There has been a small wave of spam tonight, consisting of images containing nothing but a QR code. (Do not scan these!) They're directly mentioning users, so may not be visible on everyone's feeds. We've suspended some affected instances, but in addition, there are some Mastodon settings you can configure that should help you avoid getting this type of spam.
1. Click on Notifications.
2. Click the gear icon to open settings.
3. You'll see five categories of accounts, each with a button that opens a dropdown menu.
4. Choosing Filter or Ignore on "People you don't follow," "New accounts," and "Unsolicited private mentions" should prevent you from seeing most spam. (Some of these settings might also filter out mentions you do want to see, so adapt this to your own needs.)
If you're using a third-party app, these settings may be different.