This briefing covers two distinct horizons. The past week (23–30 September 2026) is a cluster of material, actively exploited edge and enterprise-application flaws, plus confirmed identity and third-party incidents. The past month (31 August–30 September 2026) shows those events as part of a faster pattern: perimeter appliances as the preferred initial-access class, build systems as ransomware feedstock, non-human identity as a wipe and extortion primitive, and overlapping EU and U.S. reporting clocks that are now operational rather than prospective.
Executive Summary
Highest residual risk this week is not a new CVE class. It is unauthenticated remote code execution on internet-facing trust-boundary appliances, with implants that survive the patch. Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 (CVSS 9.5) were exploited for weeks before disclosure. Novel post-exploit tooling (WHIPSHOT, SLAPSHOT) was documented. F5 BIG-IP APM CVE-2026-94127 (CVSS 9.8) sits on the same pattern. Patching without hunt leaves a foothold.
Compensating controls without the vendor fix are failing in production. An extortion operator resumed mass exploitation of Oracle PeopleSoft CVE-2026-35273 by URL-encoding a single character to bypass web-application firewall rules that match the literal path. Organizations that mitigated and deferred the patch remain exposed. Treat related claims against a federal hiring portal as an investigation. Treat the PeopleSoft campaign as confirmed and actionable.
The software factory is now a ransomware initial-access path. The Known Exploited Vulnerabilities catalog was updated on 23 September to record that JetBrains TeamCity CVE-2026-63077 (CVSS 9.8, patched in July) is being used in ransomware operations. Shadowserver still sees roughly 160 internet-facing unpatched servers. Compromise of the build server is compromise of every subsequent release.
Identity and non-human identity are the common root across crime, cloud destruction, and targeted operations. A device-code phishing service that used AI inbox mining was disrupted after compromising 12,000 accounts across 10,000 organizations. Separately, compromised Azure service principals were used in a seven-minute destructive burst against storage, Key Vaults, and recovery-adjacent resources. Resource locks stopped part of the wipe. That is a cheap control with measured effect.
Regulatory clocks are no longer a 2027 problem. EU Cyber Resilience Act Article 14 reporting for actively exploited vulnerabilities and severe incidents has applied since 11 September 2026. Binding Operational Directive 26-04 risk-tiered patching is the federal prioritization model and the practical private-sector queue. CIRCIA’s final rule is expected this fall; it is not confirmed published as of 30 September 07:00 ET.
Program implication. This quarter’s highest-odds investment is not a new product category. It is hunt-then-patch on KEV edge and CI/CD assets, ingest-time package blocking plus SCA and SBOM evidence, DAST and EASM coverage of internet-facing apps and APIs, and non-human-identity privilege and delete-protection on cloud identities. Velocity of disclosure does not change the control set. It changes the SLA.
The Past Week in Review: Critical Developments
Date range: 23–30 September 2026.
Citrix NetScaler — unauthenticated RCE, custom malware, hunt-before-patch
Citrix disclosed two actively exploited remote-code-execution flaws in NetScaler ADC and Gateway on 27 September (security bulletin CTX697096). Both were added to the Known Exploited Vulnerabilities catalog the same day, with a federal civilian remediation date of 30 September.
CVE-2026-88771 is CWE-20, improper input validation. No preconditions. It affects default ADC and Gateway configurations. It allows unauthenticated command execution. Business impact is full appliance compromise, credential theft, and internal pivot.
CVE-2026-88772 is CWE-119, memory overflow. The precondition is DTLS enabled, which is the default on VPN virtual servers. It allows unauthenticated remote code execution or denial of service via a malformed DTLS handshake. Business impact is root on the FreeBSD packet engine, with the same pivot path.
Exploitation of CVE-2026-88772 was observed from at least 3 September — a minimum three-week undetected window. Exploit attempts against CVE-2026-88771 were observed on 24 September. Impacted sectors include government, financial services, education, legal and professional services, energy, and technology, in North America and Europe. Dozens of organizations were affected. The operators were advanced. Public reporting has not established a confirmed attribution.
