/proxy/ URL scans with IP addresses, (Mon, Mar 16th)
2026-03-17T01:23:49Z•483e10adee6fecb672e079904d81218036d92b1b59f646594c18395d25e308ed
CVE-2026-0866ChromiumEdgeEmailJSIoTMicrosoftRATReactRemcoscredential-exfiltrationmalwareopen-proxypatch-tuesdayphishingproxy-scanvulnerabilitieszombie-zip
What happened
SANS ISC diary feed (Mar 11–16, 2026) noting multiple active threats and advisories: widespread proxy-scanning activity using "/proxy/" and IP-based URLs; a SmartApeSG campaign delivering the Remcos RAT via ClickFix pages; a React-based phishing page that exfiltrates credentials via the EmailJS service; disclosure of the "Zombie Zip" vulnerability (CVE-2026-0866); and Microsoft Patch Tuesday (Mar 2026) addressing 93 vulnerabilities including 8 critical Chromium/Edge flaws. Also includes IoT admin-login security observations.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 483e10adee6fecb672e079904d81218036d92b1b59f646594c18395d25e308ed
- Enrichment time
- 2026-03-17T01:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.