Veracode Daily Threat Intel Brief - June 23 2026

Written by Andrea Mazzarini, Senior Principal CSM at Veracode

Subscribe to these daily briefings on LinkedIn

Join the VERACODE Community Group - Product & Security Tips - for the latest Veracode Daily Threat Intel Brief - Stay current, stay secure!

 

 

VERACODE DAILY THREAT INTEL BRIEF - 6/23/20226

 

Executive Summary – Top 5 High-Impact Threats

  • Fortinet FortiSandbox Active Exploitation (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089): Three critical (9.1) flaws under active in-wild exploitation (Defused Cyber observed past ~24h). Path traversal/auth bypass + OS command injection. FortiSandbox is core malware analysis/inspection layer for FortiGate et al. — compromise blinds defenses or enables pivot. One exploit appears AI-generated ("vibecoded") and possibly faulty. Atomic Risk: 9.5/10. Veracode direct fit.
  • FortiBleed Credential Campaign: Massive active harvesting/stuffing exposing ~73k–86k FortiGate admin/VPN credentials across 194 countries. Root: credential reuse from prior breaches (FG-IR-26-060/25-647) + brute-force on weak hygiene/no-MFA devices. Not a new CVE/product compromise, but high-blast perimeter bypass enabling ransomware/APT. Russian actors noted in signals. Atomic Risk: 9/10. Immediate hygiene failure amplified. Veracode: EASM discovery + Risk Manager.
  • Miasma/Shai-Hulud Lineage npm Worms (Phantom Gyp variants): Ongoing self-propagating supply-chain credential harvesters compromising legitimate packages (npm/PyPI). Bypasses via binding.gyp; steals dev/cloud creds and auto-spreads. High propagation risk. Atomic Risk: 9/10. Veracode: SCA + Package Firewall priority.
  • CVE-2026-20253 (Splunk Enterprise, 9.8): KEV-listed unauthenticated file ops/RCE via PostgreSQL sidecar. Early exploitation + public PoC. SIEM compromise = detection evasion crown jewel. Atomic Risk: 9/10.
  • CVE-2026-4020 (Gravity SMTP WP Plugin): Actively exploited info disclosure (API keys, full system configs). 17M+ blocked attempts, surge in June. Atomic Risk: 7.5/10.

 

Ransomware (INC 830+ victims, Gentlemen EDR-killers, Qilin, new claims on KTR/Artistic Smiles etc.) remains elevated but no singular new mega-campaign spike in last 24h. Other signals: LiteLLM CVE-2026-42271 (KEV), expr-eval 9.8 code exec, various WP/OSS CVEs. No silent major sources; Fortinet coverage now comprehensive.

 

 

Comprehensive Threats Table

ThreatIntelJune23 

 

Detailed First-Principles Analysis (Top Items)

  • FortiSandbox Exploitation: Root cause = unauthenticated endpoints in JRPC API and WEB UI allowing path traversal + command injection (CWE variants). Mechanism: crafted HTTP requests bypass auth or inject OS commands. Blast radius: FortiSandbox feeds verdicts to FortiGate/FortiAnalyzer etc. — compromise here creates detection blind spots or weaponizes the inspection layer itself for evasion/persistence. Why now: Patches existed (April + recent), yet exploitation observed immediately after awareness window. Atomic why-it-matters: Core security infrastructure under direct attack. Veracode control point: EASM discovers exposed instances; Risk Manager prioritizes in context of Fortinet estate.
  • FortiBleed Campaign: Not a software vuln but operational/hygiene failure at massive scale. Mechanism: credential reuse from prior incidents + brute-force/stuffing on devices lacking MFA or strong hashing. Blast radius: Direct perimeter access to tens of thousands of firewalls/VPNs → ransomware staging, lateral movement, data exfil. Propagation risk: High — exposed creds enable automated campaigns. First-principles: Trust in perimeter devices + password entropy decay = systemic exposure. Fortinet confirms no new CVE/product compromise. Veracode: EASM for asset discovery/hardening prioritization; Risk Manager for unified view.
  • Miasma Worms: Root = maintainer/CI token compromise + abuse of build hooks (binding.gyp bypasses typical script monitoring). Self-propagating via stolen tokens republishing malicious versions. Blast radius: Developer machines → cloud creds → downstream packages/users. High worm propagation risk in OSS trust model. Veracode: SCA + Package Firewall at intake/CI/CD is the precise control point.

 

Broader Signals

X chatter elevated on FortiSandbox CVEs and FortiBleed (73k+ creds exposed, Russian actors, MFA/rotation urgency). Ongoing npm worm discussion. Ransomware victim disclosures steady. No dominant new zero-day beyond Fortinet cluster.

 

Veracode Tool Reference with Links (Dedicated)


  • SamHouston (Veracode)

    Veracode Recommendations (Direct alignment to today's findings)

    • Malicious Packages & Supply Chain Worms (Miasma lineage): SCA + Package Firewall. Why: Detects/risk-scores malicious OSS and blocks at CI/CD before propagation. Customer action: Enable Package Firewall policies for npm/PyPI; run full SCA on all pipelines today.
    • New/KEV CVEs & Network/Security Appliances (FortiSandbox CVEs, Splunk, LiteLLM): Risk Manager (KEV) + EASM. Why: Prioritizes exploited items in context of exposed assets. Customer action: Ingest KEV into Risk Manager; run EASM discovery on Fortinet/Splunk/public assets and prioritize remediation.
    • Web/Runtime Exploits (Gravity SMTP, exposed apps): DAST + EASM. Why: Runtime testing + external surface mapping catches info disclosure and exposed endpoints. Customer action: Targeted DAST scans on WordPress/Forti* web interfaces.
    • External Attack Surface & FortiBleed/Fortinet Estate: EASM + Risk Manager. Why: Discovers internet-facing FortiGate devices for hygiene/rotation prioritization amid credential campaign. Customer action: Full EASM scan of Fortinet footprint; flag for MFA/rotation enforcement.
    • Governance Across All: Policy Management. Why: Enforces consistent rules for KEV, supply-chain, and appliance hardening. Customer action: Update policies to mandate Package Firewall + EASM for high-risk vendors.

     

    Prioritized Action Plan (SMART, Executable Today)

    • Highest Priority: FortiBleed response — Rotate ALL FortiGate admin/VPN credentials immediately; enforce MFA on every account; audit configs/logs for unauthorized changes/unknown accounts; restrict external management (trusted hosts/local-in). Treat anomalies as compromise. (EASM + Risk Manager visibility).
    • High Priority: Patch FortiSandbox instances (all three CVEs) TODAY; restrict JRPC/WEB UI exposure. Run EASM to confirm coverage.
    • Enable/expand SCA + Package Firewall for all npm/PyPI consumption; block high-risk installs in CI/CD.
    • Ingest new KEV (Splunk, LiteLLM, FortiSandbox context) into Risk Manager; triage and update critical policies.
    • Run targeted DAST on exposed web apps/APIs (Gravity SMTP, Fortinet interfaces).
    • Ransomware hardening: Verify EDR coverage, immutable backups, MFA everywhere; monitor for INC/Gentlemen TTPs.
    • Continuous: Daily EASM + Risk Manager sweeps; X/StepSecurity monitoring for Miasma/Fortinet updates.

     

    This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.

    Expand Post

Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.