Traffic violation scams switch to QR codes in new phishing texts

2026-04-06T13:23:35Z078a394ad669246de6551a2d884de6df3beae09b00b652a7cc21cce3cd37fc07
account-takeoverbrowser-scanningcloud-breachcredential-theftcve-2025-55182cve-2026-35616data-breachdevice-code-phishingexploitfortinetinfostealerlinkedinnorth-koreanpmoauthphishingqilinqr-code-phishingransomwarereact2shellsupply-chainteampcpvidarvulnerabilityzendesk

What happened

Multiple active threats and high-impact incidents reported: Fortinet issued an emergency patch for a critical FortiClient EMS vulnerability (CVE-2026-35616) that is being actively exploited, and attackers continue exploiting React2Shell (CVE-2025-55182) in automated credential-theft campaigns against vulnerable Next.js apps. Phishing continues to evolve — QR-code traffic-violation scams and a 37x surge in OAuth device-code phishing kits are stealing credentials and payments. Supply-chain and account-takeover incidents include an Axios maintainer hijack (social engineering, attributed to DPRK),

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
078a394ad669246de6551a2d884de6df3beae09b00b652a7cc21cce3cd37fc07
Enrichment time
2026-04-06T13:23:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.