Traffic violation scams switch to QR codes in new phishing texts

2026-04-06T01:23:29Z77473bb7a8774781ba3086333943293f2e82512266c47b5905ccdd363eead532
browser-scanningcredential-theftdata-breachdevice-code-phishingeuropean-commissionexchange-onlineforticlientfortinetgithubinfostealeroauthphishingprivacyqilinqr-coderansomwarereact2shellsmishingsocial-engineeringsupply-chainteampcpvidarwindows-upgradezendesk

What happened

A range of active threats and incidents were reported: scammers are using QR-based traffic-violation smishing to steal payments and PII; a critical FortiClient EMS vulnerability (CVE-2026-35616) is being exploited and prompted an emergency patch; large-scale credential-theft campaigns exploit React2Shell (CVE-2025-55182) in Next.js apps; Axios maintainers suffered a supply-chain/social-engineering compromise; device-code (OAuth) phishing attacks have surged; LinkedIn was found to be secretly scanning browser extensions and collecting device data; Hims & Hers warns of a Zendesk-related data-bre

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
77473bb7a8774781ba3086333943293f2e82512266c47b5905ccdd363eead532
Enrichment time
2026-04-06T01:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Traffic violation scams switch to QR codes in new phishing texts · Baitaphish