IPv4 Mapped IPv6 Addresses, (Tue, Mar 17th)
2026-03-17T19:23:46Z•987d4f9c6a1372866630b7e8814510f665b724a2d3fa6d825311efb951d95e78
/proxy/ scansCVE-2026-0866EmailJSIPv4-mapped IPv6IoT default credentialsRFC 4038ReactRemcosRemcos RATSmartApeSGZombie Zipcredential theftobfuscationphishingproxy scanningthreat intelligencevulnerability disclosure
What happened
Collection of SANS ISC diary entries (Mar 11–17, 2026) covering several operational security observations and incidents: use of IPv4‑mapped IPv6 addresses (RFC 4038) to obfuscate scans and proxy abuse; increased /proxy/ URL scanning techniques; a campaign (SmartApeSG) delivering Remcos RAT via a ClickFix page; a React‑based phishing page exfiltrating credentials via EmailJS; IoT devices logging in as admin/default credentials; and disclosure/analysis of a new vulnerability, Zombie Zip (CVE-2026-0866).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 987d4f9c6a1372866630b7e8814510f665b724a2d3fa6d825311efb951d95e78
- Enrichment time
- 2026-03-17T19:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.