Traffic violation scams switch to QR codes in new phishing texts
2026-04-06T13:23:35Z•078a394ad669246de6551a2d884de6df3beae09b00b652a7cc21cce3cd37fc07
account-takeoverbrowser-scanningcloud-breachcredential-theftcve-2025-55182cve-2026-35616data-breachdevice-code-phishingexploitfortinetinfostealerlinkedinnorth-koreanpmoauthphishingqilinqr-code-phishingransomwarereact2shellsupply-chainteampcpvidarvulnerabilityzendesk
What happened
Multiple active threats and high-impact incidents reported: Fortinet issued an emergency patch for a critical FortiClient EMS vulnerability (CVE-2026-35616) that is being actively exploited, and attackers continue exploiting React2Shell (CVE-2025-55182) in automated credential-theft campaigns against vulnerable Next.js apps. Phishing continues to evolve — QR-code traffic-violation scams and a 37x surge in OAuth device-code phishing kits are stealing credentials and payments. Supply-chain and account-takeover incidents include an Axios maintainer hijack (social engineering, attributed to DPRK),
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 078a394ad669246de6551a2d884de6df3beae09b00b652a7cc21cce3cd37fc07
- Enrichment time
- 2026-04-06T13:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.