Ruleset Update Summary - 2026/08/04 - v11249

Summary:

17 new OPEN, 18 new PRO (17 + 1)


Added rules:

Open:

  • 2071368 - ET WEB_SPECIFIC_APPS Red Hat Keycloak Admin REST API PII Disclosure (CVE-2026-17059) (web_specific_apps.rules)
  • 2071369 - ET WEB_SPECIFIC_APPS Red Hat Keycloak Unauthenticated Server-side Request Forgery in OIDC Dynamic Client Registration (web_specific_apps.rules)
  • 2071370 - ET WEB_SPECIFIC_APPS Dockwatch compose.php composePath Parameter Command Injection Attempt (CVE-2026-58455) (web_specific_apps.rules)
  • 2071371 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (trenadne .cyou) (malware.rules)
  • 2071372 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (trenadne .cyou) in TLS SNI (malware.rules)
  • 2071373 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (griffihhs .click) (exploit_kit.rules)
  • 2071374 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (griffihhs .click) (exploit_kit.rules)
  • 2071375 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (img2 .lelispices .com) (malware.rules)
  • 2071376 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (js-dl .kaliesthenics .com) (malware.rules)
  • 2071377 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (js .galmabuna .com) (malware.rules)
  • 2071378 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (sc-api .abuarerestaurant .net) (malware.rules)
  • 2071379 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (img2 .lelispices .com) (malware.rules)
  • 2071380 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (js-dl .kaliesthenics .com) (malware.rules)
  • 2071381 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (js .galmabuna .com) (malware.rules)
  • 2071382 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (sc-api .abuarerestaurant .net) (malware.rules)
  • 2071383 - ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (namastheandhra .com) (exploit_kit.rules)
  • 2071384 - ET EXPLOIT_KIT ZPHP Domain in TLS SNI (namastheandhra .com) (exploit_kit.rules)

Pro:

  • 2868133 - ETPRO MALWARE Malicious Win32/NetSupport Rat CnC Checkin (malware.rules)