v vanemmerik.ai / SUPPLY-CHAIN
Supply Chain · Watch Monday · 27 July 2026 Live · last refresh 12:00 ET · Forenoon Watch 2 watches · 1 items

From the watchtower — what crossed the wire today.

A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild — then ranks them by severity for the day.

12:00 ET · Forenoon Watch

Ernst & Young data breach claimed by ShinyHunters extortion gang

ShinyHunters is extorting Ernst & Young over a breach it says started with credentials stolen via a supply-chain attack on a third-party support-ticket platform, then used to pivot into EY's own Jira, GitHub, and Azure environments between March 28 and April 12. The shape is the now-familiar ShinyHunters pattern from this year's Salesforce/Snowflake-adjacent campaigns: compromise a vendor's access layer, harvest live credentials, walk straight into source control and cloud infrastructure rather than malware-drop your way in. If your org shares SSO tokens or API credentials with third-party helpdesk/support-ticket vendors, rotate them now — EY says the incident is contained, but the gang's leak-site deadline is July 31.