v vanemmerik.ai / SUPPLY-CHAIN
Supply Chain · Watch Sunday · 06 September 2026 End-of-day synthesis 4 watches · 2 items

From the watchtower — what crossed the wire today.

A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild — then ranks them by severity for the day.

The story of the day — A quiet day on the new-item front, but the two open threads from earlier in the week kept getting worse in the details: the fake-Claude-Desktop stealer campaign grew persistence modules that survive its own cleanup, and Magento/Adobe Commerce store operators are into a second day with zero vendor fix for StyleSmuggler.

Nothing new broke today that rises above medium severity — this pass is mostly about two already-open threads getting more detail, plus a routine KEV backfill.

Elastic's REVSTEALER writeup added the sharpest new detail: the malware distributed via a trojanized "Claude Opus 5 Free Desktop" installer now drops four persistence modules that outlive the stealer's own self-deletion, and one of them disables Windows Update and Defender specifically to clear room for a cryptominer. Separately, the unauthenticated, unpatched Magento and Adobe Commerce zero-day (StyleSmuggler) flagged in yesterday's First Watch is now into its second day with no CVE, advisory, or patch from Adobe — that story hasn't changed today, so it's not re-listed as a new item, but it isn't resolved either. The only other addition is a routine CISA KEV backfill of two decade-old Red Hat local-privilege-escalation bugs, relevant only to shops still running legacy RHEL hosts.

→ Operational priority for the night if you run Magento Open Source or Adobe Commerce, don't wait on a vendor patch — apply Sansec's published StyleSmuggler mitigations tonight and check logs for the payment-failure-email trigger pattern.

12:00 ET · Forenoon Watch

CISA KEV backfill: two 2015-era Red Hat local privilege-escalation bugs (CVE-2015-3246, CVE-2015-5287)

CISA's August 26 KEV batch included two decade-old Red Hat bugs this pipeline's window missed at the time: a libuser race condition that lets an authenticated local user corrupt /etc/passwd (CVE-2015-3246), and a symlink attack in the Automatic Bug Reporting Tool that escalates local privileges via a predictable temp file (CVE-2015-5287). Both are local-only, EoL-adjacent, and only matter if you're still running RHEL-era hosts with libuser or ABRT installed — but a KEV listing means CISA has evidence of active exploitation somewhere, however old. If you have legacy Red Hat systems still in service, confirm libuser and abrt are patched or removed; there's no supply-chain angle here, just two old holes getting caught by the backfill window.

06:00 ET · Morning Watch

Four undocumented REVSTEALER-linked modules disable Windows Update and Defender to run a crypto miner

Elastic Security Labs found four previously unreported persistence modules (including ones named ProManager, WinUpdate, and SoftManager) tied to REVSTEALER — the infostealer distributed via a trojanized "Claude Opus 5 Free Desktop" Electron installer impersonating Anthropic — that stay resident and keep running after the stealer itself deletes its own binary. One of the four turns off Windows Update and Microsoft Defender specifically to clear the way for a cryptocurrency miner, so the credential-theft payload and the defense-disabling payload now outlive each other's detection windows. If you've seen an unofficial "Claude Desktop" or similar AI-app installer on a Windows host, don't stop at removing the stealer: check Windows Update service state and Defender exclusion lists for tampering, since the persistence modules are designed to survive the initial cleanup.