Showing posts with label rules. Show all posts
Showing posts with label rules. Show all posts

Friday, April 1, 2022

Weekly Snort rule update for March 25 - April 1

 Cisco Talos released two new rule sets for SNORTⓇ this week, which you can view here and here.

There are multiple rules to protect against the exploitation of the highly publicized Spring4Shell vulnerabilities that could lead to remote code execution. Spring is a popular framework used to develop Java applications. Snort SIDs 30790 - 30793, 59388 and 59416 can detect this activity.

For more on these vulnerabilities, read the Talos blog here

All users can subscribe to Talos' newest rule detection functionality for as low as $29 a year with a personal account. Be sure and see our business pricing as well here. The Snort 3 release is also here after years of development and improvements, which you can upgrade to here.

Snort's rule blog posts are switching to a weekly recap format, rather than releasing every day a new rule update is released. If you have any feedback on this blog format, please reach out to us on Twitter @Snort

Friday, March 25, 2022

Weekly Snort rule update for March 21 - 25

Cisco Talos released two new rule sets for SNORTⓇ this week, which you can view here and here.

All users can subscribe to Talos' newest rule detection functionality for as low as $29 a year with a personal account. Be sure and see our business pricing as well here. The Snort 3 release is also here after years of development and improvements, which you can upgrade to here.

Snort's rule blog posts are switching to a weekly recap format, rather than releasing every day a new rule update is released. If you have any feedback on this blog format, please reach out to us on Twitter @Snort

Thursday, March 17, 2022

Weekly Snort rule update for March 14 - 18

Cisco Talos released two new rule sets for SNORTⓇ this week, which you can view here and here.

The rules from this week cover a variety of malware families, including the CaddyWiper threat that's been targeting users in Ukraine. The wiper is relatively small in size and dynamically resolves most of the APIs it uses. Cisco Talos' analysis didn't show any indications of persistency, self-propagation or exploitation code.

We also released new protections for the Dirty Pipe exploit recently discovered in the Linux operating system. This vulnerability could allow an attacker to completely root devices, including some Android devices, as researchers showed with the Google Pixel 6. QNAP also warned users that its network-attached storage devices are also at risk

All users can subscribe to Talos' newest rule detection functionality for as low as $29 a year with a personal account. Be sure and see our business pricing as well here. The Snort 3 release is also here after years of development and improvements, which you can upgrade to here.

Snort's rule blog posts are switching to a weekly recap format, rather than releasing every day a new rule update is released. If you have any feedback on this blog format, please reach out to us on Twitter @Snort

Thursday, February 17, 2022

Weekly Snort rule update for Feb. 14 - 18

Cisco Talos released two new rule sets for SNORTⓇ this week, which you can view here and here.

Our two releases include several new protections against a variety of malicious webshells. There is also an additional rule that protects against the string of vulnerabilities Cisco recently disclosed in its RV series of routers aimed at small businesses.

The CVEs have a combined severity score of a maximum 10 out of 10. If successful, an adversary could execute arbitrary code on the targeted device, cause a denial of service or bypass authentication protections.

All users can subscribe to Talos' newest rule detection functionality for as low as $29 a year with a personal account. Be sure and see our business pricing as well here. The Snort 3 release is also here after years of development and improvements, which you can upgrade to here.

Snort's rule blog posts are switching to a weekly recap format, rather than releasing every day a new rule update is released. If you have any feedback on this blog format, please reach out to us on Twitter @Snort

Thursday, January 13, 2022

Snort rule update for Jan. 13, 2022

The newest SNORTⓇ rule update from Cisco Talos is now available.

Thursday morning's rule release includes new protections against the exploitation of a Log4shell-like vulnerability recently discovered in the popular H2 Java SQL database. Although the paths to exploiting this vulnerability are similar to the recent Log4j issue, the scope of execution is less broad.

Here's a full breakdown of the rest of today's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
022

Tuesday, December 7, 2021

Snort rule update for Dec. 7, 2021

The newest SNORTⓇ rule update from Cisco Talos is now available.

Tuesday's rule update includes multiple rules to protect against vulnerabilities that are being exploited in the wild. One such vulnerability is CVE-2021-44515 in the Zoho patch management software. If exploited, it could allow attackers to bypass authentication and execute arbitrary code. Snort rule 58696 detects if attackers try to upload a file as part of exploiting this vulnerability.

Here's a full breakdown of today's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
017353

Tuesday, November 30, 2021

Snort rule update for Nov. 30, 2021

The newest SNORTⓇ rule update from Cisco Talos is now available.

Tuesday morning's release includes a new rule to protect against the high-profile DarkSide ransomware. The group, also known as DarkMatter, targeted several high-profile companies across the globe this year, including two companies in the U.S. food and agriculture sector. 

This new rule detects when the ransomware attempts to make an outbound connection.

Here's a full breakdown of the rest of today's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
10 0195

Tuesday, November 16, 2021

Snort rule update for Nov. 12, 2021

The newest SNORTⓇ rule update from Cisco Talos is now available.

