Showing posts with label Emotet. Show all posts
Showing posts with label Emotet. Show all posts

Thursday, October 24, 2019

Snort rule update for Oct. 24, 2019

Cisco Talos just released the latest SNORT® rule update for all users. Talos urges all users to implement these rules as soon as possible to keep their networks and machines protected.

Today's release contains 42 new rules, 13 new shared object rules and five modified rules.

Thursday's release provides updated protections against the Emotet botnet. While Emotet has been around for years, the attackers behind it are still updating it and releasing new variants on victims. There is also coverage for new malware variants used by the OceanLotus APT.

Tuesday, April 23, 2019

Snort rule update for April 23, 2019

Just released:
Snort Subscriber Rule Set Update for April 23, 2019

Cisco Talos just released the newest SNORT® rule set. This release includes 11 new rules, four of which are shared object rules. There are also 15 modified rules, none of which are shared object rules.

This release provides new coverage for the infamous Emotet malware traditionally spread via spam. There are also two new rules for Microsoft Windows IOleCvt vulnerability disclosed earlier this month as part of Microsoft's monthly security update.

There were no changes made to the snort.conf in this release.