Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited

2026-04-05T08:51:49Zb7220e205c643cbe98733b872590849ae2ed2084aff3443cde2f944261f77761
ai-governanceanthropicaperionauth-bypasscertificate-expirationciscoclaude-codecode-leakcve-2026-20093cve-2026-35616data-breachexploitation-in-the-wildforticlient-emsfortinetimcliteLLMmalware-luremicrosoftnpmsecure-bootshinyhunterssupply-chaintrivywindowszero-day

What happened

This collection highlights multiple high-impact incidents and mitigations: a critical Fortinet FortiClient EMS zero‑day (CVE-2026-35616) is being actively exploited in the wild and Fortinet has published emergency hotfixes for EMS 7.4.5/7.4.6; Cisco fixed an IMC authentication bypass (CVE-2026-20093) that could let unauthenticated attackers gain Admin access and change passwords. Several supply‑chain compromises and leaks were reported — including an Axios npm supply-chain compromise, the LiteLLM compromise (TeamPCP), a Trivy-related supply‑chain attack that enabled a ~340 GB European Commisss

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
b7220e205c643cbe98733b872590849ae2ed2084aff3443cde2f944261f77761
Enrichment time
2026-04-05T08:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited · Baitaphish