Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Thursday, August 12, 2021

Snort rule update for Aug. 12, 2021

Cisco Talos released the latest rule update for SNORTⓇ this morning.

Thursday's rule update includes protection against several malware families. One rule prevents the Bandidos malware, an upgraded version of Bandook, from making an outbound connection. Security researchers recently found Bandidos being used in spying campaigns against targets in Latin America.

Here's a full breakdown of this release:

Shared object rulesModified shared object rulesNew rulesModified rules
1 050

Thursday, April 2, 2020

Snort rule update for April 2, 2020 — Microsoft Patch Tuesday

Apologies for the radio silence on the blog over the past week weeks. The Snort communications team was settling into a new schedule. But that doesn't mean the rule updates haven't been rolling in.

We just released a new SNORTⓇ rule update this morning with 20 new rules, two modified rules, two modified shared object rules and 12 new shared object rules.

Today's release provides protection against the Agent Tesla malware, which recently saw a spike connected to COVID-19-related spam.

Tuesday, November 19, 2019

Snort rule update for Nov. 19, 2019

Cisco Talos just released the latest SNORT® rule update for all users. Talos urges all users to implement these rules as soon as possible to keep their networks and machines protected.

Today's release contains 26 new rules, one modified rule and four shared object rules.

This set of rules protects against a new variant of the Dridex malware and a trojan that's posing as a fake updater.

Thursday, October 24, 2019

Snort rule update for Oct. 24, 2019

Cisco Talos just released the latest SNORT® rule update for all users. Talos urges all users to implement these rules as soon as possible to keep their networks and machines protected.

Today's release contains 42 new rules, 13 new shared object rules and five modified rules.

Thursday's release provides updated protections against the Emotet botnet. While Emotet has been around for years, the attackers behind it are still updating it and releasing new variants on victims. There is also coverage for new malware variants used by the OceanLotus APT.

Tuesday, August 20, 2019

Snort rule update for Aug. 20, 2019

We apologize for the lack of update blog posts over the past two weeks, but even Snortie needs a summer vacation!

Our latest rule update just dropped this morning, though, and we've got the breakdown for you.

This release contains 65 new rules, three new shared object rules, 20 modified rules and two modified shared object rules.

Thursday's release includes additional coverage for several of the vulnerabilities Microsoft disclosed as part of its monthly security update last week, as well protection against several spyware tools.

Tuesday, June 18, 2019

Snort rule update for June 18, 2019

Just released:
Snort Subscriber Rule Set Update for June 18, 2019

Cisco Talos released the latest SNORTⓇ rule set today. This release includes 12 new rules and 10 modified, none of which are shared object rules.

This release provides protection against the new HiddenWasp malware, which has been spotted in the wild targeting Linux systems. This attack shares similarities with other, previous Linux malware. Researchers believe some of the code may have even copy and pasted from other actors.

There were no changes made to the snort.conf in this release.

Tuesday, March 5, 2019

Snort rule update for March 5, 2019

Just released:
Snort Subscriber Rule Set Update for March 5, 2019

Cisco Talos just released the newest SNORT® rule set. This release includes eight new and modified rules, none of which are shared object rules.

This release provides coverage for two malware families: Crytekk, a ransomware that infects users via a malicious, phony PayPal page, and Arescrypt, another ransomware.