Post-exploit tooling is new and persistent. WHIPSHOT is a PHP web shell disguised as a Debian package in the VPN scripts directory. Command and control is hidden in native HTTP headers. The shell often returns HTTP 404. SLAPSHOT is a Python TCP tunnel that turns the perimeter appliance into an internal proxy.
Implants and httpd.conf aliases can survive version upgrade and high-availability synchronization. Forensic triage before and after the patch is the control, not the patch alone. Target builds: 14.1-73.37 or later, or 13.1-64.23 or later (FIPS and NDcPP variants per the Citrix bulletin). Rotate credentials and certificates that traversed the gateway.
Next action. Inventory every internet-facing NetScaler ADC and Gateway tonight. Hunt WHIPSHOT, SLAPSHOT, and setuid /bin/sh on both high-availability nodes. Then patch. Then hunt again.
F5 BIG-IP APM and the rest of the edge KEV cluster
The NetScaler pair did not arrive alone. The same seven-day window produced a cluster of unauthenticated or near-unauthenticated flaws on identity-adjacent perimeter products.
F5 BIG-IP APM, CVE-2026-94127, scores 9.8 under CVSS v3.1 and 9.3 under v4.0. It entered the KEV catalog on 22 September, with a due date of 25 September. It is a heap overflow, only when APM is an OAuth authorization server. Appliance mode is also vulnerable. It is a data-plane issue. Exploitation was confirmed.
WSO2 API Manager, Control Plane, and Gateway, CVE-2026-5430, scores 9.8 to 10.0 depending on the source. KEV date 24 September, due 27 September. One description is path traversal and file upload. The vendor advisory describes JWT algorithm-mismatch admin takeover. Treat both descriptions as in scope until reconciled. Honeypots saw forged tokens from 13 September.
Adobe Commerce and Magento, CVE-2026-71362, scores 9.1. KEV date 24 September, due 27 September. It is CWE-863, incorrect authorization, giving unauthenticated elevated access with no user interaction. In-the-wild use was observed.
Microsoft SharePoint, CVE-2026-65660, scores 8.8. KEV date 25 September, due 28 September. Code injection by an authorized attacker over the network.
MikroTik RouterOS, CVE-2026-67279, is chainable. KEV date 25 September, due 28 September. It is a pre-authentication SSH workflow bypass. Chained with CVE-2026-86060 it yields unauthenticated administrative takeover.
WordPress Core, CVE-2026-87902, scores 8.1 to 9.2. KEV date 25 September, due 28 September. Remote file inclusion and path traversal. It was exploited the same day as the patch. Later reporting cited tens of thousands of unique attacking IPs.
First-principles read: these are not IT-hygiene tickets. They sit on the trust boundary where authentication is supposed to happen. An unauthenticated remote code execution on an application delivery controller, access policy manager, API manager, or on-premises SD-WAN orchestrator is equivalent to handing the attacker a valid session into whatever sits behind it.
PeopleSoft — confirmed WAF-bypass campaign; portal claim remains an investigation
On 22 September an extortion group defaced a federal hiring portal and claimed a PeopleSoft path into personnel systems, with a large claimed data volume. The agency confirmed it is investigating unauthorized activity on that portal. Broader theft, cloud lateral movement, and volume claims are not confirmed. The portal was still offline as of 28 September. A related arrest was confirmed in Europe.
Separately, and confirmed: the same operator resumed mass exploitation of CVE-2026-35273 (PeopleSoft Environment Management Hub / PSEMHUB) by requesting /%50SEMHUB/ instead of /PSEMHUB/. Many web-application firewall rules match the literal path before URL decoding; the application server decodes and routes to the vulnerable servlet. The new wave has deployed web shells on dozens of systems across higher education, healthcare, government, technology, IT services, agriculture, and transportation. A WAF-only mitigation without the vendor patch is not mitigation.
