Looking at our web honeypot data, I came across an odd new request header I hadn't seen before: "X-Forwarded-App". My first guess was that this is yet another issue with a proxy-server bucket brigade spilling secrets when a particular "App" is connecting to it. So I dove in a bit deeper, and found requests like this:

Trump administration halts government hunger report
The Trump administration has terminated an annual government hunger report, the U.S. Department of Agriculture (USDA) said Saturday. “The U.S. Department of Agriculture announced the