A malvertising campaign assembling malware inside victims' browsers, a high-severity n8n sandbox escape enabling OS command execution, and a confirmed data breach at Australian energy giant Origin Energy — three stories redefining where your defenses need to sit. Today's briefing unpacks the technical detail and what each means for your security posture.
Audio is available on Spreaker — see link below.
A malvertising campaign called SourTrade is now assembling malware directly inside victims' browsers, and that single shift in technique breaks most of what traditional detection was built to catch. Here's what makes this different.
The second story is a high-severity sandbox escape in n8n, the widely used workflow automation platform, patched in versions two point thirty-one point five and two point thirty-two point one. n8n uses an expression sandbox to evaluate JavaScript in workflow definitions. The sandbox rewrites code at the AST level to redirect JavaScript identifiers into a controlled data context, which is meant to prevent access to real Node.js globals.
The third story comes from Australia's energy sector. Origin Energy has confirmed unauthorized access to customer records, including names, addresses, dates of birth, contact information, and partial payment details.
Pull back and these three stories share a common thread. SourTrade relies on tricking users into a malicious ad flow.
What to watch going forward: n8n needs to clarify cloud exposure, and the community should watch for whether the underlying AST rewriting architecture gets a more substantial redesign or just another point patch. On SourTrade, final payload confirmation will tell us how financially motivated this operation really is.
Chapter summary auto-generated from the verified script. Listen to the full episode for the complete content.