SourTrade In-Browser Assembly, n8n Sandbox Escape & Origin Energy Breach
カートのアイテムが多すぎます
ご購入は五十タイトルがカートに入っている場合のみです。
カートに追加できませんでした。
しばらく経ってから再度お試しください。
ウィッシュリストに追加できませんでした。
しばらく経ってから再度お試しください。
ほしい物リストの削除に失敗しました。
しばらく経ってから再度お試しください。
ポッドキャストのフォローに失敗しました
ポッドキャストのフォロー解除に失敗しました
-
ナレーター:
-
著者:
(00:01:42) n8n Sandbox Escape CVE
(00:03:15) Origin Energy Customer Data Breach
(00:03:50) Three Themes Worth Tracking
(00:04:31) What To Watch Next
Three high-impact stories dominate today's cybersecurity briefing, each exposing a different dimension of the detection gap facing security teams right now.
The SourTrade malvertising campaign has evolved its technique in a way that breaks hash-based signature detection entirely. Rather than serving a finished malicious binary, attackers deliver components to the victim's browser and use the legitimate Bun runtime to compile a unique Windows executable client-side. Every session produces a different file — nothing to match against a signature database. The campaign targets crypto traders across twelve countries in twenty-five languages, impersonating platforms like TradingView, Solana, and Luno, and uses visitor fingerprinting to hide from researchers and sandboxes.
The second story is a high-severity sandbox escape in n8n, the popular workflow automation platform, patched in versions 2.31.5 and 2.32.1. An authenticated workflow editor can chain arrow functions and Reflect calls to bypass the AST-rewriting sandbox, reach real Node.js objects, and execute arbitrary OS commands at the n8n service account's privilege level — giving an attacker direct access to stored credentials, database connections, and cloud endpoints. This is the second sandbox bypass in weeks, raising structural questions about AST rewriting as an isolation mechanism.
Third, Australian energy provider Origin Energy has confirmed unauthorized access to customer records including names, addresses, dates of birth, and partial payment details. The full scope and attacker identity remain unconfirmed as the investigation continues.
All three incidents share a common thread: credential and account-level access as the entry point, and detection mechanisms that were built for yesterday's attack patterns.
This episode includes AI-generated content.
adbl_web_anon_alc_button_suppression_t1
まだレビューはありません