Next action. If PeopleSoft is in the estate, apply the June vendor patch, disable or remove EMHub if unused, and hunt for known web shells (x.jsp, u.jsp, trojanized installer). Do not brief the board that the WAF bought time unless the patch is also on.
Identity operations — device-code phishing disruption and refined targeted email
On 22 September a subscription phishing platform was disrupted. It combined OAuth device-code phishing with an AI chatbot that mined compromised inboxes for payment conversations, trusted relationships, and internal roles. The operation had compromised more than 12,000 accounts across more than 10,000 organizations, with concentration in North America, the United Kingdom, Australia, India, and France. Supporting infrastructure was seized and two arrests were made. Password reset is insufficient. Tokens and OAuth grants must be revoked. Residual risk after disruption is copycat tooling, not this brand.
The same week, a long-running targeted phishing operation refined its delivery: spoofed policy-event invites, reply-then-archive sequencing, shortcut files presented as documents, and a Python backdoor. Volume has increased relative to classic one-to-one spearphishing. This is an email-and-identity problem, not a malware-signature problem.
Agentic cloud destruction — intelligence this week, activity earlier
An operator tracked in public reporting as an agentic ransomware actor used two compromised Azure service principals in an 18-hour operation observed in June: roughly 300 read operations mapping virtual machines, subscriptions, and resource groups, then a seven-minute destructive window with more than 100 storage-account deletion attempts plus Key Vault, Function App, virtual machine, and App Service targeting, followed by storage-key collection. One service-principal credential had previously appeared in a public code repository. Resource locks and account-level protections blocked part of the wipe. This week’s disclosure is the cloud-identity evolution of that tradecraft, not a new 28 September intrusion.
The control lesson that survived contact with the attacker: delete-protection and resource locks work. Secrets in public repositories plus standing service-principal privileges do not.
Third-party security product in the custody path
On 24 September a cryptocurrency exchange detected unauthorized transfers from hot and warm wallets totaling, by later reconciliation, approximately 387.5 to 388 million dollars (initial public figure 351.6 million). Private keys were not reported stolen. Cold wallets were reported intact. The exchange stated the attacker obtained high-level internal credentials through a vulnerability in a third-party security product and injected withdrawal commands the backend treated as legitimate. Investigators described malicious activity on third-party appliances and a customized withdrawal tool. Treat loss magnitude as high-confidence and the mechanism as company-stated. Attribution is not confirmed and is not required for the control decision.
Board framing is independent of sector. A security product in the authorization path is part of the kill chain. Third-party risk reviews that stop at SOC 2 letters do not cover this.
E-commerce mass compromise and other week disclosures
An operator compromised more than 3,800 Magento and Adobe Commerce shops beginning around 4 September, and left its own collection infrastructure exposed. The campaign sits on the same Adobe Commerce and Magento problem set that produced KEV listings this week (CVE-2026-71362) and an earlier September critical template-injection issue (CVE-2026-75650, CVSS 10.0). This is payment-data and session-takeover risk at industrial scale, not a single-store incident.
Other material disclosures in the week
Apple CVE-2026-86950 is a CoreGraphics out-of-bounds write, CVSS 8.8, CWE-787. Exploitation was described as extremely sophisticated and targeted on iOS. Fixes shipped on 28 September for iOS and iPadOS 26.7.1, macOS Tahoe 26.7.1, and Sequoia 15.8.1. Treat as targeted, not mass.
OpenSSL CVE-2026-84782, disclosed 29 September, is a high-severity DTLS retransmission bug that can disclose heap memory or crash the process, CVSS 8.2. It is relevant wherever DTLS is on the wire — VPNs, voice, IoT, and, in this week’s context, the same protocol family as NetScaler CVE-2026-88772. Fourteen OpenSSL issues shipped in the same release train. WolfSSL also patched a comparable batch.
Keio Corporation ransomware, 26 September, hit a Japanese railway and hospitality group. Train operations continued. Payment and reservation systems were disrupted.
