Ruleset Update Summary - 2026/07/30 - v11246

Summary:

5 new OPEN, 6 new PRO (5 + 1)


Added rules:

Open:

  • 2022531 - ET RETIRED Possible 2015-7547 Malformed Server response (retired.rules)
  • 2071347 - ET EXPLOIT Check Point CPMI Protocol Authentication Bypass via Application Login (CVE-2026-16232) (exploit.rules)
  • 2071348 - ET INFO Check Point FWM/CPMI Unauthenticated Legacy Gui_Client Handshake (SIC DN Disclosure) (info.rules)
  • 2071349 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (glazeom .cyou) (malware.rules)
  • 2071350 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (glazeom .cyou) in TLS SNI (malware.rules)

Pro:

  • 2868096 - ETPRO MALWARE Malicious Win32/NetSupport Rat CnC Checkin (malware.rules)

Removed rules:

  • 2022531 - ET EXPLOIT Possible 2015-7547 Malformed Server response (exploit.rules)
  • 2071347 - ET WEB_SERVER Check Point CPMI Protocol Authentication Bypass via Application Login (CVE-2026-16232) (web_server.rules)