
Product & Security Tips — SamHouston (Veracode) asked a question.
Written by Andrea Mazzarini, Senior Principal CSM at Veracode
Subscribe to these daily briefings on LinkedIn
Top threats: Persistent Miasma/Mini Shai-Hulud supply-chain worms targeting OSS (npm/PyPI/GitHub/AI tools) with credential theft and self-propagation; multiple CISA KEV additions including Cisco, LiteSpeed cPanel, Oracle PeopleSoft; Splunk pre-auth RCE with public exploit; ongoing Qilin ransomware via Check Point VPN zero-day.
- Miasma worm toolkit (supply chain): High blast-radius propagation via compromised maintainer accounts and malicious packages; Atomic Risk 9/10. First-principles: Trust in OSS registries broken at source—any downstream dependency inherits execution. Strong Veracode applicability.
- CVE-2026-20253 Splunk Enterprise (pre-auth RCE/file ops): Public exploit, CVSS 9.5; Atomic Risk 9/10. Immediate enterprise logging/monitoring exposure.
- CVE-2026-35273 Oracle PeopleSoft + CVE-2026-54420 LiteSpeed cPanel (KEV): In-wild exploitation; Atomic Risk 8-9/10. Ransomware/credential vectors.
- CVE-2026-50751 Check Point VPN: Qilin ransomware exploitation.
Comprehensive Threats Table
Detailed First-Principles Analysis (Top Items)
- Miasma worm: Root cause = compromised GitHub creds + CI poisoning enabling self-replication across registries and AI configs. Mechanism: Credential stealers + backdoors in packages (e.g., atomic-lockfile variants). Blast radius: Massive propagation to downstream consumers; worms evolve via public toolkit leak. Veracode control: SCA + Package Firewall blocks malicious deps at intake/CI.
- Splunk CVE-2026-20253: Missing auth on PostgreSQL sidecar endpoint → arbitrary file ops/RCE. Why now: Public PoC + logging exposure in security tool. First-principles: Perimeter on "secure" products fails without zero-trust. Veracode: Runtime/DAST for exposed services.
Broader Signals: Elevated X/Reddit chatter on supply-chain worms and KEV patches. Ransomware (Qilin, others) active but no brand-new mega-campaigns in last 24h. Ongoing credential-harvesting via fake OSS sites.
Veracode Tool Reference with Links
SCA + Package Firewall: https://docs.veracode.com/r/Software_Composition_Analysis and https://docs.veracode.com/r/Veracode_Package_Firewall
Risk Manager: https://docs.veracode.com/r/Veracode_Risk_Manager
Veracode Fix: https://docs.veracode.com/r/About_Veracode_Fix
SAST: https://docs.veracode.com/r/c_static_overview
DAST: https://docs.veracode.com/r/DAST
EASM: https://docs.veracode.com/r/Discover_your_attack_surface
Container Security: https://docs.veracode.com/r/Veracode_Container_Security
Policy Management: https://docs.veracode.com/r/c_appsec_policies
Veracode Recommendations Malicious Packages & Supply Chain Worms: Miasma/atomic-lockfile — SCA + Package Firewall fits for blocking OSS risks in CI/CD. Action: Enable Package Firewall policies for high-risk registries and scan all deps.
New/KEV CVEs: Splunk, Oracle, Cisco, LiteSpeed — Risk Manager (KEV) for prioritization/unified view. Action: Import KEV items and triage by exposure.
Web/Runtime Exploits: Splunk/DAST-eligible services — DAST for runtime validation.
Governance: Policy Management to enforce SCA/KEV rules across portfolio.
Prioritized Action Plan (SMART)
- Bold: Today — Run full SCA scan + enable Package Firewall for npm/PyPI; block atomic-lockfile/Miasma IOCs in CI/CD.
- Inventory exposed Splunk/Oracle/Check Point instances via EASM; patch KEV items by EOD (Risk Manager).
- Rotate creds for all devs/maintainers; audit GitHub Actions for poisoning.
- Update policies (Policy Management) with today's findings; test Veracode Fix on sample SCA results.
- Monitor X/KEV for 24h follow-up.
This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.
.png)