v vanemmerik.ai / SUPPLY-CHAIN · ARCHIVE

Every watch, in order.

65 watches published so far. Each one captures what crossed the wire that day — new disclosures, fresh CISA KEV adds, package-hijack campaigns in progress — ranked by severity.

THU 23 JUL 2026

Supply Chain Watch · 2026-07-23 · Two Auth.js Criticals, A Quiet Batch Behind Them

Two Auth.js advisories that can silently disable authentication anchor a day otherwise dominated by open redirects and memory-exhaustion bugs — React Router's four-advisory redirect-hardening batch, a paired pypdf infinite-loop fix, and a fresh PHPSpreadsheet SSRF bypass — with nothing yet confirmed under active attack.

2 critical 8 high 9 medium 2 context
WED 22 JUL 2026

Supply Chain Watch · 2026-07-22 · A four-wave Wednesday — Gitea, n8n twice, Netty, Next.js, Jetty, JupyterLab, LiteLLM — plus two KEV criticals

Late escalation at 21:00 ET: a fourth disclosure wave — 50 more advisories spanning a second n8n batch plus first-time appearances from Next.js, Eclipse Jetty, JupyterLab, and LiteLLM — landed within 75 minutes of the day's 18:00 synthesis, pushing the day's total past 135 items and its high-severity count past 55.

5 critical 56 high 62 medium 1 context
MON 20 JUL 2026

Supply Chain Watch · 2026-07-20 · A 90-advisory GHSA wave overshadows SleeperGem's RubyGems hijack

A same-day GHSA wave that ran from 6pm to past 9pm ET eventually reached 90 advisories, overshadowing SleeperGem's quiet RubyGems hijack — headlined by a critical node-tar bug reachable through every npm install, a Composer bug that lets a malicious transitive dependency write files outside vendor/, and a second, equally large round of Pillow, Axios, and .NET disclosures that landed after First Watch had already gone to print.

4 critical 38 high 44 medium 7 context
TUE 14 JUL 2026

Supply Chain Watch · 2026-07-14

A pile-up day: four new FacturaScripts advisories, three same-root-cause Anyquery RCE-class bugs, and three separate MCP-server disclosures landed alongside two live GitHub/npm impersonation campaigns and four newly-confirmed CISA KEV exploits.

12 critical 22 high 17 medium 0 context
MON 13 JUL 2026

Supply Chain Watch · 2026-07-13 — A late Kimai Docker-secret account takeover and a brute-forceable FacturaScripts 2FA bypass escalate the day to five criticals

A late 21:00 ET wave adds two more confirmed-exploitable criticals — a hardcoded Docker default secret enabling Kimai account takeover and a brute-forceable FacturaScripts 2FA bypass — on top of a day that already carried a newly-exploited legacy Cisco IOS bug, DIRAC's double eval()-to-RCE disclosure, and day three of the unresolved jscrambler npm infostealer.

5 critical 4 high 2 medium 8 context
FRI 10 JUL 2026

Supply Chain Watch · 2026-07-10 — SiYuan answers YesWiki's 13-advisory morning with 7 of its own, three RCE chains deep, while a compromised Injective Labs repo ships a wallet-stealing npm package

A second coordinated multi-CVE batch — seven SiYuan advisories with three independent RCE chains — landed hours after this morning's YesWiki disclosure, while a compromised Injective Labs GitHub repo pushed a wallet-draining npm package into the wild.

15 critical 25 high 26 medium 2 context
THU 09 JUL 2026

Supply Chain Watch · 2026-07-09 — Wallet and payment SDKs hit across three ecosystems, YesWiki takes a 13-advisory teardown, then a late Elixir HTTP-client batch lands after bed-check

Late escalation at 21:00 ET: a fresh GHSA batch lands three more high-severity disclosures — header-leak and memory-exhaustion bugs across Elixir's two workhorse HTTP clients, Tesla and Mint — on top of a day already shaped by a three-ecosystem wallet/payment-credential wave and a 13-advisory YesWiki teardown.

6 critical 13 high 14 medium 0 context
WED 08 JUL 2026

Supply Chain Watch · 2026-07-08 — Agentic tooling's authless-API problem

Five unrelated AI-agent and MCP-adjacent tools — Langflow, Open WebUI, ha-mcp, ckan-mcp-server, and Serena — disclosed authorization or authentication gaps on the same day, the clearest sign yet that agentic tooling is shipping with the auth debt web frameworks paid off a decade ago.

8 critical 9 high 13 medium 3 context
SAT 04 JUL 2026

PolinRider Keeps Scaling, and Little Else Broke

The DPRK-linked PolinRider campaign is now up to 108 malicious packages and browser extensions across four ecosystems, and it's the only story of the day — KEV, GHSA, and the rest of the RSS feeds stayed quiet.

1 critical 0 high 0 medium 0 context
FRI 03 JUL 2026

Six Projects, One Coordinated-Disclosure Day

Six unrelated open-source projects each shipped a coordinated multi-CVE batch today, from Steeltoe's seven advisories to Zebra's twelve, while the MCP-gateway trust-boundary bug count for the week climbed to four.

