SmartApeSG campaign uses ClickFix page to push Remcos RAT, (Sat, Mar 14th)
2026-03-15T13:23:49Z•ac2264cb9ceb704b3449b0862649f73d12329f0f08b24d12cf9555aa0656b168
chromiumclickfixcredential-theftcritical-vulnerabilitiescve-2026-0866default-credentialsemailjsencrypted-client-helloiotmicrosoft-edgemicrosoft-patch-tuesdayphishingpodcastratreactremcosrfcsans-iscsmartapesgtlszombie-zip
What happened
SANS ISC diary roundup (Mar 9–14, 2026) covering multiple security items: a SmartApeSG campaign using a ClickFix page to deploy the Remcos RAT; a React-based phishing page that exfiltrates credentials via the EmailJS service; publication and analysis of CVE-2026-0866 (“Zombie Zip”); Microsoft Patch Tuesday (Mar 2026) addressing 93 vulnerabilities—including 8 rated critical and multiple Chromium/Edge issues; commentary on IoT devices logging in as admin (default credentials risk); discussion of Encrypted Client Hello-related RFCs; plus links to regular ISC Stormcast podcasts.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- ac2264cb9ceb704b3449b0862649f73d12329f0f08b24d12cf9555aa0656b168
- Enrichment time
- 2026-03-15T13:23:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.