A new SNORTⓇ rule release is available this morning, courtesy of Cisco Talos. Here's an overview at this rule set:
|Shared object rules||Modified shared object rules||New rules||Modified rules|
Thursday's release provides a few new rules protecting against the Emotet botnet. Everyone already knows about Emotet, but it continues to grow, most recently targeting state and other local government agencies, according to a recent advisory from the U.S. Cybersecurity and Infrastructure Security Agency.
Talos has added and modified multiple rules in the malware-cnc and server-other rule sets to provide coverage for emerging threats from these technologies.