
Product & Security Tips — SamHouston (Veracode) asked a question.
Written by Andrea Mazzarini, Senior Principal CSM at Veracode
Subscribe to these daily briefings on LinkedIn: https://www.linkedin.com/newsletters/daily-threat-intel-brief-7466482445257723904/
Join the VERACODE Community Group - Product & Security Tips - for the latest Veracode Daily Threat Intel Brief - Stay current, stay secure!
https://community.veracode.com/s/group/0F9Uf0000001c01KAA/product-security-tips
Executive Summary (2026-07-07)
Top threats:
- Ongoing npm/PyPI/OSS supply chain worms (Miasma/Shai-Hulud lineage, PolinRider, Lazarus-linked): Persistent malicious package campaigns targeting developers/CI/CD. High propagation via dependencies. Atomic Risk: 9/10. First-principles: Trust in OSS registries broken at source; one compromised maintainer/CI poisons thousands of downstream apps. Strong Veracode SCA/Package Firewall applicability.
- CVE-2026-46242 "Bad Epoll" (Linux kernel epoll UAF/race, PoC public): Local root on affected kernels (6.4+), desktops/servers/Android. Atomic Risk: 8/10. Unprivileged escalation vector in core I/O subsystem.
- CVE-2026-48558 SimpleHelp RMM auth bypass (KEV, actively exploited): Unauth privileged access, malware delivery (Djinn Stealer). ~1k–14k exposed. Atomic Risk: 9/10. RMM as high-value initial access.
- CVE-2026-55200 libssh2 client RCE (public PoC): Malicious SSH server triggers heap corruption on connect. Atomic Risk: 8/10. Client-side risk in tooling/automation.
- CVE-2026-42897 Exchange OWA (prior zero-day activity): Crafted email spoofing/XSS. Ongoing relevance for on-prem. Atomic Risk: 7/10.
No major new 24h ransomware zero-days, but agentic ransomware (JadePuffer) signals automation evolution; persistent group activity (Qilin, Gentlemen, etc.).
Comprehensive Threats Table
Detailed First-Principles Analysis (Top Items)
- Supply chain worms: Root cause = maintainer/CI compromise + weak review (e.g., node-gyp, GitHub Actions poisoning). Mechanism: Malicious deps steal creds, self-propagate. Blast radius: Exponential via transitive deps; hits AI/dev tooling hard. Veracode control: Package Firewall blocks at ingest; SCA for visibility.
- Bad Epoll: Race in epoll close paths (use-after-free). Local unpriv → root. Propagation risk high in containers/shared kernels. Patch kernel; audit exposure.
Broader Signals
Elevated X/Threat intel on supply chain + kernel exploits. Ransomware groups leveraging initial access brokers/stealers.
Veracode Tool Reference with Links
- SCA + Package Firewall: https://docs.veracode.com/r/Software_Composition_Analysis and https://docs.veracode.com/r/Veracode_Package_Firewall
- Risk Manager: https://docs.veracode.com/r/Veracode_Risk_Manager
- Veracode Fix: https://docs.veracode.com/r/About_Veracode_Fix
- SAST: https://docs.veracode.com/r/c_static_overview
- DAST: https://docs.veracode.com/r/DAST
- EASM: https://docs.veracode.com/r/Discover_your_attack_surface
- Container Security: https://docs.veracode.com/r/Veracode_Container_Security
- Policy Management: https://docs.veracode.com/r/c_appsec_policies
Veracode Recommendations
- Malicious Packages & Supply Chain Worms: npm worms/PolinRider. SCA + Package Firewall fits for dependency scanning/blocking. Action: Enable Package Firewall policies for high-risk registries; scan all CI/CD pipelines.
- New/KEV CVEs: Bad Epoll, SimpleHelp, libssh2. Risk Manager for prioritization/KEV context. Action: Ingest into Risk Manager, triage by blast radius.
- Web/Runtime/External: Exchange/SimpleHelp. EASM + DAST. Action: Run EASM for exposed RMM/web apps.
- Containers: Kernel/container risks. Container Security. Action: Scan images/k8s.
- Governance: Policy Management for enforcement across findings.
Prioritized Action Plan (SMART, Today)
- Enable/audit SCA + Package Firewall for all OSS/CI/CD pipelines; block unvetted npm/PyPI (due EOD).
- Patch/update kernels/libssh2/SimpleHelp/Exchange mitigations; verify via Risk Manager (complete in 24h).
- Run targeted EASM on exposed assets + DAST on web/RMM endpoints.
- Update policies in Policy Management for KEV/supply chain rules.
- Scan containers with Container Security; remediate via Veracode Fix where applicable.
This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.
.png)