v vanemmerik.ai / SUPPLY-CHAIN
Supply Chain · Watch Saturday · 18 July 2026 End-of-day synthesis 4 watches · 1 items

From the watchtower — what crossed the wire today.

A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild — then ranks them by severity for the day.

The story of the day — The only development on an otherwise silent Saturday was ACR Stealer's ClickFix campaign graduating from a researcher writeup to a vendor-confirmed, enterprise-scale surge.

Saturday was the quietest pass in weeks: all three fetchers came back empty of anything new since this morning, no fresh GHSA disclosures, no new CISA KEV adds, nothing from Phylum, Socket, Aikido, or Hacker News in the last six hours. The registries and disclosure feeds simply went dark for the weekend.

The one holdover from this morning got worse, not better. Microsoft's own security telemetry now shows a surge in ACR Stealer hits against its enterprise customers — the same infostealer the Hacker News writeup flagged yesterday riding ClickFix lures to lift session tokens and OneDrive/SharePoint documents. A vendor issuing a customer-facing warning off its own telemetry is a different signal than a researcher's one-off case study; it means the campaign's hit rate is high enough to move the needle across Microsoft's install base, not a handful of isolated ClickFix victims. We're re-ranking it from context to high on that basis.

→ Operational priority for the night gate or block Win+R paste flows on managed endpoints, and treat any session token from a host that may have run a ClickFix lure as burned — rotate it, don't just reset the password.

12:00 ET · Forenoon Watch

Microsoft warns of a surge in ACR Stealer attacks against its enterprise customers

Microsoft's own telemetry now shows a surge in ACR Stealer hits against enterprise customers — the same infostealer this watch flagged yesterday riding ClickFix lures to lift session tokens and OneDrive/SharePoint documents. The jump from a researcher writeup to a vendor-issued customer warning means the campaign's hit rate is high enough to move the needle at scale, not a handful of isolated ClickFix victims; re-ranked from context to high on that basis. Guidance is unchanged: gate or block Win+R paste flows, and treat any live session token from a possibly-affected host as burned, not just the password.