ISC Stormcast For Thursday, March 12th, 2026 https://isc.sans.edu/podcastdetail/9846, (Thu, Mar 12th)

2026-03-13T01:23:49Z66c4c2c64e65dc540af35e7412693ce780b7e07af18093b98e008454a34e96a3
CVE-2026-0866advisorychromiumcritical-vulnerabilitiesdefault-credentialsdisclosureechencrypted-client-helloiotmicrosoft-edgemicrosoft-patch-tuesdaypatchingsoftware-releasetlsvulnerabilityyara-x

What happened

SANS ISC diary highlights from Mar 6–12, 2026: analysis of a newly published vulnerability “Zombie Zip” (CVE-2026-0866); Microsoft Patch Tuesday covering 93 CVEs (including 9 Chromium vulnerabilities affecting Edge and 8 rated critical; two were previously disclosed but not yet exploited); a guest diary warning about IoT devices that log in as admin (default/weak credentials); publication discussion of Encrypted Client Hello (ECH) related RFCs; and a YARA-X 1.14.0 release with improvements and bug fixes. Several daily Stormcast podcast entries were also published.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
66c4c2c64e65dc540af35e7412693ce780b7e07af18093b98e008454a34e96a3
Enrichment time
2026-03-13T01:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.