Product & Security TipsSamHouston (Veracode) asked a question.

VERACODE DAILY THREAT INTEL - July 8 2026

Written by Andrea Mazzarini, Senior Principal CSM at Veracode

Subscribe to these daily briefings on LinkedIn: https://www.linkedin.com/newsletters/daily-threat-intel-brief-7466482445257723904/

Join the VERACODE Community Group - Product & Security Tips - for the latest Veracode Daily Threat Intel Brief - Stay current, stay secure!

https://community.veracode.com/s/group/0F9Uf0000001c01KAA/product-security-tips

 

Executive Summary

  • Miasma / Phantom Gyp npm supply chain worm (Shai-Hulud lineage): Self-propagating credential-harvesting worm abusing binding.gyp / node-gyp for install-time execution. 57+ packages / 286+ malicious versions (high-download targets like @vapi-ai/server-sdk). Ongoing variants into late June. Atomic Risk: 9/10. First-principles: Maintainer compromise + novel bypass of script-hook detection enables CI/CD takeover and ecosystem-wide propagation via stolen cloud/OSS creds. Strong Veracode fit: SCA + Package Firewall.

 

  • CVE-2026-48282 Adobe ColdFusion Path Traversal (KEV added 2026-07-07): Fresh CISA addition confirming active exploitation. Atomic Risk: 8/10. Path traversal as reliable initial access vector for ransomware/APT follow-on.

 

  • CVE-2026-45659 Microsoft SharePoint RCE (recent KEV, deserialization): Actively exploited on enterprise collaboration platform. Atomic Risk: 9/10. Broad internal blast radius.

 

  • CVE-2026-11645 Chromium V8 zero-day (KEV) + ongoing ransomware (SafePay leading recent claims) remain high-signal but secondary to supply chain worm this cycle.
  •  

 

Comprehensive Threats Table

 

0b72bf01-942b-49d2-b851-9aa55ad5da1d 

 

 

Detailed First-Principles Analysis (Top Items)

 

Miasma / Phantom Gyp npm worm: Root cause = compromised maintainer accounts (social engineering/credential theft) publishing trojanized versions. Mechanism = weaponized binding.gyp (normally benign for native addons) triggers node-gyp execution at npm install time — evades most package.json preinstall/postinstall scanners. Payload exfiltrates env vars, tokens, validates access, then self-publishes malicious versions of victim's other packages and injects CI steps. Blast radius = extreme (supply chain worm): poisons high-download packages → thousands of downstream builds/CI runners compromised → cloud credential theft enables ransomware/APT lateral movement. Propagation risk highest in OSS-dependent orgs with weak package governance. Veracode control point: SCA + Package Firewall detects embedded malicious code and blocks at ingest/CI before install.

 

CVE-2026-48282 Adobe ColdFusion: Classic path traversal (CWE-22 class) allows arbitrary file read/write on server. Why it matters now: Fresh KEV confirmation means adversaries are actively chaining it for initial access. ColdFusion often runs legacy enterprise apps with high data sensitivity. Immediate patch + exposure reduction is non-negotiable.

 

CVE-2026-45659 SharePoint: Deserialization of untrusted data → RCE. High-value target for internal network pivoting and data exfil. KEV status demands top-tier prioritization.

 

 

Broader Signals

X (Latest mode) shows routine CVE chatter (Palo Alto PAN-OS disclosures today) and general ransomware discussion; no massive new zero-day PoC dump or brand-new ransomware campaign spike in strict last 24h. Miasma volume peaked with June waves but variants (e.g., Leo Platform) keep the campaign live. Credential theft (e.g., FortiBleed) continues feeding ransomware. APT notes limited in window but China-linked activity observed on older vectors.

Veracode Tool Reference with Links

Veracode Recommendations

Malicious Packages & Supply Chain Worms

Threat: Miasma Phantom Gyp / Shai-Hulud variants (binding.gyp worm, credential harvesting, self-propagation). Why fits: Only tool that directly detects embedded malicious code in OSS packages and enforces real-time blocking of known-bad versions in pipelines. Customer action: Enable Package Firewall malicious package policies + strict SCA gates in every npm/CI/CD pipeline today; full historical scan for affected packages. Tool: SCA + Package Firewall

 

New/KEV CVEs

Threat: CVE-2026-48282 (Adobe ColdFusion), CVE-2026-45659 (SharePoint). Why fits: Unified exploitation-context view + automated prioritization across all findings. Customer action: Ingest these KEVs into Risk Manager; apply 24–72h SLAs for internet-facing assets; trigger Fix on any custom integrations. Tool: Risk Manager (KEV)

 

Web/Runtime Exploits

Threat: SharePoint RCE, Adobe ColdFusion path traversal, Chromium V8. Why fits: Identifies runtime-exploitable issues (deserialization, traversal) in live web/apps that static analysis misses. Customer action: Targeted DAST scans on all exposed SharePoint/ColdFusion instances; prioritize high findings for immediate fix. Tool: DAST

 

External Attack Surface

Threat: Exposed ColdFusion/SharePoint servers under active exploitation. Why fits: Discovers unknown exposed assets and correlates with KEV risk. Customer action: Run EASM discovery; map exposed assets to new KEVs; remediate or shield. Tool: EASM + Risk Manager

Governance

 

Threat: All above require consistent enforcement. Customer action: Update Policy Management to mandate Package Firewall + SCA pass for OSS, KEV prioritization, and DAST for web apps before any production deploy. Tool: Policy Management

This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.


Topics (3)

No articles found
Loading

Ask the Community

Get answers, share a use case, discuss your favorite features, or get input from the community.