v vanemmerik.ai / SUPPLY-CHAIN
Supply Chain · Watch Sunday · 13 September 2026 End-of-day synthesis 4 watches · 2 items

From the watchtower — what crossed the wire today.

A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild — then ranks them by severity for the day.

The story of the day — A genuinely quiet evening — the only two items are a Microsoft disclosure about trusted-infrastructure phishing and a CVE catching up to an already-known China-linked backdoor campaign, with nothing new hitting npm, PyPI, or CISA's KEV list today.

First Watch closes out a slow day for the registries: no new GHSA disclosures matched the window, CISA hasn't added anything to KEV since yesterday's Artifactory/ScreenConnect/GitLab batch, and the RSS sweep surfaced only two context-tier items.

Microsoft disclosed two campaigns that ride on infrastructure targets already trust rather than compromising it directly — a million-plus CEO-impersonation scam routed through legitimate bulk-mail delivery services, and passkey-themed phishing used to hijack Entra ID/M365 accounts — the same "abuse what's already trusted" shape this feed tracks in package registries, just aimed at identity instead of code. Separately, BleepingComputer's write-up on the Tencent Sogou Input Method backdoor assigns a CVE (CVE-2026-51990) to the same UNC3569/GRAYRABBIT campaign flagged here two days ago; read it as confirmation, not a new threat.

The bright spot is the quiet itself: no active package-poisoning campaign is running today, and the week's two open threads — the Artifactory-to-backdoor campaign and the Shopper authorization-bug siblings — didn't produce overnight sequels. Operational priority for the night: no fire drill needed; use the lull to confirm SPF/DKIM alignment can't be spoofed on any outbound mail infra you operate, and confirm Sogou IME is patched to 16.3.0.3498+ if it's present anywhere in your environment.

18:00 ET · First Watch

BleepingComputer follow-up assigns CVE-2026-51990 to the Sogou IME flaw behind the GRAYRABBIT backdoor

BleepingComputer's write-up assigns CVE-2026-51990 to the same Tencent Sogou Input Method flaw and GRAYRABBIT backdoor that The Hacker News tied to China-linked UNC3569 two days ago — this reads as a CVE catching up to an already-disclosed campaign, not a new vulnerability or a new actor. Targeting (government, education, and financial orgs across East and Southeast Asia) and the vector (a widely-installed third-party IME) are unchanged from the 09-11 item, so treat this as confirmation rather than escalation. No new action beyond the standing guidance: confirm Sogou IME is current (16.3.0.3498+) if it's present in your environment.

12:00 ET · Forenoon Watch

Passkey phishing and third-party email infra abuse used to hijack Microsoft cloud accounts

Microsoft disclosed two active campaigns riding on trusted third-party infrastructure: 1M+ CEO-impersonation scam emails routed through legitimate bulk-mail delivery services between August 3-5, and passkey-themed phishing used to hijack Entra ID/M365 accounts for data exfiltration. Neither touches a package ecosystem, but the shape — abuse infrastructure the target already trusts rather than compromise it directly — is the same pattern this feed tracks in npm/PyPI campaigns; route to IAM/security-awareness rather than SRE. If you operate outbound mail through shared delivery infra, verify SPF/DKIM alignment can't be spoofed by a look-alike sender.