IPv4 Mapped IPv6 Addresses, (Tue, Mar 17th)

2026-03-17T13:23:45Zb04cbc9e2eb33567f7ebd4b3f3841dc0bee762eee3ca0c679815a451e7d942bf
/proxy/CVE-2026-0866ClickFixEmailJSIPv4-mapped IPv6IoTRATRFC4038ReactRemcosSmartApeSGZombie Zipcredential theftdefault adminhoneypotsphishingproxy scansvulnerability

What happened

SANS ISC diary entries from Mar 11–17, 2026 cover multiple active threats and observations: attackers are abusing IPv4-mapped IPv6 addresses (RFC 4038) in /proxy/ URL scans to obfuscate source addresses; a SmartApeSG campaign is distributing the Remcos RAT via a ClickFix page; a React-based phishing page was found that exfiltrates credentials using the legitimate EmailJS service; IoT devices logging in as admin are highlighted as a dangerous failure mode; and a new vulnerability (Zombie Zip, CVE-2026-0866) was published. These items indicate active credential theft, proxy-scanning abuse, and a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
b04cbc9e2eb33567f7ebd4b3f3841dc0bee762eee3ca0c679815a451e7d942bf
Enrichment time
2026-03-17T13:23:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.