Summary:
17 new OPEN, 18 new PRO (17 + 1)
Added rules:
Open:
- 2071368 - ET WEB_SPECIFIC_APPS Red Hat Keycloak Admin REST API PII Disclosure (CVE-2026-17059) (web_specific_apps.rules)
- 2071369 - ET WEB_SPECIFIC_APPS Red Hat Keycloak Unauthenticated Server-side Request Forgery in OIDC Dynamic Client Registration (web_specific_apps.rules)
- 2071370 - ET WEB_SPECIFIC_APPS Dockwatch compose.php composePath Parameter Command Injection Attempt (CVE-2026-58455) (web_specific_apps.rules)
- 2071371 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (trenadne .cyou) (malware.rules)
- 2071372 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (trenadne .cyou) in TLS SNI (malware.rules)
- 2071373 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (griffihhs .click) (exploit_kit.rules)
- 2071374 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (griffihhs .click) (exploit_kit.rules)
- 2071375 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (img2 .lelispices .com) (malware.rules)
- 2071376 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (js-dl .kaliesthenics .com) (malware.rules)
- 2071377 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (js .galmabuna .com) (malware.rules)
- 2071378 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (sc-api .abuarerestaurant .net) (malware.rules)
- 2071379 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (img2 .lelispices .com) (malware.rules)
- 2071380 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (js-dl .kaliesthenics .com) (malware.rules)
- 2071381 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (js .galmabuna .com) (malware.rules)
- 2071382 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (sc-api .abuarerestaurant .net) (malware.rules)
- 2071383 - ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (namastheandhra .com) (exploit_kit.rules)
- 2071384 - ET EXPLOIT_KIT ZPHP Domain in TLS SNI (namastheandhra .com) (exploit_kit.rules)
Pro:
- 2868133 - ETPRO MALWARE Malicious Win32/NetSupport Rat CnC Checkin (malware.rules)