Leaked n8n API Tokens Exposed 321 Live Instances
GitGuardian found 321 reachable n8n instances still accepting API tokens leaked in public GitHub commits. Revoke exposed keys, audit workflows and executions, and rotate connected credentials.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
September 13, 2026
GitGuardian found 321 reachable n8n instances still accepting API tokens leaked in public GitHub commits. Revoke exposed keys, audit workflows and executions, and rotate connected credentials.
N-central needs HF4 build 2026.3.1.14. Check appliance accounts and API logs, then investigate Take Control sessions and downstream persistence.
Arch temporarily stopped AUR pushes after malicious package takeovers. Check openconnect-sso exposure, Linux persistence, stolen secrets, and the right recovery order.
Rails patched CVE-2026-66066 in Active Storage. Check whether your app uses vulnerable libvips processing, update, rotate exposed secrets, and inspect official forensic evidence.
Coldcard weak seed generation affects Mk3 and earlier Mk4, Mk5, and Q releases. Updating stops new weak seeds but does not repair an existing…
A compromised Adform tracking script could replace Bitcoin, Ethereum, and Tron recipient addresses while an affected page was open. Check transfers and clear browser…
Crypto.com warns of targeted phishing emails about unfamiliar activity and fake bank-account changes. Check the Anti-Phishing Code, verify safely, and recover by exposure stage.
XCSSET v40 runs through trojanized Xcode projects and adds fileless persistence, browser theft, and defense evasion. Learn the build trigger, exposure boundary, and safe…
A Copilot for Word test showed a hidden instruction copying itself into generated documents. Here is the real trigger, what the research proves, and…