ISC Stormcast For Monday, March 16th, 2026 https://isc.sans.edu/podcastdetail/9850, (Mon, Mar 16th)
2026-03-16T07:23:50Z•40293370261650601e8e9556c654a722f1860183312d3d56b9c9c5f3b8843c7f
CVE-2026-0866ChromiumClickFixEdgeEmailJSIoTMicrosoft Patch TuesdayRATReactRemcosSANS ISCSmartApeSGZombie Zipcredential-theftdefault-credentialsphishingvulnerability-management
What happened
SANS ISC diary roundup (March 10–16, 2026) covering multiple security items: a SmartApeSG campaign using a ClickFix page to deliver the Remcos RAT; a React-based phishing page that exfiltrates credentials via the legitimate EmailJS service; a guest note on risk from IoT devices that log in as admin; analysis of the newly published 'Zombie Zip' vulnerability (CVE-2026-0866); and Microsoft Patch Tuesday (March 2026) addressing 93 vulnerabilities (including 9 Chromium issues in Edge and 8 rated critical).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 40293370261650601e8e9556c654a722f1860183312d3d56b9c9c5f3b8843c7f
- Enrichment time
- 2026-03-16T07:23:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.