Summary:
11 new OPEN, 15 new PRO (11 + 4)
Added rules:
Open:
- 2071416 - ET PHISHING TA2730 Javascript Request 2026-08-06 (phishing.rules)
- 2071417 - ET PHISHING TA2730 Domain in DNS Lookup (0tokens .xyz) (phishing.rules)
- 2071418 - ET PHISHING TA2730 Domain in TLS SNI (0tokens .xyz) (phishing.rules)
- 2071419 - ET PHISHING Generic AiTM Fingerprint Exfil (phishing.rules)
- 2071420 - ET WEB_SERVER Cisco Unified Communications Manager 15.x Unauthenticated Remote Code Execution (web_server.rules)
- 2071421 - ET WEB_SPECIFIC_APPS Microsoft SharePoint Authentication Bypass and Privilege Escalation (CVE-2023-29357) (web_specific_apps.rules)
- 2071422 - ET WEB_SPECIFIC_APPS Microsoft SharePoint Authenticated Remote Code Execution via Insecure Deserialization (CVE-2026-45659) (web_specific_apps.rules)
- 2071423 - ET INFO DYNAMIC_DNS Query to a *.longmusic .com domain (info.rules)
- 2071424 - ET INFO DYNAMIC_DNS HTTP Request to a *.longmusic .com domain (info.rules)
- 2071425 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (weaponswh .run) (malware.rules)
- 2071426 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (weaponswh .run) in TLS SNI (malware.rules)
Pro:
- 2868157 - ETPRO WEB_SPECIFIC_APPS Microsoft SharePoint Remote Code Execution Vulnerability (CVE-2025-49701) (web_specific_apps.rules)
- 2868158 - ETPRO EXPLOIT Microsoft Remote Desktop Services Remote Code Execution (CVE-2025-27480) (exploit.rules)
- 2868159 - ETPRO EXPLOIT Microsoft Windows Shell Security Feature Bypass (CVE-2026-32225) (exploit.rules)
- 2868160 - ETPRO WEB_SPECIFIC_APPS Microsoft Sharepoint Toolpane.aspx Authentication Bypass (CVE-2026-32201) (web_specific_apps.rules)
Disabled and modified rules:
- 2859373 - ETPRO HUNTING HTTP POST Request with Attempted Directory Traversal Inbound (hunting.rules)