Park24 / Times Car. 6.6 million car-share accounts, including driver’s-license images.
Defense Manpower Data Center. Notifications circulating this week cover a file-share exposure discovered 16 July 2026, with unauthorized access from October 2025 to July 2026. About 2.76 million living and 294,000 deceased individuals; unencrypted Social Security numbers and personnel data. This is not a September intrusion. It is a September notification of a nine-month access window on an unencrypted file share — a control-effectiveness failure, not a novel technique.
The Past Month: Trends and Persistent Risks
Date range: 31 August–30 September 2026.
The week’s events are not outliers. They are the visible edge of a 30-day pattern.
What accelerated
Edge-appliance zero-days as the default initial-access class. September added Citrix, F5 APM, Check Point management and VPN, Arista VeloCloud Orchestrator (CVE-2026-93952, CVSS 10.0), MikroTik, and earlier-in-month Cisco Secure Firewall Management Center (CVE-2026-20079, CVSS 10.0) to the exploited set. The operating cycle is consistent: limited targeted use, vendor bulletin, KEV listing with a three-day BOD 26-04 clock, then mass scanning once a proof of concept or researcher write-up lands. This is the same structural problem as prior Fortinet, Ivanti, and Citrix cycles. The control response that fails is waiting for change-control Friday.
KEV and disclosure velocity. Second-quarter industry figures put new CVE volume at 20,755 for the quarter (up 36 percent quarter over quarter) with 44 KEV additions. The September platform patch cycle was in the high 900s of CVEs — the largest monthly set in that series. A dense cluster of KEV entries landed in the last ten days of September alone. CVSS-first queues cannot keep up. The four-variable test in BOD 26-04 — public exposure, KEV status, automatable exploitation, total control — is the prioritization model that matches attacker behavior.
Enterprise-application exploitation outrunning compensating controls. PeopleSoft CVE-2026-35273 moved from a June education-sector wave (more than 100 victims reported) to a September web-application-firewall bypass wave across government, healthcare, and transportation. Adobe Commerce produced two KEV-class problems in the month. WordPress core was exploited the day of patch. Web-application firewalls, content-delivery rules, and the next maintenance window are being priced in by operators.
CI/CD as ransomware feedstock. TeamCity CVE-2026-63077 was patched 25 July, added to KEV on 5 August, and flagged for ransomware use on 23 September. All four TeamCity KEV entries since October 2023 have been used in ransomware. The internet-facing unpatched count fell from roughly 700 to roughly 160 — improvement, not closure. The residual risk is not the CVE. It is the unpatched build server that still signs production.
Identity overtook raw vulnerability exploit as the plurality ransomware root cause in current industry reporting. Malicious email (26 percent) plus phishing (24 percent) is the leading pair. Exploited vulnerabilities fell to 18 percent from 32 percent the prior year. The August victim count was 1,073, a 2026 monthly high, up 12 percent versus July, with industrials a large share. Those two facts sit together. Fewer cases of a new CVE becoming ransomware in 24 hours does not mean ransomware is receding. It means identity and known-unpatched systems are doing the work.
AI moved from content generation to operator. Three month-horizon evidence points, none of which should be over-read as a single campaign.
Coding-agent plugin integrity, disclosed 17–18 September, so month, not week. A SHA-pinning bypass in four widely used AI coding agents. Zero-click remote code execution if a marketplace plugin’s repository is attacker-controlled. Two vendors patched. One agent remained unpatched at disclosure. One was retired rather than patched. This is the first clear supply-chain vulnerability of the AI-agent ecosystem.
Device-code phishing, above. AI as a force multiplier on stolen mailboxes.
Agentic post-exploitation. A vulnerability-coordination organization stated on 24 September, and updated the statement on 29 September, that an autonomous AI agent was used for noisy post-exploitation after an unnamed technical vulnerability (explicitly not the NetScaler issue). First-party victim statement. Useful as a direction signal, not as a named technique that can be hunted tomorrow.
