Cisco Talos released the newest SNORTⓇ rule update Tuesday afternoon.
This release includes several new rules to protect against attacks from Russian Foreign Intelligence Service (SVR) cyber actors (aka APT29 and CozyBear). A joint release from U.S. intelligence organizations outlined the vulnerabilities this group uses to target many of its victims.
Here's a breakdown of everything in today's release:
Shared object rules | Modified shared object rules | New rules | Modified rules |
---|---|---|---|
0 | 0 | 15 | 4 |
snort.conf
in this release.Talos' rule release:
Talos has added and modified multiple rules in the deleted, indicator-compromise, malware-other, protocol-voip and server-webapp rule sets to provide coverage for emerging threats from these technologies.