/proxy/ URL scans with IP addresses, (Mon, Mar 16th)
2026-03-16T19:23:52Z•56cdf3f0c3cf9dfc3b83f7dce110e1ea0baeea47189aef55c0b39fc80afb9467
/proxy/CVE-2026-0866ChromiumClickFixEmailJSIP-based scanningIoTMicrosoft EdgeMicrosoft Patch TuesdayRATReactRemcosSmartApeSGZombie Zipcredential theftdefault credentialshoneypotpatchesphishingproxy scanningsecurity advisory
What happened
Feed from SANS ISC (Mar 10–16, 2026) highlighting multiple active trends and advisories: increased proxy-scanning activity using /proxy/ URL patterns and IP-based requests observed in honeypots; a SmartApeSG campaign using a ClickFix page to distribute the Remcos RAT; a React-based credential‑phishing page that exfiltrates creds via the EmailJS service; disclosure and analysis of the “Zombie Zip” vulnerability (CVE-2026-0866); Microsoft March 2026 Patch Tuesday fixing 93 vulnerabilities (including 8 critical Chromium/Edge issues); and a guest diary warning about IoT devices logging in as admin
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 56cdf3f0c3cf9dfc3b83f7dce110e1ea0baeea47189aef55c0b39fc80afb9467
- Enrichment time
- 2026-03-16T19:23:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.