/proxy/ URL scans with IP addresses, (Mon, Mar 16th)

2026-03-16T19:23:52Z56cdf3f0c3cf9dfc3b83f7dce110e1ea0baeea47189aef55c0b39fc80afb9467
/proxy/CVE-2026-0866ChromiumClickFixEmailJSIP-based scanningIoTMicrosoft EdgeMicrosoft Patch TuesdayRATReactRemcosSmartApeSGZombie Zipcredential theftdefault credentialshoneypotpatchesphishingproxy scanningsecurity advisory

What happened

Feed from SANS ISC (Mar 10–16, 2026) highlighting multiple active trends and advisories: increased proxy-scanning activity using /proxy/ URL patterns and IP-based requests observed in honeypots; a SmartApeSG campaign using a ClickFix page to distribute the Remcos RAT; a React-based credential‑phishing page that exfiltrates creds via the EmailJS service; disclosure and analysis of the “Zombie Zip” vulnerability (CVE-2026-0866); Microsoft March 2026 Patch Tuesday fixing 93 vulnerabilities (including 8 critical Chromium/Edge issues); and a guest diary warning about IoT devices logging in as admin

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
56cdf3f0c3cf9dfc3b83f7dce110e1ea0baeea47189aef55c0b39fc80afb9467
Enrichment time
2026-03-16T19:23:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.