What stabilized, and remains material
Ransomware industrial tempo remains high. A small set of established double-extortion operations continues to dominate leak-site volume. That is not a new class of problem. It is a persistent one that now feeds on identity and on last quarter’s unpatched KEV entries.
Open-source malicious-package cadence has been elevated for months (industry tracking in the high single digits of confirmed incidents per month versus roughly one per month earlier). Wormable package behavior is no longer exotic. Combined with AI-agent plugin distribution, ingest-time blocking is the control that matches the threat. Detect-after-install software composition analysis is necessary, and late.
What is emerging or compounding
EU Cyber Resilience Act Article 14 is live as of 11 September 2026 for manufacturers of products with digital elements already on the EU market: 24-hour early warning and 72-hour notification for actively exploited vulnerabilities and severe incidents, with ENISA as the receiving path. Full CRA product-security obligations remain 11 December 2027. This is a current legal clock.
NIS2 national enforcement is proceeding more through supervisory orders than published corporate fines. Four member states were referred to the Court of Justice of the European Union earlier in 2026 for non-transposition. DORA has been applicable to EU financial entities and designated critical ICT third-party providers since 17 January 2025. EU AI Act transparency obligations have applied since 2 August 2026. High-risk system duties were deferred (December 2027 and August 2028 under the Digital Omnibus track). One material incident at a financial firm can trip DORA, NIS2, GDPR, and — if an AI system is in the path — AI Act documentation duties on different clocks.
CIRCIA remains imminent, not live. Work is focused on harmonizing the reporting structure. Draft 2024 text was criticized as overly broad. Do not brief the board that CIRCIA reporting is in force. Do brief that 72-hour incident and 24-hour ransom-payment reporting is the design point to staff against.
BOD 26-04 replaced CVSS-first federal remediation, revoking BOD 19-02 and BOD 22-01. Highest-risk cell: publicly exposed, on the KEV catalog, automatable, and granting total control — a three-day clock, with forensic triage required on designated KEV entries. Private-sector programs that still sort by CVSS score are optimizing the wrong queue.
Strategic Foresight: Signals for the Next 30–90 Days
Grounded in the month’s evidence. Confidence tagged. Not a prediction market.
Edge appliances remain the highest-probability material-event class through Q4.
Basis: Citrix, F5, Check Point, Arista, MikroTik, and Cisco FMC in a single month, the same cycle as prior years. Confidence: high. Prepare a pre-authorized emergency change path for ADC, VPN, and APM, a 72-hour hunt playbook, and an internet-exposure inventory that is days old, not quarterly.
Encoding and normalization bypasses against mitigated-but-unpatched enterprise apps.
Basis: PeopleSoft /%50SEMHUB/ defeating literal-path WAF rules. Confidence: high. Stop accepting WAF exceptions as closure for KEV-class application flaws. Patch or remove the feature.
Device-code OAuth and AI-assisted inbox fraud persist after the disruption.
Basis: the platform was disrupted, the technique is cheap to copy, and a 10,000-organization blast radius was already demonstrated. Confidence: high. Disable or strongly restrict device-code flow where unused. Run continuous OAuth-app consent review. Keep a token-revocation runbook.
Agentic tooling gets quieter and more useful to operators.
Basis: noisy autonomous post-exploitation, destructive use of non-human identity, and a coding-agent plugin integrity failure. Confidence: medium-high on direction, low on the next named victim. Inventory agents and plugins. Pin-and-verify that actually verifies the tree. Treat coding-agent marketplaces as a software supply chain.
Regulatory collision in Q4.
Basis: CRA reporting is already live, NIS2 varies by member state, DORA is already binding, and CIRCIA final text is expected this fall. Confidence: high on collision, medium on the CIRCIA date. Build a single incident-notification matrix mapped to every clock the organization is actually on. If software or devices ship into the EU, staff a manufacturer CRA runbook.
