Summary:
5 new OPEN, 6 new PRO (5 + 1)
Added rules:
Open:
- 2022531 - ET RETIRED Possible 2015-7547 Malformed Server response (retired.rules)
- 2071347 - ET EXPLOIT Check Point CPMI Protocol Authentication Bypass via Application Login (CVE-2026-16232) (exploit.rules)
- 2071348 - ET INFO Check Point FWM/CPMI Unauthenticated Legacy Gui_Client Handshake (SIC DN Disclosure) (info.rules)
- 2071349 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (glazeom .cyou) (malware.rules)
- 2071350 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (glazeom .cyou) in TLS SNI (malware.rules)
Pro:
- 2868096 - ETPRO MALWARE Malicious Win32/NetSupport Rat CnC Checkin (malware.rules)
Removed rules:
- 2022531 - ET EXPLOIT Possible 2015-7547 Malformed Server response (exploit.rules)
- 2071347 - ET WEB_SERVER Check Point CPMI Protocol Authentication Bypass via Application Login (CVE-2026-16232) (web_server.rules)