Ruleset Update Summary - 2026/06/12 - v11213

Summary:

11 new OPEN, 12 new PRO (11 + 1)


Added rules:

Open:

  • 2069918 - ET EXPLOIT_KIT Clearfake Set-Cookie Inbound M1 (exploit_kit.rules)
  • 2069919 - ET EXPLOIT_KIT Clearfake Set-Cookie Inbound M2 (exploit_kit.rules)
  • 2069920 - ET WEB_SPECIFIC_APPS Ubiquiti Unifi OS Authentication Bypass (CVE-2026-34908) (web_specific_apps.rules)
  • 2069921 - ET WEB_SPECIFIC_APPS Ubiquiti Unifi OS Path Traversal (CVE-2026-34909) (web_specific_apps.rules)
  • 2069922 - ET WEB_SPECIFIC_APPS Ubiquiti Unifi OS Command Injection (CVE-2026-34910) (web_specific_apps.rules)
  • 2069923 - ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (bronzepavilion .top) (exploit_kit.rules)
  • 2069924 - ET EXPLOIT_KIT ZPHP Domain in TLS SNI (bronzepavilion .top) (exploit_kit.rules)
  • 2069925 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (jiminej .lol) (exploit_kit.rules)
  • 2069926 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (oliveiaa .icu) (exploit_kit.rules)
  • 2069927 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (jiminej .lol) (exploit_kit.rules)
  • 2069928 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (oliveiaa .icu) (exploit_kit.rules)

Pro:

  • 2809198 - ETPRO RETIRED SChannel Possible Heap Overflow ECDSAWithSHA384 CVE-2014-6321 (retired.rules)

Removed rules:

  • 2809198 - ETPRO EXPLOIT SChannel Possible Heap Overflow ECDSAWithSHA384 CVE-2014-6321 (exploit.rules)