Financial-custody and developer-identity targeting continues.
Basis: exchange hot-wallet theft via a third-party security product, plus ongoing recruiter-lure activity against developers. Confidence: high on persistence, medium on the next sector. Review treasury and custody third parties. Put developer-endpoint and recruiter-lure controls in place.
Board investment implication. Do not fund AI security as a separate theater. Fund agent inventory, plugin allowlists, package firewall on developer ecosystems, DAST and EASM on AI-exposed APIs, and identity controls on OAuth device-code flows. Patching edge, plus identity, plus ingest-time supply-chain blocking, beats net-new platform spend this quarter.
Veracode Recommendations: How Leading Programs Are Responding
Capabilities below were refreshed against the live platform page and documentation on 30 September 2026. The suite in current production use: Risk Manager, Fix, Static Analysis, Software Composition Analysis, Dynamic Analysis, External Attack Surface Management, Package Firewall, Software Supply Chain Intelligence, Container Security including infrastructure-as-code and secrets, the Veracode CLI, Integrations, and Policies. Map the control to the threat. Do not collapse the program to static analysis.
Stop malicious and policy-violating packages at ingest — Package Firewall and SCA
Why now. Coding-agent plugin integrity failures, elevated malicious-package cadence, TeamCity as ransomware initial access, and the third-party security-product lesson all say the same thing. Detection after the lockfile is late. Ingest-time policy is the control that matches wormable and typosquat supply-chain behavior.
Action. Put Package Firewall in front of npm, PyPI, Maven, Cargo, and internal artifact repositories. Default-deny unprocessed packages. Encode policy in Open Policy Agent and Rego for malware, known-vulnerability, license, and author-risk tags. Pair with SCA agent-based scans on every repository so existing lockfiles are not a blind spot.
Live documentation.
Package Firewall overview: https://docs.veracode.com/r/Veracode_Package_Firewall.
Set up Package Firewall: https://docs.veracode.com/r/Set_up_package_firewall.
Create and test a firewall: https://docs.veracode.com/r/Create_and_test_a_firewall.
Manage firewall policies: https://docs.veracode.com/r/Manage_firewall_policies.
SCA agent-based scans: https://docs.veracode.com/r/Agent_Based_Scans.
Issue tags covering author, engineering, malware, vulnerability, and license: https://docs.veracode.com/r/Identify_security_issues_in_packages.
Measurable outcome. Percentage of builds whose dependencies resolved only through a policy-enforcing firewall. Count of blocked malicious or policy-violating versions per week. Time-to-block versus time-to-ticket under detect-after-install SCA alone.
Make KEV and exploitability the remediation queue — Risk Manager and Policies
Why now. BOD 26-04 and this month’s KEV cluster make CVSS-sorted backlogs a governance failure. Risk Manager is the application-security posture management layer that correlates findings across code, pipeline, infrastructure-as-code, and cloud, attaches owner and root cause, and computes a next-best action instead of a severity sort.
Action. Ingest static, composition, dynamic, container, and cloud-connector findings into Risk Manager. Weight internet-facing, KEV, automatable, and total-control the way BOD 26-04 does. Enforce the same logic as policy gates so fix-for-policy and fix-for-exploited are the same list.
Live documentation.
Veracode Risk Manager: https://docs.veracode.com/r/Veracode_Risk_Manager.
Platform findings, policies, and analytics: https://docs.veracode.com/r/review_main.
Develop a remediation plan: https://docs.veracode.com/r/review_remediationplan.
Measurable outcome. Mean time from KEV addition to covered asset identified and ticketed. Percentage of policy-failing findings with a named owner. Risk reduced per engineering-day, not raw closed-ticket count.
Find the internet-facing estate you actually have — EASM and DAST
Why now. NetScaler, BIG-IP APM, WSO2 API managers, Magento storefronts, WordPress, SharePoint, and PeopleSoft PSEMHUB are only manageable if they are in inventory. External Attack Surface Management’s 21 September updates added multi-project visibility, scheduled scans, and prioritized findings (Fix now, Fix soon, Monitor, Track). Dynamic analysis then tests the web applications and APIs the way an attacker does, including API specifications and Postman collections.
