Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

BPA-Free? New Study Shows Popular Replacements May Harm Human Cells

Researchers report that some chemicals used in printed food-package stickers as replacements for bisphenol A can still disrupt human ovarian cell function. Chemicals that have taken the place of bisphenol A (BPA) in food packaging may cause potentially harmful changes in human ovarian cells, acco

Hidden Brain Energy Leak Links Stress to Depression and Anxiety

Scientists found that reduced ATP signaling in the hippocampus can trigger both depression and anxiety in mice.

Lower ATP levels and a drop in connexin 43 expression appeared to make stressed animals more vulnerable. Manipulating this protein alone was enough to produce mood-related symptoms, while restoring it reversed them.

ATP Signaling and Mood Disorders.

Mysterious Structures Discovered Beneath Earth May Explain Why Our Planet Supports Life

A Rutgers researcher and collaborators have linked unusual geological anomalies to Earth’s molten origins and its unique habitability. For many years, researchers have struggled to understand two enormous and puzzling formations hidden deep within Earth. Their immense size and unusual traits make

Matrix Push C2 Uses Browser Notifications for Fileless, Cross-Platform Phishing Attacks

That’s not all. Since the attack plays out via the web browser, it’s also a cross-platform threat. This essentially turns any browser application on any platform that subscribes to the malicious notifications to be enlisted to the pool of clients, giving adversaries a persistent communication channel.

Matrix Push C2 is offered as a malware-as-a-service (MaaS) kit to other threat actors. It’s sold directly through crimeware channels, typically via Telegram and cybercrime forums, under a tiered subscription model: about $150 for one month, $405 for three months, $765 for six months, and $1,500 for a full year.

“Payments are accepted in cryptocurrency, and buyers communicate directly with the operator for access,” Dr. Darren Williams, founder and CEO of BlackFog, told The Hacker News. “Matrix Push was first observed at the beginning of October and has been active since then. There’s no evidence of older versions, earlier branding, or long-standing infrastructure. Everything indicates this is a newly launched kit.”

Second Sha1-Hulud Wave Affects 25,000+ Repositories via npm Preinstall Credential Theft

Multiple security vendors are sounding the alarm about a second wave of attacks targeting the npm registry in a manner that’s reminiscent of the Shai-Hulud attack.

The new supply chain campaign, dubbed Sha1-Hulud, has compromised hundreds of npm packages, according to reports from Aikido, HelixGuard, JFrog, Koi Security, ReversingLabs, SafeDep, Socket, Step Security, and Wiz. The trojanized npm packages were uploaded to npm between November 21 and 23, 2025. The attack has impacted popular packages from Zapier, ENS Domains, PostHog, and Postman, among others.

“The campaign introduces a new variant that executes malicious code during the preinstall phase, significantly increasing potential exposure in build and runtime environments,” Wiz researchers Hila Ramati, Merav Bar, Gal Benmocha, and Gili Tikochinski said.

/* */