When Routine Becomes Risk: Rethinking Trust in a Fully Automated World
In cybersecurity, we’ve long focused on defending against what’s new–zero-days, sophisticated campaigns, advanced persistent threats.
But increasingly, the larger scale breaches aren’t achieving their impact through novelty. They are finding it instead in normalcy—common developer workflows, default execution routines, and the mundane like.
The Shai Hulud worm has impacted the widely used Node Package Manager software repository in two major waves in 2025, in September and again last week. So far, the self-replicating attack has compromised hundreds of widely-used packages and tens of thousands of GitHub repositories. The September variant stole sensitive developer, CI/CD, and cloud credentials and exfiltrated data. The November variant is more destructive; if it fails in its objective to steal tokens or credentials, or secure an exfiltration channel, it attempts to destroy the victim's entire home directory by deleting every writable file owned by the current user under their home folder.
What I find most interesting and alarming about this worm is its subtlety. It didn’t break through firewalls or exploit an unpatched vulnerability. Instead, it moved silently, through developer workflows, automation tokens, and CI/CD systems that organizations rely on every day. It exploited what we trust.
And that’s the real shift: routine is now the risk surface. What we automate, standardize, and assume to be safe is often the most scalable way in.
In cybersecurity, familiarity breeds blind spots. The systems we see every day, the scripts that run in the background, the dependencies that update without ceremony, these are precisely what we often overlook. And over time, that oversight creates a false sense of safety.
Automation Doesn’t Eliminate Risk, It Amplifies Assumptions
Modern development pipelines are built for speed, scale, and abstraction. That’s what makes software move faster. But speed often comes at the expense of visibility, and abstraction introduces new layers we stop questioning.
When workflows are trusted by default—build scripts, deployment tokens, publishing mechanisms—they multiply the impact of any single compromised node. Shai Hulud didn’t just find a way in; it found a way through, because no one was looking.
Trust is Technical Debt
Every time we trust a process we don’t test, we embed technical debt into our security program.
Recommended by LinkedIn
And like any form of debt, the longer it goes unexamined, the more expensive it becomes to unwind. That’s why security programs built on static assessments and assumed safe zones inevitably fall behind the adversary.
With the rapid pace of attacker innovation, cyber risk isn’t only in what’s believed to be exploitable. It’s everywhere. Including what’s assumed to be proven and safe, and yet still isn’t.
Reclaiming Visibility through Adversarial Testing
The way forward isn’t simply more scanning or stricter controls. What’s needed is a mindset shift: from compliance coverage to continuous challenge.
At HackerOne, we believe the only way to surface what systems obscure is through adversarial pressure: ethical hackers continuously probing for the novel and elusive vulnerabilities, AI red teaming, and continuous validation of trusted processes.
We’re investing in visibility across every layer that matters–code, cloud, and AI systems.
This isn’t just about finding vulnerabilities. It’s about continuously testing the assumptions we’ve stopped examining.
Where Are You Trusting Without Testing?
It’s time to shift the conversation from edge-based defense to assumption-based visibility. Let’s challenge what we’ve normalized—and rethink what we define as “safe.”
Because in today’s environment, the greatest risk isn’t what we don’t know, it’s what we don’t question.
Thanks for sharing Kara Sprague, HackerOne always taking #CyberSecurity Seriously even in jest ➡️ Dusting the sand off to give a more fresh perspective, love the article 💛💙 #FemaleLeadership #SurfsUP #SFtech #SanFrancisco #WeLoveOurCity