v vanemmerik.ai / SUPPLY-CHAIN
Supply Chain · Watch Friday · 11 September 2026 Live · last refresh 12:00 ET · Forenoon Watch 2 watches · 2 items

From the watchtower — what crossed the wire today.

A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild — then ranks them by severity for the day.

06:00 ET · Morning Watch

Attackers chain three JFrog Artifactory flaws to full admin control and plant backdoors

Wiz traced active exploitation of JFrog Artifactory between Aug 15 and Sep 8 to three chained flaws: CVE-2026-42018 leaks the internal anonymous-user token even with anonymous access disabled, CVE-2026-42016's scope-validation gap lets that low-privilege token get elevated, and CVE-2026-82329 is an unauthenticated POST to /access/api/v1/registry/join that hands out an admin-scoped token outright on default configuration. Attackers used the admin access to create persistent accounts, deploy malicious Groovy plugins, run shell commands, and install Rust-based backdoors, then harvested cluster join keys — Artifactory sits at the center of CI/CD as the build-pipeline source of truth, so admin compromise there is the same blast-radius shape as a poisoned package registry. Patch to JFrog's fixed release now and audit self-hosted instances for unexpected admin accounts, unfamiliar Groovy plugins, or join-key rotations in that window.

China-linked UNC3569 exploits a Sogou Input Method flaw to drop the GRAYRABBIT backdoor

Gen Digital ties China-linked group UNC3569 to a flaw in Sogou Input Method — patched upstream in Tencent's 16.3.0.3498 — used via a crafted link to drop the group's long-running GRAYRABBIT backdoor, a lightweight implant built for file operations, recon, and a remote shell. Targeting stayed narrow (government, education, and financial orgs across East and Southeast Asia), so this reads as targeted espionage rather than a mass supply-chain compromise, but the vector — a widely-installed third-party input tool — is the same trusted-software angle worth remembering. No action needed beyond confirming Sogou IME is current if it's present in your environment.