Just saw this recently. I check the security log regularly and I've started to notice entries like:
2026-09-07 22:51:12 92.150.54.138 {44.31.29.208} Authorization cookie check Failed :deleted
2026-09-07 22:51:16 92.150.54.138 {68.71.17.175} Authorization cookie check Failed :deleted
2026-09-07 22:51:16 92.150.54.138 {48.201.13.167} Authorization cookie check Failed :deleted
2026-09-07 22:51:27 92.150.54.138 {91.150.186.200} Authorization cookie check Failed :deleted
2026-09-07 22:51:27 92.150.54.138 {15.167.217.77} Authorization cookie check Failed :deleted
Looking at other logs such as cPanel visitor logs, the 92.150.54.138 IP address seems to be the main one actually accessing the site. I wonder where it's getting the other IP addresses from? Just curious. I typically ban these IP addresses.
And yeah, still on 1.5.7.
Thanks,
Mark H.
Some sort of load balancing (I've seen similar on another site from cloudflare)?