
Product & Security Tips — SamHouston (Veracode) asked a question.
Written by Andrea Mazzarini, Senior Principal CSM at Veracode
Subscribe to these daily briefings on LinkedIn
Join the VERACODE Community Group - Product & Security Tips - for the latest Veracode Daily Threat Intel Brief - Stay current, stay secure!
Executive Summary
- Ongoing npm/OSS supply chain worms (Miasma, Phantom Gyp, ChainVeil, Mastra variants): High-blast-radius credential theft and self-propagation via compromised legitimate packages (e.g., @redhat-cloud-services, TanStack remnants, Mastra). Atomic Risk: 9/10. First-principles: Trust in OSS registries + CI/CD pipelines is foundational; compromise here scales to thousands of downstream builds instantly. Strong Veracode applicability.
- Cisco Catalyst SD-WAN CVE-2026-20262 (KEV): Actively exploited path traversal/arbitrary file write. Atomic Risk: 9/10. Enterprise network control plane exposure.
- Fortinet FortiSandbox triple criticals (CVE-2026-39813, -39808, -25089): Actively exploited OS command injection/path traversal. Atomic Risk: 9/10. Threat intel platform compromise cascades to dependent Fortinet products.
- Jenkins CVE-2026-53435: Deserialization → RCE/impersonation, in-wild exploitation. Atomic Risk: 8.5/10. CI/CD pipeline root compromise.
- Joomla Widget Factory CVE-2026-48907 (KEV): Improper access control → RCE. Atomic Risk: 8/10.
No major new zero-days in last 24h beyond these; ransomware activity routine but no novel campaigns dominating.
Comprehensive Threats Table
Detailed First-Principles Analysis (Top Items)
- npm Worms: Root cause = compromised maintainer accounts/CI pipelines (GitHub Actions poisoning, binding.gyp evasion). Mechanism: Install-time preinstall + credential harvesters (cloud tokens, GitHub/npm). Blast radius: Exponential via dependency trees; worms self-republish. Veracode control: SCA + Package Firewall blocks malicious at intake/enforcement in CI/CD.
- Cisco/FortiSandbox/Joomla: Classic auth bypass + injection in exposed management planes. Why now: Patch lag + KEV pressure. Propagation risk high in interconnected enterprise environments.
Veracode Tool Reference with Links
- SCA + Package Firewall: https://docs.veracode.com/r/Software_Composition_Analysis and https://docs.veracode.com/r/Veracode_Package_Firewall
- Risk Manager: https://docs.veracode.com/r/Veracode_Risk_Manager
- Veracode Fix: https://docs.veracode.com/r/About_Veracode_Fix
- SAST: https://docs.veracode.com/r/c_static_overview
- DAST: https://docs.veracode.com/r/DAST
- EASM: https://docs.veracode.com/r/Discover_your_attack_surface
- Container Security: https://docs.veracode.com/r/Veracode_Container_Security
- Policy Management: https://docs.veracode.com/r/c_appsec_policies
Veracode Recommendations
- Malicious Packages & Supply Chain Worms: Miasma et al. → SCA + Package Firewall. Fits: Blocks malicious OSS at source. Action: Enable Package Firewall policies for npm/PyPI and enforce in CI/CD pipelines.
- New/KEV CVEs: Cisco/Joomla/FortiSandbox → Risk Manager (KEV). Fits: Unified prioritization. Action: Ingest new KEVs and triage by blast radius.
- Web/Runtime/Enterprise: FortiSandbox/Jenkins → DAST + Risk Manager. Action: Run targeted scans on exposed management interfaces.
- Custom Code/CI-CD: Jenkins → SAST + Fix. Action: Scan and remediate deserialization paths.
- Governance: All → Policy Management. Action: Update policies to auto-fail high-risk dependencies.
Prioritized Action Plan
- Bold: Enable Package Firewall + SCA for all npm/PyPI dependencies in CI/CD; audit installs since 2026-05-01; rotate exposed creds.
- Patch Cisco SD-WAN, FortiSandbox, Jenkins, Joomla by deadlines.
- Run Risk Manager prioritization on new KEVs; enforce Policy Management updates.
- Targeted DAST on web-exposed assets; EASM for attack surface reduction.
- Daily: Monitor CISA KEV and Veracode dashboards for propagation.
This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.
.png)