transformation of traditional systems and societies ##

## Questions to inspire discussion.

Education Transformation.

🎓 Q: How will AI reduce education time while improving effectiveness?

A: AI will customize education to each child’s learning style, reducing daily learning time to 1 hour per day while delivering 5 times more effective learning compared to traditional methods, with costs falling to zero within 3–5 years and breaking the university industry that currently creates massive student debt.

Healthcare Revolution.

Amaterasu Particle That Broke Physics Has Finally Been Explained

A mysterious, extremely energetic particle, known as the Amaterasu particle, was detected coming from a distant region of space, and scientists have proposed explanations for its origin, potentially tracing it back to a starburst galaxy like Messier 82 ##

## Questions to inspire discussion.

Understanding Ultra-High Energy Cosmic Rays.

🔬 Q: What makes the Amaterasu particle exceptionally powerful? A: The Amaterasu particle detected in Utah in 2021 carries energy 40 million times higher than anything produced on Earth, equivalent to a baseball traveling at 100 km/h compressed into a single subatomic particle, making it one of the most energetic particles ever detected.

Solving the Origin Mystery.

🎯 Q: Where did scientists determine the Amaterasu particle actually originated? A: A 2026 study by Max Planck Institute scientists using approximate Bayesian computation and 3D magnetic field simulations traced the particle’s origin to a starburst galaxy like Messier 82, located 12 million light-years away, rather than the initially suspected local void with only six known galaxies.

Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

Cybersecurity researchers have discovered a fresh set of malicious packages across npm and the Python Package Index (PyPI) repository linked to a fake recruitment-themed campaign orchestrated by the North Korea-linked Lazarus Group.

The coordinated campaign has been codenamed graphalgo in reference to the first package published in the npm registry. It’s assessed to be active since May 2025.

“Developers are approached via social platforms like LinkedIn and Facebook, or through job offerings on forums like Reddit,” ReversingLabs researcher Karlo Zanki said in a report. “The campaign includes a well-orchestrated story around a company involved in blockchain and cryptocurrency exchanges.”

We Just Found a Mind-blowing New World of Electrostatic Biology

Support this channel on Patreon to help me make this a full time job: https://www.patreon.com/whatdamath (Unreleased videos, extra footage, DMs, no ads)
Alternatively, PayPal donations can be sent here: http://paypal.me/whatdamath.
Get a Wonderful Person Tee: https://teespring.com/stores/whatdamath.
More cool designs are on Amazon: https://amzn.to/3QFIrFX

Hello and welcome! My name is Anton and in this video, we will talk about a strange electrostatic world of tiny organisms.
Links:
https://www.pnas.org/doi/epdf/10.1073/pnas.2503555122
https://www.cell.com/action/showPdf?pii=S0960-9822%2823%2900674-7
http://cell.com/current-biology/fulltext/S0960-9822(23)00772-8
Other videos:


#biology #science #electrostatics.

0:00 Static phenomena and electrostatic ecology.
1:50 Pollen and bees.
3:00 Flying spiders and ballooning.
4:10 Ticks.
4:40 Electrosensation.
5:40 Worms and jumping.
7:50 Worm parasites.
9:50 Practical applications and aeroplankton.

Enjoy and please subscribe.

Bitcoin/Ethereum to spare? Donate them here to help this channel grow!
bc1qnkl3nk0zt7w0xzrgur9pnkcduj7a3xxllcn7d4
or ETH: 0x60f088B10b03115405d313f964BeA93eF0Bd3DbF

The hardware used to record these videos:

We Learned a Bit More About How Human Brains Became So Complex

Support this channel on Patreon to help me make this a full time job: https://www.patreon.com/whatdamath (Unreleased videos, extra footage, DMs, no ads)
Alternatively, PayPal donations can be sent here: http://paypal.me/whatdamath.
Get a Wonderful Person Tee: https://teespring.com/stores/whatdamath.
More cool designs are on Amazon: https://amzn.to/3QFIrFX

Hello and welcome! My name is Anton and in this video, we will talk about a few studies that explain how the human brain developed complexity.
Links:
https://linkinghub.elsevier.com/retrieve/pii/S0092867423009170
https://www.science.org/doi/10.1126/science.ade5645
https://www.biorxiv.org/content/10.1101/2024.05.01.592020v5.full.pdf.
https://www.science.org/doi/10.1126/science.abm1696
https://www.nature.com/articles/s41559-022-01925-6
https://www.microbiologyresearch.org/content/journal/mgen/10…01322#tab2
Other videos:
https://www.youtube.com/watch?v=qyMbXCzcS0k.
https://www.youtube.com/watch?v=e10yOoP-x3g.

