Ruleset Update Summary - 2026/07/31 - v11247

Summary:

8 new OPEN, 24 new PRO (8 + 16)


Added rules:

Open:

  • 2020976 - ET HUNTING HTTP 300-Series Redirect to file URI attempt (hunting.rules)
  • 2071351 - ET WEB_SPECIFIC_APPS Flowise Authenticated Remote Code Execution (CVE-2026-46442) (web_specific_apps.rules)
  • 2071352 - ET WEB_SPECIFIC_APPS Adobe ColdFusion Path Traversal (CVE-2026-48313) (web_specific_apps.rules)
  • 2071353 - ET WEB_SPECIFIC_APPS ServiceNow AI Platform Unauthenticated JavaScript Sandbox Escape Remote Code Execution (CVE-2026-6875) (web_specific_apps.rules)
  • 2071354 - ET WEB_SPECIFIC_APPS Alibaba Sentinel Default Credentials (CNVD-2021-35876) (web_specific_apps.rules)
  • 2071355 - ET WEB_SPECIFIC_APPS IBM Langflow Auto-Login Bypass (CVE-2026-9198) (web_specific_apps.rules)
  • 2071356 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (piggybc .cyou) (malware.rules)
  • 2071357 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (piggybc .cyou) in TLS SNI (malware.rules)

Pro:

  • 2868097 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - PING Outbound (malware.rules)
  • 2868098 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PING Outbound (malware.rules)
  • 2868099 - ETPRO MALWARE TA584 Win32/XWorm CnC Command - Ping Inbound (malware.rules)
  • 2868100 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - RD- Inbound (malware.rules)
  • 2868101 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - sendPlugin Outbound (malware.rules)
  • 2868102 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - Informations Outbound (malware.rules)
  • 2868103 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - GetInformations Inbound (malware.rules)
  • 2868104 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PCShutdown Inbound (malware.rules)
  • 2868105 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - PING Outbound (malware.rules)
  • 2868106 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PING Outbound (malware.rules)
  • 2868107 - ETPRO MALWARE TA584 Win32/XWorm CnC Command - Ping Inbound (malware.rules)
  • 2868108 - ETPRO MALWARE TA584 Win32/XWorm V2 CnC Command - RD- Inbound (malware.rules)
  • 2868109 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - sendPlugin Outbound (malware.rules)
  • 2868110 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - Informations Outbound (malware.rules)
  • 2868111 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - GetInformations Inbound (malware.rules)
  • 2868112 - ETPRO MALWARE TA584 Win32/XWorm V3 CnC Command - PCShutdown Inbound (malware.rules)

Removed rules:

  • 2020916 - ET EXPLOIT Possible Redirect to SMB exploit attempt - 302 (exploit.rules)
  • 2020917 - ET EXPLOIT Possible Redirect to SMB exploit attempt - 301 (exploit.rules)
  • 2020976 - ET EXPLOIT Possible Redirect to SMB exploit attempt - 307 (exploit.rules)
  • 2020977 - ET EXPLOIT Possible Redirect to SMB exploit attempt - 303 (exploit.rules)