Skip to main content

Threats Tagged 'automation'

View all threats tagged with 'automation'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: automation

Threats Tagged 'automation'

Click on any threat for detailed analysis and mitigation recommendations

Shai-Hulud 2.0 is a highly aggressive and automated supply-chain malware targeting the npm ecosystem, identified in November 2025. It rapidly compromises hundreds of npm packages within hours, behaving like a worm that harvests credentials and cloud secrets. The malware leverages GitHub Actions as a persistent backdoor and creates public repositories to exfiltrate stolen data. This attack represents a significant escalation in supply-chain attack sophistication, affecting major projects and organizations globally. It results in tens of thousands of attacker-created GitHub repositories, facilitating widespread propagation. The malware automates spreading to new npm accounts, increasing infection speed and scale. It does not require user interaction once initial compromise occurs and exploits trusted software supply chains. No CVE or patch is currently available, and no known exploits in the wild have been reported yet. The attack’s medium severity rating may underestimate its potential impact given its worm-like behavior and credential theft capabilities.

Join the discussion

Axios user agent activity has surged by 241% from June to August 2025, outpacing other flagged user agents. Attacks combining Axios with Direct Send achieved a 70% success rate in recent campaigns, significantly higher than non-Axios campaigns. The combination exploits Direct Send's trusted nature and Axios's lightweight design to bypass traditional security defenses. Attackers are using Axios to automate phishing, credential stealing, and API exploitation at unprecedented scale. The campaign initially targeted high-profile individuals in finance, healthcare, and manufacturing, but has expanded to include everyday users. Organizations are advised to implement robust detection mechanisms for suspicious user-agent activity, particularly Axios-related patterns, to mitigate this evolving threat.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: automation
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses