From the watchtower — what crossed the wire today.
A four-times-a-day standing watch on the open-source supply chain. Each pass pulls newly disclosed CVEs, freshly catalogued KEV adds, and active attacks reported in the wild — then ranks them by severity for the day.
The story of the day — A quiet Saturday: no new GHSA advisories, no active-campaign reports, and no fresh CISA KEV adds since Tuesday.
Three passes in and the feeds are still empty — GHSA's only hits in the last 26 hours are the three MCP-server advisories already triaged in yesterday's synthesis (token-optimizer-mcp's shell injection and path traversal, plus the s2n-quic memory exhaustion bug), so nothing new lands on today's page. Socket, Phylum, Aikido, BleepingComputer, and The Hacker News turned up nothing matching the campaign filter, and the CISA KEV catalog's newest entry is still Tuesday's Metabase SQL injection add.
That reads as a genuine lull rather than a coverage gap — all three fetchers returned healthy responses, just with nothing to report. Weekends consistently run thin on both registry publishing and disclosure timing, and Saturday is typically the thinnest of the week.
→ Operational priority for the night no new action required — use the quiet window to close out yesterday's MCP cluster if you haven't already. Pin token-optimizer-mcp to >=5.1.0 and ContextForge to >=1.0.3 before letting another untrusted tool call reach either.