A React-based phishing page with credential exfiltration via EmailJS, (Fri, Mar 13th)
2026-03-13T13:23:51Z•b9d7c0c11484dfc3297873d1d3ce8d8da5596e3d67a47c7b50910782383561d9
CVE-2026-0866EmailJSReactchromiumcredential-exfiltrationedgeiotmicrosoft-patch-tuesdaypatchingphishingvulnerability-disclosureweb-phishingzombie-zip
What happened
Multiple SANS ISC diary entries: a React-built phishing page was observed that dynamically constructs the credential-collection UI and leverages the legitimate EmailJS service to exfiltrate stolen credentials, making detection and takedown more challenging. A new vulnerability named “Zombie Zip” was published as CVE-2026-0866. Microsoft released its March 2026 Patch Tuesday addressing 93 vulnerabilities (including 9 Chromium issues affecting Edge, 8 rated critical); two were previously disclosed but not yet exploited. Additional posts cover IoT admin-login issues and new RFCs for Encrypted CH,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- b9d7c0c11484dfc3297873d1d3ce8d8da5596e3d67a47c7b50910782383561d9
- Enrichment time
- 2026-03-13T13:23:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.