abraham
133 posts

abraham
@abemil7
ai consultant @ https://t.co/A4zkHj5wPP building @8studioPlatform pronouns: locked / in
medina Katılım Eylül 2025
87 Takip Edilen7 Takipçiler

Alexandria Ocasio-Cortez: You can't earn a billion dollars.
Ilana Glazer: That's right.
AOC: You just can't earn that.
Glazer: That's exactly correct.
AOC: You can get market power. You can break rules. You can do all sorts of things. You can abuse labor laws.
Glazer: Yup.
AOC: You can pay people less than what they're worth.
Glazer: Yup.
AOC: But you can't earn that, right?
Glazer: That's right.
AOC: And so you have to create a myth that -- since you didn't earn that, you have to create a myth of earning it.
English

Got a legit-looking @RobinhoodApp email today. Haven’t touched the account in years.
Downloaded the raw .eml and checked headers.
SPF ✅
DKIM ✅
DMARC ✅
It was actually sent from Robinhood’s infrastructure.
But the body had a phishing payload injected into it.
The top half of the email was normal:
“Your recent login to Robinhood”
Then inside the HTML, mid-content, it suddenly injected:
“UNRECOGNIZED ACTIVITY — Case #RH-6801”
with a “Review Activity” button.
That button did NOT go to robinhood.com.
It went to:
googletagmanager.com → redirect → tinzio.net
Classic cloaking.
This is what makes it dangerous:
This isn’t a spoof.
This isn’t a random phishing email.
It passed all authentication checks and came from a real sender.
What likely happened:
Some part of the email pipeline (template / dynamic field / notification system) got abused and allowed HTML injection.
So attackers piggybacked on a legit email.
Why this matters:
Most advice says “check the sender”.
That doesn’t work here.
Everything looked legit at the header level.
What to do instead:
Never click email buttons for anything financial
Always go directly to the app or type the URL manually
Treat urgency + “case numbers” as a red flag
Inspect link destinations (not just the visible text)
If something feels off, it probably is
What I did:
I downloaded the .eml file and sent it to an AI to analyze
Logged in manually
Changed password
Rotated 2FA
Checked devices + account changes
If you use Robinhood (or any fintech), assume this technique will get reused.
Real emails can still be weaponized.
Stay sharp.

English

@slattxbt @RobinhoodApp same, also i get calls everyday now from services asking for my 2fa :/ mostly from apple. i can imagine how they prey on the elderly
English

@abemil7 @RobinhoodApp Bro i thought i was tripping when i got the email I haven’t used Robinhood in 5 years 🤣
English

@abemil7 @RobinhoodApp Got the same. Notice SPF/DKIM/DMARC passed. Did their email service get compromised?
English

@TruthFromATL @RobinhoodApp sadly not everyone has these safe learning experiences
English

@abemil7 @RobinhoodApp luckily, my company has us to mandatory compliance training and phishing is one of those lessons we have to pass.
also we get random emails from the IT team as test and if we fail we have to do a class so i’m very aware 🫣
English

@TruthFromATL @RobinhoodApp ya mine too had the period in the middle, but idk i wouldnt call it obvious! it used to be much more obvious
English

@abemil7 @RobinhoodApp got the same email.
it’s obvious because my email doesn’t have a period in the middle.
i do feel bad for someone who’s not educated and panics and loses their life savings!
English

@ty_kra_lab any benchmarks on performance.. i wouldnt want to kill my main thread just for the liquid glass that could be gpu accelerated
English

I see Liquid Glass everywhere but the problem is everyone’s created a sphere and that’s it.
I prefer to create systems.
I’ve Vibecoded the full-fledged cpu based universal Liquid Glass design system that works on every browser and device , getting closer and closer to the official iOS 26 one.
Still working in progress before a full release.
English







