FortiClient EMS is under active exploitation through CVE-2026-35616, a critical improper access control flaw affecting versions 7.4.5 and 7.4.6. The vulnerability allows pre-authentication API bypass and may let attackers execute unauthorised code or commands via crafted requests..
React2Shell exploitation is driving an automated credential theft campaign against vulnerable Next.js applications. Device code phishing activity also surged 37-fold this year, abusing the OAuth 2.0 Device Authorization Grant flow to hijack user accounts.
A GitHub Actions campaign abused pull_request_target to open more than 500 malicious pull requests between 11 March and 3 April 2026. The payloads targeted files including conftest.py, package.json, Makefile, and build.rs, and led to compromise of two npm packages across 106 versions.
The European Commission breach began after attackers used an AWS API key stolen through the Trivy supply chain compromise on 19 March. The intrusion exposed about 91.7 GB of compressed data from infrastructure serving 71 clients, including at least 29 other Union entities.
Thirty-six malicious npm packages masquerading as Strapi plugins targeted Redis and PostgreSQL environments with reverse shells, credential theft, and persistent implants. A separate software supply chain wave also involved attackers posting the leaked Claude Code source together with malware.
Fake traffic violation text messages impersonating U.S. state courts used QR codes to direct victims to phishing pages requesting a $6.99 payment. The Drift cryptocurrency theft, which resulted in losses of $285 million, was attributed to a six-month DPRK social engineering operation.