
Product & Security Tips — SamHouston (Veracode) asked a question.
Written by Andrea Mazzarini, Senior Principal CSM at Veracode
Subscribe to these daily briefings on LinkedIn
Join the VERACODE Community Group - Product & Security Tips - for the latest Veracode Daily Threat Intel Brief - Stay current, stay secure!
VERACODE DAILY THREAT INTEL BRIEF - 6/23/20226
Executive Summary – Top 5 High-Impact Threats
- Fortinet FortiSandbox Active Exploitation (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089): Three critical (9.1) flaws under active in-wild exploitation (Defused Cyber observed past ~24h). Path traversal/auth bypass + OS command injection. FortiSandbox is core malware analysis/inspection layer for FortiGate et al. — compromise blinds defenses or enables pivot. One exploit appears AI-generated ("vibecoded") and possibly faulty. Atomic Risk: 9.5/10. Veracode direct fit.
- FortiBleed Credential Campaign: Massive active harvesting/stuffing exposing ~73k–86k FortiGate admin/VPN credentials across 194 countries. Root: credential reuse from prior breaches (FG-IR-26-060/25-647) + brute-force on weak hygiene/no-MFA devices. Not a new CVE/product compromise, but high-blast perimeter bypass enabling ransomware/APT. Russian actors noted in signals. Atomic Risk: 9/10. Immediate hygiene failure amplified. Veracode: EASM discovery + Risk Manager.
- Miasma/Shai-Hulud Lineage npm Worms (Phantom Gyp variants): Ongoing self-propagating supply-chain credential harvesters compromising legitimate packages (npm/PyPI). Bypasses via binding.gyp; steals dev/cloud creds and auto-spreads. High propagation risk. Atomic Risk: 9/10. Veracode: SCA + Package Firewall priority.
- CVE-2026-20253 (Splunk Enterprise, 9.8): KEV-listed unauthenticated file ops/RCE via PostgreSQL sidecar. Early exploitation + public PoC. SIEM compromise = detection evasion crown jewel. Atomic Risk: 9/10.
- CVE-2026-4020 (Gravity SMTP WP Plugin): Actively exploited info disclosure (API keys, full system configs). 17M+ blocked attempts, surge in June. Atomic Risk: 7.5/10.
Ransomware (INC 830+ victims, Gentlemen EDR-killers, Qilin, new claims on KTR/Artistic Smiles etc.) remains elevated but no singular new mega-campaign spike in last 24h. Other signals: LiteLLM CVE-2026-42271 (KEV), expr-eval 9.8 code exec, various WP/OSS CVEs. No silent major sources; Fortinet coverage now comprehensive.
Comprehensive Threats Table
Detailed First-Principles Analysis (Top Items)
- FortiSandbox Exploitation: Root cause = unauthenticated endpoints in JRPC API and WEB UI allowing path traversal + command injection (CWE variants). Mechanism: crafted HTTP requests bypass auth or inject OS commands. Blast radius: FortiSandbox feeds verdicts to FortiGate/FortiAnalyzer etc. — compromise here creates detection blind spots or weaponizes the inspection layer itself for evasion/persistence. Why now: Patches existed (April + recent), yet exploitation observed immediately after awareness window. Atomic why-it-matters: Core security infrastructure under direct attack. Veracode control point: EASM discovers exposed instances; Risk Manager prioritizes in context of Fortinet estate.
- FortiBleed Campaign: Not a software vuln but operational/hygiene failure at massive scale. Mechanism: credential reuse from prior incidents + brute-force/stuffing on devices lacking MFA or strong hashing. Blast radius: Direct perimeter access to tens of thousands of firewalls/VPNs → ransomware staging, lateral movement, data exfil. Propagation risk: High — exposed creds enable automated campaigns. First-principles: Trust in perimeter devices + password entropy decay = systemic exposure. Fortinet confirms no new CVE/product compromise. Veracode: EASM for asset discovery/hardening prioritization; Risk Manager for unified view.
- Miasma Worms: Root = maintainer/CI token compromise + abuse of build hooks (binding.gyp bypasses typical script monitoring). Self-propagating via stolen tokens republishing malicious versions. Blast radius: Developer machines → cloud creds → downstream packages/users. High worm propagation risk in OSS trust model. Veracode: SCA + Package Firewall at intake/CI/CD is the precise control point.
Broader Signals
X chatter elevated on FortiSandbox CVEs and FortiBleed (73k+ creds exposed, Russian actors, MFA/rotation urgency). Ongoing npm worm discussion. Ransomware victim disclosures steady. No dominant new zero-day beyond Fortinet cluster.
Veracode Tool Reference with Links (Dedicated)
- SCA + Package Firewall (malicious packages, supply chain worms, OSS vulnerabilities): https://docs.veracode.com/r/Software_Composition_Analysis and https://docs.veracode.com/r/Veracode_Package_Firewall
- Risk Manager (unified risk prioritization with CISA KEV context): https://docs.veracode.com/r/Veracode_Risk_Manager
- Veracode Fix (AI remediation for SAST/SCA): https://docs.veracode.com/r/About_Veracode_Fix
- SAST (custom code vulnerabilities): https://docs.veracode.com/r/c_static_overview
- DAST (runtime web app and API testing): https://docs.veracode.com/r/DAST
- EASM (external attack surface discovery): https://docs.veracode.com/r/Discover_your_attack_surface
- Container Security: https://docs.veracode.com/r/Veracode_Container_Security
- Policy Management (governance and enforcement): https://docs.veracode.com/r/c_appsec_policies
.png)
Veracode Recommendations (Direct alignment to today's findings)
Prioritized Action Plan (SMART, Executable Today)
This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.