Week in review: Axios npm supply chain compromise, critical FortiClient EMS bugs exploited
2026-04-05T08:51:49Z•b7220e205c643cbe98733b872590849ae2ed2084aff3443cde2f944261f77761
ai-governanceanthropicaperionauth-bypasscertificate-expirationciscoclaude-codecode-leakcve-2026-20093cve-2026-35616data-breachexploitation-in-the-wildforticlient-emsfortinetimcliteLLMmalware-luremicrosoftnpmsecure-bootshinyhunterssupply-chaintrivywindowszero-day
What happened
This collection highlights multiple high-impact incidents and mitigations: a critical Fortinet FortiClient EMS zero‑day (CVE-2026-35616) is being actively exploited in the wild and Fortinet has published emergency hotfixes for EMS 7.4.5/7.4.6; Cisco fixed an IMC authentication bypass (CVE-2026-20093) that could let unauthenticated attackers gain Admin access and change passwords. Several supply‑chain compromises and leaks were reported — including an Axios npm supply-chain compromise, the LiteLLM compromise (TeamPCP), a Trivy-related supply‑chain attack that enabled a ~340 GB European Commisss
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- b7220e205c643cbe98733b872590849ae2ed2084aff3443cde2f944261f77761
- Enrichment time
- 2026-04-05T08:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.