n8n
Coverage of n8n in the Nexus archive.
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers discovered 321 n8n instances with API tokens exposed in public GitHub commits, enabling attackers to access sensitive data and downstream credentials through four demonstrated methods without exploiting software vulnerabilities. Scans identified 4,576 unique credentials linked to 1,255 hostnames.
- New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go-based botnet named NadMesh is exploiting exposed AI services to steal cloud keys and Kubernetes tokens. The operator's dashboard reports 3,811 unique AWS keys collected, using Shodan to scan AI tools like ComfyUI, Ollama, and Gradio that teams often deploy without proper security.
- Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. A critical flaw impacting Ivanti Xtraction could be exploited to achieve information disclosure or client-side attacks. The vulnerabilities affect multiple products from these companies.
- n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails
Threat actors have been exploiting n8n, an AI workflow automation platform, since October 2025 to bypass security filters and deliver malware via phishing emails. These campaigns automate malicious email distribution, enabling device fingerprinting and payload delivery through trusted infrastructure.