Traffic violation scams switch to QR codes in new phishing texts
2026-04-06T01:23:29Z•77473bb7a8774781ba3086333943293f2e82512266c47b5905ccdd363eead532
browser-scanningcredential-theftdata-breachdevice-code-phishingeuropean-commissionexchange-onlineforticlientfortinetgithubinfostealeroauthphishingprivacyqilinqr-coderansomwarereact2shellsmishingsocial-engineeringsupply-chainteampcpvidarwindows-upgradezendesk
What happened
A range of active threats and incidents were reported: scammers are using QR-based traffic-violation smishing to steal payments and PII; a critical FortiClient EMS vulnerability (CVE-2026-35616) is being exploited and prompted an emergency patch; large-scale credential-theft campaigns exploit React2Shell (CVE-2025-55182) in Next.js apps; Axios maintainers suffered a supply-chain/social-engineering compromise; device-code (OAuth) phishing attacks have surged; LinkedIn was found to be secretly scanning browser extensions and collecting device data; Hims & Hers warns of a Zendesk-related data-bre
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 77473bb7a8774781ba3086333943293f2e82512266c47b5905ccdd363eead532
- Enrichment time
- 2026-04-06T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.