#brain #biology #evolution.

0:00 Discoveries about the evolution of the brain.
1:20 800 Million years ago… how it all began.
3:10 Did nervous system evolve multiple times? Comb jellies.
4:45 Big brains — primates vs octopuses.
9:20 Human brains and human intelligence genes.
11:20 Gut microbes and fuel for the brain.
12:20 Conclusions and implications.

Enjoy and please subscribe.

Bitcoin/Ethereum to spare? Donate them here to help this channel grow!
bc1qnkl3nk0zt7w0xzrgur9pnkcduj7a3xxllcn7d4
or ETH: 0x60f088B10b03115405d313f964BeA93eF0Bd3DbF

The hardware used to record these videos:

Experiments Hint on Time Being an Illusion

Support this channel on Patreon to help me make this a full time job: https://www.patreon.com/whatdamath (Unreleased videos, extra footage, DMs, no ads)
Alternatively, PayPal donations can be sent here: http://paypal.me/whatdamath.
Get a Wonderful Person Tee: https://teespring.com/stores/whatdamath.
More cool designs are on Amazon: https://amzn.to/3QFIrFX

Hello and welcome! My name is Anton and in this video, we will talk about experimental evidence that time may be an illusion.
Links:
https://arxiv.org/pdf/2310.13386
https://journals.aps.org/prd/pdf/10.1103/qfns-48vq.
https://en.wikipedia.org/wiki/Problem_of_time.
https://journals.aps.org/prl/pdf/10.1103/5rtj-djfk.
https://journals.aps.org/prx/pdf/10.1103/PhysRevX.11.021029
https://journals.aps.org/prx/pdf/10.1103/PhysRevX.7.031022
#time #physics #universe.

0:00 Time — what is it?
1:20 Time in general relativity (Einstein)
2:10 Quantum mechanics time.
2:40 The problem of time.
3:30 Page Wootters mechanism — is time emergent?
5:00 Experiments and possible proofs — entropy and quantum dots.
7:40 Large scale system.
8:30 What this suggests and how black holes can help.
9:50 Conclusions.

Enjoy and please subscribe.

Bitcoin/Ethereum to spare? Donate them here to help this channel grow!
bc1qnkl3nk0zt7w0xzrgur9pnkcduj7a3xxllcn7d4
or ETH: 0x60f088B10b03115405d313f964BeA93eF0Bd3DbF

The hardware used to record these videos:

New GlassWorm attack targets macOS via compromised OpenVSX extensions

A new GlassWorm malware attack through compromised OpenVSX extensions focuses on stealing passwords, crypto-wallet data, and developer credentials and configurations from macOS systems.

The threat actor gained access to the account of a legitimate developer (oorzc) and pushed malicious updates with the GlassWorm payload to four extensions that had been downloaded 22,000 times.

GlassWorm attacks first appeared in late October, hiding the malicious code using “invisible” Unicode characters to steal cryptocurrency wallet and developer account details. The malware also supports VNC-based remote access and SOCKS proxying.

A Breakthrough That Cuts Blockchain Delays Nearly in Half

The idea of a fully connected digital world is quickly becoming real through the Internet of Things (IoT). This expanding network includes physical devices such as small sensors, autonomous vehicles, and industrial machines that collect and exchange data online.

Protecting this data from tampering is essential, which has led engineers to explore blockchain as a security solution. Although blockchain is widely known for its role in cryptocurrencies, its core function is as a decentralized digital ledger. Instead of data being controlled by a single organization, information is shared and maintained across many computers.

/* */