9 critical 15 high 2 medium 1 context
THU 25 JUN 2026

golang.org/x/crypto/ssh breaks open late on a Go-heavy day

A late coordinated disclosure cracks the golang.org/x/crypto/ssh stack open — a CVSS-10 public-key auth bypass and five more critical SSH/agent flaws — onto a day already defined by Shai-Hulud crossing into Go and OpenAM's five-way collapse.

7 critical 9 high 3 medium 4 context
TUE 23 JUN 2026

Supply Chain Watch · 2026-06-23 — Identity takes the brunt; late Snipe-IT tenancy batch

Identity infrastructure took the brunt — pre-auth RCE in OpenDJ, pre-auth XSS and LDAP injection in OpenAM, and LastPass breached through stolen OAuth tokens — while npm typosquats dropped a Windows RAT, CISA logged four exploited appliance flaws, and a late Snipe-IT disclosure batch added a cross-tenant data injection after the bell.

4 critical 7 high 2 medium 1 context
MON 22 JUN 2026

Supply Chain Watch · 2026-06-22 · The trusted update channel was the attack

The trusted update channel was the attack: ShapedPlugin shipped a CVSS-10 backdoor through official Pro-plugin releases for a month — and the evening brought a late wave of forge and npm-library disclosures, capped by a fresh SCIM prototype-pollution critical.

3 critical 4 high 0 medium 1 context
SUN 21 JUN 2026

Supply Chain Watch · 2026-06-21 — A quiet Sunday on the registries

A quiet Sunday on the registries — no new criticals and no fresh KEV adds, leaving the day's only live thread an actively-exploited WordPress plugin leaking the API keys and OAuth tokens that downstream attacks usually have to phish for.

0 critical 0 high 1 medium 0 context
SAT 20 JUN 2026

Supply Chain Watch · 2026-06-20 — A state actor claims the Mastra compromise

Microsoft pinned last week's 140-package Mastra AI npm compromise on North Korea's BlueNoroff while the agent stack kept failing in public — a third critical-class Langflow hole now on CISA KEV, fresh cross-tenant breaks in the agent-memory stores, and another MCP-server SSRF and path-traversal cluster.

2 critical 7 high 10 medium 4 context
FRI 19 JUN 2026

Supply Chain Watch · 2026-06-19 — The agentic toolchain audits itself in public

The agentic toolchain audited itself in public all day — Langflow and Network-AI criticals, an MCP-server SSRF/XSS cluster, and cross-tenant breaks across the agent-memory stores — and kept going after dark with a LangSmith SDK file-read and a Lokka MCP Azure-token leak.

5 critical 21 high 14 medium 0 context
THU 18 JUN 2026

Supply Chain Watch · The agent ecosystem's bad day

AI agent frameworks and MCP servers became the day's soft target — a dozen-plus unauthenticated-control-plane and prompt-injection-to-RCE holes landed across PraisonAI, Crawl4AI, OpenClaw and the MCP tooling, while a real update-channel compromise hit WordPress and CISA flagged an actively-exploited Splunk file-write.

15 critical 13 high 39 medium 2 context
TUE 16 JUN 2026

Supply Chain Watch · 2026-06-16 — AI-stack mass disclosure escalates after dark: Rclone unauth RCE, LiteLLM auth bypass, n8n CVSS-10 browser hole & cross-tenant cred takeover, Gitea/Gogs token-scope bypasses

The day escalated after dark: unauthenticated RCE in Rclone, an auth bypass in the LiteLLM proxy, a CVSS-10 unauthenticated browser-control hole and cross-tenant credential takeover in n8n, and a token-scope-bypass cluster across Gitea and Gogs piled onto the AI-development-stack mass disclosure and the IDE plugins caught stealing AI keys.

10 critical 22 high 5 medium 4 context
SUN 14 JUN 2026

A quiet registry day, and a decade-long auth-stack hijack

A rare quiet day across the registries, with the lone headline a decade-long hijack of a target's authentication stack that reframes identity as the supply chain's deepest dependency.

0 critical 0 high 0 medium 1 context
SAT 13 JUN 2026

File Browser empties its disclosure queue

The week's File Browser disclosure run crests with six advisories dropped at once — unauth share leaks, a one-packet login DoS, zip-slip and symlink escapes — while esbuild's Deno installer quietly reopens a build-time RCE path.

0 critical 12 high 22 medium 1 context
FRI 29 MAY 2026

Supply Chain Watch · 2026-05-29

Late escalation at 21:00 ET: a 19-advisory audit dump against PraisonAI lands on top of the morning's vm2/Redshift/Gotenberg trio — official A2A example reaches unauthenticated `eval()`, `deploy --type api` ships with auth disabled, and Platform's JWT key defaults to a hardcoded `dev-secret-change-me`.

3 critical 9 high 8 medium 2 context