v vanemmerik.ai / SUPPLY-CHAIN · ARCHIVE

Every watch, in order.

30 watches published so far. Each one captures what crossed the wire that day — new disclosures, fresh CISA KEV adds, package-hijack campaigns in progress — ranked by severity.

MON 22 JUN 2026

Supply Chain Watch · 2026-06-22 · The trusted update channel was the attack

The trusted update channel was the attack: ShapedPlugin shipped a CVSS-10 backdoor through official Pro-plugin releases for a month — and the evening brought a late wave of forge and npm-library disclosures, capped by a fresh SCIM prototype-pollution critical.

3 critical 4 high 0 medium 1 context
SUN 21 JUN 2026

Supply Chain Watch · 2026-06-21 — A quiet Sunday on the registries

A quiet Sunday on the registries — no new criticals and no fresh KEV adds, leaving the day's only live thread an actively-exploited WordPress plugin leaking the API keys and OAuth tokens that downstream attacks usually have to phish for.

0 critical 0 high 1 medium 0 context
SAT 20 JUN 2026

Supply Chain Watch · 2026-06-20 — A state actor claims the Mastra compromise

Microsoft pinned last week's 140-package Mastra AI npm compromise on North Korea's BlueNoroff while the agent stack kept failing in public — a third critical-class Langflow hole now on CISA KEV, fresh cross-tenant breaks in the agent-memory stores, and another MCP-server SSRF and path-traversal cluster.

2 critical 7 high 10 medium 4 context
FRI 19 JUN 2026

Supply Chain Watch · 2026-06-19 — The agentic toolchain audits itself in public

The agentic toolchain audited itself in public all day — Langflow and Network-AI criticals, an MCP-server SSRF/XSS cluster, and cross-tenant breaks across the agent-memory stores — and kept going after dark with a LangSmith SDK file-read and a Lokka MCP Azure-token leak.

5 critical 21 high 14 medium 0 context
THU 18 JUN 2026

Supply Chain Watch · The agent ecosystem's bad day

AI agent frameworks and MCP servers became the day's soft target — a dozen-plus unauthenticated-control-plane and prompt-injection-to-RCE holes landed across PraisonAI, Crawl4AI, OpenClaw and the MCP tooling, while a real update-channel compromise hit WordPress and CISA flagged an actively-exploited Splunk file-write.

15 critical 13 high 39 medium 2 context
TUE 16 JUN 2026

Supply Chain Watch · 2026-06-16 — AI-stack mass disclosure escalates after dark: Rclone unauth RCE, LiteLLM auth bypass, n8n CVSS-10 browser hole & cross-tenant cred takeover, Gitea/Gogs token-scope bypasses

The day escalated after dark: unauthenticated RCE in Rclone, an auth bypass in the LiteLLM proxy, a CVSS-10 unauthenticated browser-control hole and cross-tenant credential takeover in n8n, and a token-scope-bypass cluster across Gitea and Gogs piled onto the AI-development-stack mass disclosure and the IDE plugins caught stealing AI keys.

10 critical 22 high 5 medium 4 context
SUN 14 JUN 2026

A quiet registry day, and a decade-long auth-stack hijack

A rare quiet day across the registries, with the lone headline a decade-long hijack of a target's authentication stack that reframes identity as the supply chain's deepest dependency.

0 critical 0 high 0 medium 1 context
SAT 13 JUN 2026

File Browser empties its disclosure queue

The week's File Browser disclosure run crests with six advisories dropped at once — unauth share leaks, a one-packet login DoS, zip-slip and symlink escapes — while esbuild's Deno installer quietly reopens a build-time RCE path.

0 critical 12 high 22 medium 1 context
FRI 29 MAY 2026

Supply Chain Watch · 2026-05-29

Late escalation at 21:00 ET: a 19-advisory audit dump against PraisonAI lands on top of the morning's vm2/Redshift/Gotenberg trio — official A2A example reaches unauthenticated `eval()`, `deploy --type api` ships with auth disabled, and Platform's JWT key defaults to a hardcoded `dev-secret-change-me`.

3 critical 9 high 8 medium 2 context