The n8n n8mare: How threat actors are misusing AI workflow automation

Investigation reveals widespread abuse of n8n, an AI workflow automation platform, in sophisticated phishing campaigns from October 2025 through March 2026. Attackers exploit the platform's webhook functionality to deliver malware and fingerprint devices while bypassing security filters through trusted infrastructure. Email volume containing n8n webhook URLs increased by 686% between January 2025 and March 2026. Observed campaigns utilize CAPTCHA-protected pages to deliver remote access tools including modified Datto RMM and ITarian Endpoint Management software. The webhooks mask malicious payload sources behind legitimate n8n domains. Additional abuse cases involve tracking pixels embedded in emails for device fingerprinting. These attacks demonstrate how legitimate productivity and automation platforms can be weaponized, requiring behavioral detection approaches rather than simple domain blocking to protect organizational workflows.

Pulse ID: 69dfa9e58a74337f7fb97333
Pulse Link: https://otx.alienvault.com/pulse/69dfa9e58a74337f7fb97333
Pulse Author: AlienVault
Created: 2026-04-15 15:08:21

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CAPTCHA #CyberSecurity #Email #Endpoint #InfoSec #Malware #OTX #OpenThreatExchange #Phishing #RAT #RCE #Rust #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

RE: https://toad.social/@bruceturner/116398671798296895

Este toot representa el asco que siento cada vez que me salta el #Captcha de Google.

Just curious, does anyone else take a captcha challenge from a merchant's website as an indication that they aren't interested in your business? How about you hire some people to identify busses and leave me out of it?
#captcha
🚍🤖 Ah, the #future is here: #AI #cameras dishing out #tickets like candy, and Bloomberg's #CAPTCHA is the final boss. Click this box to prove you're not a bot, while AI #school #bus cameras prove they can out-fine humans any day! 🙃💸
https://www.bloomberg.com/news/features/2026-04-14/buspatrol-school-bus-traffic-tickets-have-limited-safety-benefits-critics-say #Technology #HackerNews #ngated
The AI School Bus Camera Company Blanketing America in Tickets

BusPatrol says its technology helps curb dangerous driving at no cost to cities. Public records from across the US often tell a different story.

Bloomberg.com

Just built GitCaptcha.

Before every git commit, it shows you a CAPTCHA in ASCII art and makes you prove you're human.

Because nothing says “secure software engineering” like solving pixelated text from a Docker container.

https://github.com/pointless-code/git-captcha

#pre-commit #git-hooks #devtools #NodeJs #captcha #CodingHumor #DevLife #Docker #JavaScript #MemeTech #pointless

Why meaningful days look like a 404 error: Because life’s greatest moments are best spent staring at #CAPTCHA challenges and Firewalls. 🤦‍♂️✨ If #enlightenment is one cookie click away, count me out. 🍪🚫
https://pilgrima.ge/p/the-grand-line #meaningfuldays #404error #digitalwellbeing #cookieclicks #HackerNews #ngated
The Grand Line

On bronze pirates, cloudy days, and the roads we do not know we are walking

The Pilgrim Age
Captchas Cognitivos: Más fácil con IA que con ojos

Blog personal de Chema Alonso ( https://MyPublicInbox.com/ChemaAlonso ): Ciberseguridad, IA, Innovación, Tecnología, Cómics & Cosas Personasles.

So #Microsoft #Teams is now asking me to solve a #Captcha before joining a call I was invited to. 🙄

Thanks to Microsoft, for supporting #digitalIndependence by making it so hard to create an #MSGitHub account that people just give up and go to e.g. @Codeberg instead!

A friend tried to create an account these days. They gave them the option of a visual or an audio #CAPTCHA. Both are not *one* CAPTCHA, but a series of *ten*.

If my friend insists on having an MS-GitHub account, they has to solve the CAPTCHA with #AI. Humans have no chance:

(1/2)

#digitalSovereignty #codeberg #GAFAM