Action. Run Deep Discovery against the primary corporate domain. Feed every newly found web application and API into dynamic analysis: Quick scan on production, Full scan on pre-production. Prioritize Magento and Adobe Commerce, WordPress, PeopleSoft HTTP endpoints, and any OAuth authorization-server surfaces.
Live documentation.
Discover your attack surface: https://docs.veracode.com/r/Discover_your_attack_surface.
Assess EASM risks: https://docs.veracode.com/r/Assess_your_risks.
Scan web applications and APIs:https://docs.veracode.com/r/Scan_web_applications_and_APIs.
DAST quickstart: https://docs.veracode.com/r/DAST_quickstart.
EASM updates of 21 September 2026: https://docs.veracode.com/updates/r/EASM_updates.
Measurable outcome. Unknown internet-facing applications and APIs found this month. Percentage of external web and API assets with a current dynamic-analysis result. Time from an EASM Fix-now finding to dynamic confirmation or takedown.
Close first-party and open-source flaws at developer speed — SAST, Fix, and CLI
Why now. A Patch Tuesday in the high 900s and a month of framework remote-code-execution issues (WordPress, Next.js, Adobe Commerce, WSO2) will bury a manual triage team. Fix generates reviewable patches for static and composition findings via the CLI, the IDE, and source-control merge requests. Pipeline and upload-and-scan static analysis remain the system of record for policy.
Action. Require static analysis and software composition analysis on every production pipeline. Enable Fix in the CLI and in the IDE developers already use. Batch-fix only with a mandatory rescan. Do not treat a generated patch as closed until the subsequent static scan is clean.
Live documentation.
Scan source code in the Veracode Platform: https://docs.veracode.com/r/Scan_source_code_in_the_Veracode_Platform.
About Veracode Fix: https://docs.veracode.com/r/About_Veracode_Fix.
Apply Fix in CLI, IDE, and source control: https://docs.veracode.com/r/Use_Veracode_Fix_in_your_development_workflows.
Fix for SCA: https://docs.veracode.com/r/Veracode_Fix_for_SCA.
Veracode integrations: https://docs.veracode.com/r/Veracode_Integrations.
Measurable outcome. Median hours from an open policy-failing static or composition finding to a verified-fixed rescan. Percentage of high-severity findings closed by Fix versus manual rewrite. Pipeline block rate on new policy-failing flaws.
Assume the pivot from the appliance into cloud and cluster — Container Security, IaC, secrets, and CLI
Why now. SLAPSHOT’s purpose is internal reach. The cloud operator’s purpose is identity-driven destruction of cloud resources. Secrets in public issues and infrastructure-as-code misconfigurations are how those two meet. Container Security scans images, infrastructure-as-code, and exposed secrets, and can emit a software bill of materials. The CLI veracode scan command is the pipeline enforcement point.
Action. Scan every image that ships and every Terraform, Helm, and Kubernetes directory that defines production. Fail the build on embedded secrets and on policy-violating base images. Generate software bills of materials as CRA, NIS2, and DORA evidence, not as a compliance souvenir.
Live documentation.
Container Security, covering containers, IaC, and secrets: https://docs.veracode.com/r/Veracode_Container_Security.
Run Container Security scans: https://docs.veracode.com/r/Run_Container_Security_scans.
CLI veracode scan: https://docs.veracode.com/r/veracode_scan.
Install the Veracode CLI: https://docs.veracode.com/r/Install_the_Veracode_CLI.
Measurable outcome. Percentage of production images scanned before deploy. Secrets findings escaped to main — target zero. Software-bill-of-materials coverage of internet-facing services.
