ISC Stormcast For Monday, March 16th, 2026 https://isc.sans.edu/podcastdetail/9850, (Mon, Mar 16th)

2026-03-16T07:23:50Z40293370261650601e8e9556c654a722f1860183312d3d56b9c9c5f3b8843c7f
CVE-2026-0866ChromiumClickFixEdgeEmailJSIoTMicrosoft Patch TuesdayRATReactRemcosSANS ISCSmartApeSGZombie Zipcredential-theftdefault-credentialsphishingvulnerability-management

What happened

SANS ISC diary roundup (March 10–16, 2026) covering multiple security items: a SmartApeSG campaign using a ClickFix page to deliver the Remcos RAT; a React-based phishing page that exfiltrates credentials via the legitimate EmailJS service; a guest note on risk from IoT devices that log in as admin; analysis of the newly published 'Zombie Zip' vulnerability (CVE-2026-0866); and Microsoft Patch Tuesday (March 2026) addressing 93 vulnerabilities (including 9 Chromium issues in Edge and 8 rated critical).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
40293370261650601e8e9556c654a722f1860183312d3d56b9c9c5f3b8843c7f
Enrichment time
2026-03-16T07:23:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.