Traffic violation scams switch to QR codes in new phishing texts

2026-04-06T07:23:33Z9bf16ba0a9f2bbb2cd00ead1e3f615418e094c896ef248facc56743ba050d4f3
CVE-2025-55182CVE-2026-35616European-CommissionFortiClient EMSFortinetGitHubHims & HersOAuthQilinReact2ShellTeamPCPVidarZendeskcloud-hack','CERT-EU'credential-theftdata-breachdevice-code-phishinginfostealermulti-extortionnpmphishingqr-coderansomwaresocial-engineeringsupply-chain

What happened

A range of active and emerging threats reported across April 2026: a critical FortiClient EMS vulnerability (CVE-2026-35616) is being actively exploited prompting an emergency patch; Next.js React2Shell (CVE-2025-55182) is being abused in large automated credential-theft campaigns; device-code (OAuth) phishing attacks and QR-code traffic-violation scams are proliferating to harvest credentials and payments; supply-chain and social-engineering incidents hit open-source (Axios npm maintainer hijack) and GitHub (fake repos pushing Vidar infostealer leveraging the Claude Code leak); high-impact OP

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
9bf16ba0a9f2bbb2cd00ead1e3f615418e094c896ef248facc56743ba050d4f3
Enrichment time
2026-04-06T07:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Traffic violation scams switch to QR codes in new phishing texts · Baitaphish