
Product & Security Tips — SamHouston (Veracode) asked a question.
Written by Andrea Mazzarini, Senior Principal CSM at Veracode
Subscribe to these daily briefings on LinkedIn: https://www.linkedin.com/newsletters/daily-threat-intel-brief-7466482445257723904/
Join the VERACODE Community Group - Product & Security Tips - for the latest Veracode Daily Threat Intel Brief - Stay current, stay secure!
https://community.veracode.com/s/group/0F9Uf0000001c01KAA/product-security-tips
Executive Summary
- Ongoing npm supply chain worms (Miasma/Shai-Hulud variants, binding.gyp/Phantom Gyp technique): Self-propagating malicious packages steal CI/CD credentials, SSH keys, cloud tokens; high propagation risk via npm install. Atomic Risk: 9/10 — first-principles: trust in OSS registries broken at install time; worms self-replicate, evading script-based detection. Strong Veracode applicability.
- CVE-2026-45659 (Microsoft SharePoint RCE, CISA KEV added ~2026-07-01): Deserialization flaw enabling remote code execution. Atomic Risk: 8/10 — network-reachable enterprise software; ransomware potential.
- CVE-2026-0257 (Palo Alto GlobalProtect auth bypass, actively exploited): VPN authentication bypass. Atomic Risk: 8/10 — edge access compromise enables lateral movement.
- CVE-2026-33825 (Microsoft Defender BlueHammer LPE, ransomware use): Privilege escalation. Atomic Risk: 7/10 — post-compromise escalation vector.
- PolinRider (North Korean): 108+ malicious packages/extensions across npm/Packagist/Go. Atomic Risk: 8/10 — targeted supply chain for credential theft.
No major new 24–48h zero-days with public PoCs beyond ongoing campaigns; focus remains supply chain persistence and recent KEV.
Comprehensive Threats Table
Detailed First-Principles Analysis (Top Items)
- Miasma/Shai-Hulud: Root cause = weak npm registry trust + install-time execution (node-gyp via binding.gyp bypasses package.json checks). Mechanism: credential harvest → self-publish malicious variants → worm propagation. Blast radius: thousands of workflows/repos; steals AWS/GCP/K8s/SSH. Veracode control: SCA + Package Firewall blocks at source.
- SharePoint CVE-2026-45659: Deserialization of untrusted data → RCE. High blast radius in enterprise collab tools. Prioritize via Risk Manager for KEV context.
- Supply chain worms prioritize over isolated CVEs due to transitive trust failure across ecosystems.
Broader Signals
- X volume low on brand-new exploits in last 24h; sustained chatter on supply chain (Miasma variants).
- Ransomware activity ongoing (INC, others); no massive new campaigns in last 48h.
- North Korean PolinRider expansion signals persistent developer tooling targeting.
Veracode Tool Reference with Links
- SCA + Package Firewall (malicious packages, supply chain worms, OSS vulnerabilities): https://docs.veracode.com/r/Software_Composition_Analysis and https://docs.veracode.com/r/Veracode_Package_Firewall
- Risk Manager (unified risk prioritization with CISA KEV context): https://docs.veracode.com/r/Veracode_Risk_Manager
- Veracode Fix (AI remediation for SAST/SCA): https://docs.veracode.com/r/About_Veracode_Fix
- SAST (custom code vulnerabilities): https://docs.veracode.com/r/c_static_overview
- DAST (runtime web app and API testing): https://docs.veracode.com/r/DAST
- EASM (external attack surface discovery): https://docs.veracode.com/r/Discover_your_attack_surface
- Container Security: https://docs.veracode.com/r/Veracode_Container_Security
- Policy Management (governance and enforcement): https://docs.veracode.com/r/c_appsec_policies
Veracode Recommendations
- Malicious Packages & Supply Chain Worms: Miasma/Shai-Hulud/PolinRider. SCA + Package Firewall fits — blocks malicious OSS at ingest/CI. Action: Enable policies for high-risk registries and enforce in pipelines.
- New/KEV CVEs: SharePoint CVE-2026-45659, SimpleHelp, Defender. Risk Manager fits — KEV prioritization/unified view. Action: Ingest KEV items, triage by blast radius.
- External Attack Surface: Palo Alto GlobalProtect. EASM + Risk Manager fits — discover exposed VPNs. Action: Scan external assets, enforce patching.
- Governance: All findings. Policy Management fits — enforce controls. Action: Update policies for SCA/KEV.
Prioritized Action Plan
- Enable SCA + Package Firewall policies for malicious packages/OSS worms; enforce in all CI/CD today. Rotate exposed credentials.
- Run Risk Manager on new KEV (SharePoint, Defender, SimpleHelp); prioritize patching with BOD 22-01 alignment.
- EASM scan for exposed GlobalProtect instances; patch PAN-OS immediately.
- Audit npm/PyPI/Packagist deps with SCA; block binding.gyp anomalies.
- Update Policy Management for automated enforcement and reporting.
- Monitor X/KEV feeds daily; re-scan post-remediation.
This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.
.png)