IPv4 Mapped IPv6 Addresses, (Tue, Mar 17th)

2026-03-17T19:23:46Z987d4f9c6a1372866630b7e8814510f665b724a2d3fa6d825311efb951d95e78
/proxy/ scansCVE-2026-0866EmailJSIPv4-mapped IPv6IoT default credentialsRFC 4038ReactRemcosRemcos RATSmartApeSGZombie Zipcredential theftobfuscationphishingproxy scanningthreat intelligencevulnerability disclosure

What happened

Collection of SANS ISC diary entries (Mar 11–17, 2026) covering several operational security observations and incidents: use of IPv4‑mapped IPv6 addresses (RFC 4038) to obfuscate scans and proxy abuse; increased /proxy/ URL scanning techniques; a campaign (SmartApeSG) delivering Remcos RAT via a ClickFix page; a React‑based phishing page exfiltrating credentials via EmailJS; IoT devices logging in as admin/default credentials; and disclosure/analysis of a new vulnerability, Zombie Zip (CVE-2026-0866).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
987d4f9c6a1372866630b7e8814510f665b724a2d3fa6d825311efb951d95e78
Enrichment time
2026-03-17T19:23:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.