n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails - The Hacker News
AI workflow platforms are becoming the new attack surface. n8n webhooks have been abused since October 2025 to deliver malware at scale.

Why it matters
As AI automation tools become critical infrastructure for businesses, they're becoming prime targets for threat actors. This n8n campaign reveals a systemic vulnerability in how enterprises trust and integrate AI workflow platforms—a gap that will force security and procurement decisions across leadership teams.
The key facts
5 to known8n webhooks abused since October 2025
Attack vector: phishing emails + device fingerprinting
Threat actors exploiting trusted webhook infrastructure
Multiple security firms covering (Cisco Talos, SC Media, CyberSecurityNews)
Malware delivery through workflow automation platform
Go to the source
Reuters Technologynews.google.com
Publisher excerpt: n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails The Hacker News The n8n n8mare: How threat actors are misusing AI workflow automation Cisco Talos Blog AI workflow platform n8n abused for phishing and device fingerprinting SC Media Malware Delivered Through Trusted…