Cisco Talos released another rule update for SNORTⓇ last night that adds additional protection against the exploitation of zero-day vulnerabilities in Microsoft Exchange Server. This follows the eight rules we released earlier this week.
Microsoft disclosed these vulnerabilities earlier in the week, attributing the attacks to a group known as HAFNIUM. For more on this threat, head to the Talos blog.
Here's a breakdown of Wednesday's rule release:
Shared object rules | Modified shared object rules | New rules | Modified rules |
---|---|---|---|
2 | 2 | 5 | 4 |
snort.conf
in this release.Talos' rule release:
Talos has added and modified multiple rules in the file-image, file-office, malware-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.