/proxy/ URL scans with IP addresses, (Mon, Mar 16th)

2026-03-17T01:23:49Z483e10adee6fecb672e079904d81218036d92b1b59f646594c18395d25e308ed
CVE-2026-0866ChromiumEdgeEmailJSIoTMicrosoftRATReactRemcoscredential-exfiltrationmalwareopen-proxypatch-tuesdayphishingproxy-scanvulnerabilitieszombie-zip

What happened

SANS ISC diary feed (Mar 11–16, 2026) noting multiple active threats and advisories: widespread proxy-scanning activity using "/proxy/" and IP-based URLs; a SmartApeSG campaign delivering the Remcos RAT via ClickFix pages; a React-based phishing page that exfiltrates credentials via the EmailJS service; disclosure of the "Zombie Zip" vulnerability (CVE-2026-0866); and Microsoft Patch Tuesday (Mar 2026) addressing 93 vulnerabilities including 8 critical Chromium/Edge flaws. Also includes IoT admin-login security observations.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
483e10adee6fecb672e079904d81218036d92b1b59f646594c18395d25e308ed
Enrichment time
2026-03-17T01:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · /proxy/ URL scans with IP addresses, (Mon, Mar 16th) · Baitaphish