Cybersecurity Daily: News & Threats · 28 Jul 2026 · 5 min

SourTrade In-Browser Assembly, n8n Sandbox Escape & Origin Energy Breach

A malvertising campaign assembling malware inside victims' browsers, a high-severity n8n sandbox escape enabling OS command execution, and a confirmed data breach at Australian energy giant Origin Energy — three stories redefining where your defenses need to sit. Today's briefing unpacks the technical detail and what each means for your security posture.

Cybersecurity Daily: News & Threats
Now Playing
SourTrade In-Browser Assembly, n8n Sandbox Escape & Origin Energy Breach

Audio is available on Spreaker — see link below.

What's covered

SourTrade Browser Assembly Attack

A malvertising campaign called SourTrade is now assembling malware directly inside victims' browsers, and that single shift in technique breaks most of what traditional detection was built to catch. Here's what makes this different.

Listen now →

n8n Sandbox Escape CVE

The second story is a high-severity sandbox escape in n8n, the widely used workflow automation platform, patched in versions two point thirty-one point five and two point thirty-two point one. n8n uses an expression sandbox to evaluate JavaScript in workflow definitions. The sandbox rewrites code at the AST level to redirect JavaScript identifiers into a controlled data context, which is meant to prevent access to real Node.js globals.

Listen now →

Origin Energy Customer Data Breach

The third story comes from Australia's energy sector. Origin Energy has confirmed unauthorized access to customer records, including names, addresses, dates of birth, contact information, and partial payment details.

Listen now →

Three Themes Worth Tracking

Pull back and these three stories share a common thread. SourTrade relies on tricking users into a malicious ad flow.

Listen now →

What To Watch Next

What to watch going forward: n8n needs to clarify cloud exposure, and the community should watch for whether the underlying AST rewriting architecture gets a more substantial redesign or just another point patch. On SourTrade, final payload confirmation will tell us how financially motivated this operation really is.

Listen now →

Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.

More episodes

From Cybersecurity Daily: News & Threats