Residential proxies make a mockery of IP-based defenses
2026-04-06T08:51:59Z•f7e5f0b68c207aaaae31d95708e1d126a0c8eeff9bae622b96f65017ad5acd86
2FAAPERIONCVE-2026-20093CVE-2026-35616Cisco-IMCClaude-CodeFortiClient-EMSLiteLLMProton-AuthenticatorSmartFlowTeamPCPauth-bypasscertificate-expirationincident-responseip-reputationmalware-distributionnpm-compromiseon-prem-AIpatchingproxy-evasionresidential-proxiessecure-bootsource-code-leaksupply-chain-attackwireless-security
What happened
This collection highlights multiple active and emerging security risks: a critical FortiClient EMS zero‑day (CVE-2026-35616) is being exploited in the wild and Fortinet has issued emergency hotfixes; Cisco Integrated Management Controller has an auth‑bypass allowing remote admin access (CVE-2026-20093); attackers are leveraging residential proxy networks to mask malicious traffic and evade IP‑based reputations; a leaked Claude Code repository has been used to distribute malware lures; and supply‑chain attacks (e.g., npm/LiteLLM) continue to pose widespread risk. Also featured: guidance to use/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- f7e5f0b68c207aaaae31d95708e1d126a0c8eeff9bae622b96f65017ad5acd86
- Enrichment time
- 2026-04-06T08:51:59Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.