Traffic violation scams switch to QR codes in new phishing texts
2026-04-06T07:23:33Z•9bf16ba0a9f2bbb2cd00ead1e3f615418e094c896ef248facc56743ba050d4f3
CVE-2025-55182CVE-2026-35616European-CommissionFortiClient EMSFortinetGitHubHims & HersOAuthQilinReact2ShellTeamPCPVidarZendeskcloud-hack','CERT-EU'credential-theftdata-breachdevice-code-phishinginfostealermulti-extortionnpmphishingqr-coderansomwaresocial-engineeringsupply-chain
What happened
A range of active and emerging threats reported across April 2026: a critical FortiClient EMS vulnerability (CVE-2026-35616) is being actively exploited prompting an emergency patch; Next.js React2Shell (CVE-2025-55182) is being abused in large automated credential-theft campaigns; device-code (OAuth) phishing attacks and QR-code traffic-violation scams are proliferating to harvest credentials and payments; supply-chain and social-engineering incidents hit open-source (Axios npm maintainer hijack) and GitHub (fake repos pushing Vidar infostealer leveraging the Claude Code leak); high-impact OP
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 9bf16ba0a9f2bbb2cd00ead1e3f615418e094c896ef248facc56743ba050d4f3
- Enrichment time
- 2026-04-06T07:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.