Treat the AI coding agent as a software supply chain
Why now. A coding-agent pinning failure broke the control that programs trusted. Package Firewall plus software composition analysis plus an allowlist of agent plugins is the available control set. Risk Manager then rolls agent-introduced findings into the same owner queue as everything else.
Action. Inventory AI coding-agent installs. Enforce patched versions where a vendor fix exists. Route agent plugin and package installs through Package Firewall. Do not wait for every vendor fix before compensating controls are in place.
Measurable outcome. Percentage of developer endpoints on patched agent versions. Plugin installs blocked that failed malware or pin-integrity policy.
Platform overview for executive readers: https://www.veracode.com/platform/.
What CISOs Should Do Now
Capacity-realistic sequence. Informed by the week and the month. Failure modes stated.
Hunt, then patch, then hunt again on Citrix, F5, and TeamCity. Look for WHIPSHOT and SLAPSHOT artifacts, unexpected .deb, .php, or .sig files in VPN script paths, setuid /bin/sh, high-availability peer surprises, and TeamCity agent-polling anomalies. Failure mode: patching without hunt leaves the implant and destroys evidence. BOD 26-04 forensic triage is the right standard even outside the federal civilian estate.
Cloud non-human identity. Enumerate service principals and workload identities with delete or key-read rights. Enable resource locks and delete-protection on storage accounts, Key Vaults, and recovery vaults. Rotate any secret that has ever appeared in a ticket, gist, or public issue. That seven-minute window is the design threat.
Identity residual from device-code phishing. Revoke refresh tokens and unused OAuth grants. Restrict device-code flow. Review mailbox forwarding and consent to new enterprise applications. Password reset is not containment.
This week.
PeopleSoft, Magento, and WordPress: treat as production incidents if unpatched against this month’s KEV entries. Web-application firewall rules that match literal paths are not closure.
Third-party path. Identify every security product that sits in an authorization, withdrawal, or build-approval path. The exchange custody incident is the object lesson. TeamCity is the software-factory version of the same lesson.
Package Firewall and SCA gate on developer ecosystems and continuous integration, including AI-agent plugin sources. Measure blocked packages this week, not next quarter.
EASM Deep Discovery against the corporate domain. Push new web and API assets into dynamic analysis. The unknown storefront or forgotten PeopleSoft URL is how the month’s campaigns scale.
This month — board-visible.
Replace CVSS-first ranking with a BOD 26-04-style queue inside Risk Manager: public exposure, KEV, automatable, total control.
Build one notification matrix covering GDPR, NIS2, DORA if in scope, CRA Article 14 if the organization manufactures, SEC Form 8-K if public, and a CIRCIA-ready 72-hour and 24-hour draft. The clocks already overlap. CIRCIA will add another.
Report to the board three numbers only. Percent of internet-facing KEV assets patched and forensically triaged. Time-to-inventory for NetScaler, F5, TeamCity, PeopleSoft, and Magento. Percent of production cloud storage and Key Vaults with delete-protection.
The week’s material events.
NetScaler with persistent tunneling malware, a KEV cluster on identity-adjacent appliances, PeopleSoft web-application-firewall bypass, TeamCity in ransomware use, and identity-driven cloud destruction — are the same problem viewed from different layers of the stack. Attackers are buying time on the trust boundary, then using identity and the software factory to convert access into impact. The month confirms the velocity. Programs that can evidence a three-day KEV service level, ingest-time package control, external-surface coverage, and non-human-identity delete-protection will take less damage in the fourth quarter than programs that add another dashboard. That is the residual-risk test. Everything else is commentary.
This report is provided for informational purposes only and is not intended as legal, technical, or professional advice. While we strive for accuracy, Veracode does not warrant the completeness or accuracy of the information. Recipients should not rely solely on this report and must conduct their own thorough investigation and verification. Please work with your internal teams and relevant stakeholders to properly assess, implement, and remediate any identified threats or vulnerabilities. The information has been compiled from multiple sources, and Veracode assumes no liability for any errors, omissions, or actions taken based on this content.