Tuesday morning's release includes a new rule to protect against the SQUIRRELWAFFLE attack we detailed in late October. SQUIRRELWAFFLE provides threat actors with an initial foothold onto systems and their network environments that can then be used to facilitate further compromise or additional malware infections depending on how adversaries choose to attempt to monetize their access. 

Here's a full breakdown of the rest of today's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
01239

Thursday, November 4, 2021

Snort rule update for Nov. 4, 2021

The newest SNORTⓇ rule update from Cisco Talos is now available.

We apologize that these rule blog posts have not been as frequent recently — our comms team was on a bit of a fall break. But, we're excited to let everyone know about today's rule release. 

We have multiple rules available to protect against the exploitation of multiple vulnerabilities Cisco disclosed in some of their routers that could allow unauthenticated attackers to log in using hard-coded credentials or default SSH keys.

Here's a full breakdown of the rest of Tuesday's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
12 0141

Tuesday, October 19, 2021

Snort rule update for Oct. 19, 2021

The newest SNORTⓇ rule update is available this morning from Cisco Talos.

Our rule release includes detection content for several different malware families, including the AndroSpy backdoor and Quasar RAT, a .NET-based malware used by a variety of attackers.

Here's a full breakdown of the rest of Tuesday's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
0230

Thursday, October 14, 2021

Snort rule update for Oct. 14, 2021

Cisco Talos released the newest SNORTⓇ rule update today.  This release includes protections against several vulnerabilities including the Trend Micro Encryption Email Gateway and the phpMyAdmin tool.

Here's a full breakdown of the rest of Thursday's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
2250

Tuesday, October 12, 2021

Snort rule update for Oct. 12, 2021 — Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for many of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this month, head to the Talos blog.

Here's a breakdown of this afternoon's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
10378

Tuesday, October 5, 2021

Snort rule update for Oct. 5, 2021

Cisco Talos shared the newest rule update for SNORTⓇ this afternoon. 

Tuesday's release includes new protection against the BlackMatter ransomware attack. Japanese technology company Olympus recently suffered an attack from this group, suffering outages across its European, Middle East and Africa computer networks. BlackMatter also recently infected a large grain co-op in Iowa, with the group demanding a $5.9 million ransom payment. 

Here's a full breakdown of Thursday's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
0135

Thursday, September 23, 2021

Snort rule update for Sept. 23, 2021

A new SNORTⓇ rule update is out this morning.

There are two rules in this package that protect against a zero-day vulnerability in the macOS Finder.  An attacker could exploit this vulnerability by tricking a user into opening a specially crafted email attachment that executes arbitrary commands. Apple released an update for this issue, but it is still exploitable, according to security researchers.

Here's a full breakdown of Thursday's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
1201

Tuesday, September 21, 2021

Snort rule update for Sept. 21, 2021

Cisco Talos released the latest rule update for SNORTⓇ Tuesday morning.

We neglected to post about this Thursday, but there was also another rule update that Talos released late last week.

Here's a full breakdown of today's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
1141

Thursday, September 9, 2021

Snort rule update for Sept. 9, 2021 — New coverage for Microsoft MSHTML zero-day

The latest SNORT rule update is available this morning, including new coverage for the recently disclosed zero-day vulnerability in Microsoft MSHTML

Users are encouraged to deploy SIDs 58120 – 58129 to detect and prevent the exploitation of CVE-2021-40444, which Microsoft disclosed earlier this week. If an adversary were to successfully exploit this vulnerability, they could remotely execute code on the victim machine or gain complete control. The Microsoft advisory also stated that proof-of-concept code for this vulnerability is available in the wild. 

Here's a full breakdown of this rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
0192

Thursday, August 5, 2021

Snort rule update for Aug. 5, 2021

The latest SNORTⓇ ruleset is available this morning from Cisco Talos.

Thursday's rule update includes protection against two pre-authorization vulnerabilities in the Cisco RV series of routers. The two vulnerabilities Cisco disclosed this week could allow an attacker to trigger a denial-of-service condition or execute commands and arbitrary code on vulnerable devices.

Here's a full breakdown of this release:

Shared object rulesModified shared object rulesNew rulesModified rules
100

Tuesday, July 20, 2021

Snort rule update for July 20, 2021

Cisco Talos released the newest SNORTⓇ ruleset this morning.

Tuesday's rule update provides multiple forms of protection against the exploitation of high-severity vulnerabilities in Cisco's Business Process Automation (BPA) application and Web Security Appliance (WSA). An adversary could take advantage of these issues to access sensitive data or take over a targeted system.

Here's a full breakdown of today's release:

Shared object rulesModified shared object rulesNew rulesModified rules
2172

Tuesday, July 13, 2021

Snort rule update for July 13, 2021 — Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for many of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this month, head to the Talos blog.

Here's a breakdown of this afternoon's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
20195

Tuesday, July 6, 2021

Snort rule update for July 6, 2021 — Coverage for Kaseya supply chain attack

Cisco Talos released a new SNORTⓇ ruleset today, including a rule to protect against exploitation of the widespread Kaseya vulnerability. For more on this attack, head to the Talos blog.

Here's a full breakdown of Tuesday's release:

Shared object rulesModified shared object rulesNew rulesModified rules
025