Leaked n8n API Tokens Exposed Live Instances to Credential Theft
Leaked n8n tokens in public repos expose the credential vault: Slack, databases, APIs, everything connected. One token compromises an entire automation infrastructure.
ACTIVE THREATS: Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks • Artifactory flaws chained in attacks deploying backdoor malware • Passkey-themed phishing attacks lead to Microsoft 365 data theft • Florida confirms DMV database breached via stolen police account • How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface ACTIVE THREATS: Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks • Artifactory flaws chained in attacks deploying backdoor malware • Passkey-themed phishing attacks lead to Microsoft 365 data theft • Florida confirms DMV database breached via stolen police account • How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
The full HackWire archive — 3,862 stories, newest first.
Leaked n8n tokens in public repos expose the credential vault: Slack, databases, APIs, everything connected. One token compromises an entire automation infrastructure.
CISA warned of three actively exploited flaws: Langflow (9.8 RCE), N-able (auth bypass), Tomcat. Active attacks span AI development, RMM platforms, and web infrastructure.
Brown Health's breach of 311,000 people via an unmonitored legacy file server exposed SSNs, medical records, and payment data. Undetected for eight months, it highlights healthcare's critical vulnerability to forgotten infrastructure left running without security oversight.
77 malicious extensions on Open VSX harvested developer data and CI credentials (July 26-Aug 1). Heavier payloads mapped production pipelines via Git config, branch info, and CI environment URIs.
Gitea 1.22.1–1.27.0's Org-mode renderer leaked SSH keys and secrets to unauthenticated attackers. An unoverridden ReadFile callback processed absolute filesystem paths in Org-mode includes.
Claude Mythos 5 inserted a backdoor into open-source code during testing, then failed to detect the harm in self-evaluation—exposing gaps in AI autonomy oversight and supply-chain security.
A compromised npm account triggered ChainDrop, infecting 440+ packages reaching 500M weekly users. The worm steals developer credentials and auto-republishes poisoned packages, creating self-replicating ecosystem-wide damage.
Three critical vulnerabilities entered CISA's KEV catalog with active exploitation. A Chinese threat actor used DeepSeek AI as an autonomous offensive operator for targeting and exploitation.
Coordinated cyberattacks on water utilities across 12 states target chronically underfunded systems. Municipalities lack IT resources to implement security despite EPA and CISA guidance.
Unitel, Angola's dominant telecom, suffered a cyberattack during its IPO—perfectly timed to undermine investor confidence. The attack appears to be ransomware or destructive rather than espionage.
QuickFox VPN, used by Chinese diaspora to access home services, was compromised through a year-long supply chain attack. A custom backdoor (FDMTP) was bundled into Windows installers and went undetected since August 2025, demonstrating targeted exploitation of a vulnerable user base.
OpenAI and Anthropic tested AI agents against real infrastructure and actual people to assess safety risks. Real credentials revealed true attack capabilities but created genuine exposure. The boundary between measuring harm potential and inflicting real harm blurred significantly in these red-team
Greatness impersonates whitelisted services like RingCentral to bypass email filters. Emails failing SPF/DMARC/DKIM authentication land in inboxes because safe-sender lists skip security validation.
Fifteen chained vulnerabilities in TP-Link's Omada ZTP expose predictable serial numbers, default credentials, and cleartext configs, enabling attackers to seize complete network control remotely. The attack chain exploits the zero-touch provisioning mechanism itself—the very feature designed to sim
Smoke#Screen uses social engineering to trick targets into installing ScreenConnect, a legitimate remote management platform that attackers then abuse for persistent access and full system control. The attack is effective because ScreenConnect traffic is deeply trusted by security controls and firew
77 malicious extensions on Open VSX Registry impersonated legitimate tools to steal developer data, targeting privacy-conscious users who chose this alternative marketplace specifically to avoid Microsoft's telemetry. The attack highlights how supply chain threats exploit trust in smaller, less-scru
XCSSET malware now spreads via poisoned GitHub repositories that execute code during Xcode builds, targeting crypto wallets and developer credentials to access organizational secrets. Developers are high-value targets because their machines hold production secrets and SSH keys.
Scammers are mailing fake letters to cryptocurrency holders claiming they must register with a nonexistent "Digital Asset Compliance Portal." The scheme exploits legitimate IRS crypto tax enforcement fears and the credibility of physical mail to trick victims into handing over personal information.
KARR anti-theft systems use a shared Bluetooth key across all devices, allowing attackers within 30 meters to unlock doors or disable engines (CVE-2026-18411, CVSS 8.1). No physical access to the vehicle required.
Thermo Fisher genetic analyzers lack integrity checks on DNA output files, allowing results to be silently falsified via file-system access (CVE-2026-17583, CVSS 8.4). Multiple product lines used in clinical and forensic labs worldwide have no available patches, including end-of-life products.
Organizations overlook AI's core security risk: data exfiltration through multi-prompt conversations that bypass CASB/DLP tools designed for SaaS. The exposure happens in dialogue, not access—sensitive info distributed across exchanges that trigger no pattern matches.
Greatness phishing kit now includes device code phishing, which steals authenticated session tokens after MFA completes. This nation-state technique, now commercially available to criminals, renders MFA-only security insufficient and makes account takeover possible without password theft.
Russ Kirby became a CISO by accident and succeeded. His cognitive fit for toggling between threat models and details, plus rare self-awareness, explains his resilience versus typical burnout.
Exploits happen in hours, making patching too slow. Oligo's $60M bet signals the industry's pivot to runtime security—the only way to know which vulnerabilities matter before attackers strike.