Showing posts with label snort rules. Show all posts
Showing posts with label snort rules. Show all posts

Wednesday, January 12, 2022

Snort rule update for Jan. 11, 2022 — Microsoft Patch Tuesday

Cisco Talos released a new SNORT® ruleset Tuesday evening, providing coverage for many of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this month, view all of them on Microsoft's security update page. You can also read our breakdown of the most notable vulnerabilities on the Talos blog.

Here's a breakdown of Tuesday's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
00229

Tuesday, November 16, 2021

Snort rule update for Nov. 12, 2021

The newest SNORTⓇ rule update from Cisco Talos is now available.

Tuesday morning's release includes a new rule to protect against the SQUIRRELWAFFLE attack we detailed in late October. SQUIRRELWAFFLE provides threat actors with an initial foothold onto systems and their network environments that can then be used to facilitate further compromise or additional malware infections depending on how adversaries choose to attempt to monetize their access. 

Here's a full breakdown of the rest of today's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
01239

Thursday, November 4, 2021

Snort rule update for Nov. 4, 2021

The newest SNORTⓇ rule update from Cisco Talos is now available.

We apologize that these rule blog posts have not been as frequent recently — our comms team was on a bit of a fall break. But, we're excited to let everyone know about today's rule release. 

We have multiple rules available to protect against the exploitation of multiple vulnerabilities Cisco disclosed in some of their routers that could allow unauthenticated attackers to log in using hard-coded credentials or default SSH keys.

Here's a full breakdown of the rest of Tuesday's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
12 0141

Thursday, October 7, 2021

Snort rule update for Oct. 7, 2021

The newest SNORTⓇ rule update is available now. 

Cisco Talos' latest ruleset includes SID 58276 (SID 300053 for Snort 3) to protect against the exploitation of a zero-day vulnerability in the Apache HTTP Server Project. An attacker could exploit CVE-2021-41773 to execute remote code on the targeted machine. As of earlier this week, this exploit has already been used in the wild.

Here's a full breakdown of the rest of Thursday's rule update:

Shared object rulesModified shared object rulesNew rulesModified rules
0222

Tuesday, August 31, 2021

Snort rule update for Aug. 31, 2021

Cisco Talos released the latest SNORTⓇ rule update Tuesday afternoon. 

Today's release includes new rules to protect against vulnerabilities in Apache Flink and the Kentico content management system, among other software.

Here's a full breakdown of this release:

Shared object rulesModified shared object rulesNew rulesModified rules
0104

Thursday, August 26, 2021

Snort rule update for Aug. 26, 2021

The newest SNORTⓇ rule update is out now from Cisco Talos.

Thursday's rule release contains new protections against some widely discussed vulnerabilities in Realtek SDKs that affect thousands of internet-of-things devices. The vulnerabilities exist in products from more than 65 manufacturers, including IP cameras, childrens' toys and travel routers.

Here's a full breakdown of this release:

Shared object rulesModified shared object rulesNew rulesModified rules
0143

Tuesday, August 24, 2021

Snort rule update for Aug. 24, 2021

Cisco Talos released the latest rule update for SNORTⓇ this morning.

Our latest rule set includes two new rules to protect against the LockBit ransomware. Researchers are tracking the 2.0 version of this malware spreading rapidly across the threat landscape, recently hitting multiple high-profile targets.

Here's a full breakdown of this release:

Shared object rulesModified shared object rulesNew rulesModified rules
10 0140

Thursday, August 12, 2021

Snort rule update for Aug. 12, 2021

Cisco Talos released the latest rule update for SNORTⓇ this morning.

Thursday's rule update includes protection against several malware families. One rule prevents the Bandidos malware, an upgraded version of Bandook, from making an outbound connection. Security researchers recently found Bandidos being used in spying campaigns against targets in Latin America.

Here's a full breakdown of this release:

Shared object rulesModified shared object rulesNew rulesModified rules
050

Tuesday, August 10, 2021

Snort rule update for Aug. 10, 2021 — Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for many of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this month, head to the Talos blog.

Here's a breakdown of this afternoon's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
20180

Thursday, May 13, 2021

Snort rule update for May 13, 2021

The newest SNORTⓇ rule update is out now. Cisco Talos released this ruleset providing additional protection against the CrimsonRAT malware.

The Transparent Tribe APT, as highlighted by Talos researchers, recently added CrimsonRAT to their arsenal as they began targeting more government contractors. 

Here's a breakdown of Thursday's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
0   01912

Tuesday, May 11, 2021

Snort rule update for May 11, 2021 — Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for many of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this month, head to the Talos blog.

Here's a breakdown of this afternoon's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
241016

Tuesday, May 4, 2021

Snort rule update for May 4, 2021

Cisco Talos released the newest rule release for SNORTⓇ Tuesday.

This release includes multiple rules to protect against vulnerabilities in the Micro Focus Operations Bridge and the KLog Server. 

Here's a breakdown of Tuesday's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
1022029

Thursday, April 29, 2021

Snort rule update for April 29, 2021

Cisco Talos just released the latest SNORTⓇ rule update.

Thursday's release includes protection against the exploitation of a recently disclosed vulnerability in Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software. An adversary could exploit this vulnerability to cause a denial-of-service condition on a client's VPN connection if they're using an affected version of the Cisco Secure Client. 

Here's a breakdown of this rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
3063

Thursday, March 25, 2021

Snort rule update for March 25, 2021

Cisco Talos released the newest rule update for SNORTⓇ this morning.

Thursday's release includes another new rule to protect against attacks from the Hafnium threat group that's been recently spotted exploiting zero-day vulnerabilities in Microsoft Exchange Server. 

There are also multiple rules to protect against the exploitation of several vulnerabilities Cisco recently disclosed in its IOS XE software. Cisco disclosed 15 vulnerabilities earlier this week, all of which are considered to be high-severity.

Here's a breakdown of today's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
16342

Thursday, March 18, 2021

Snort rule update for March 18, 2021 — Additional rules to protect against Hafnium attacks

The latest rule update for SNORTⓇ released early this morning via Cisco Talos.

This latest release provides several new rules to protect against attacks from the Hafnium state-sponsored actor. Microsoft first discovered this group a few weeks ago when it disclosed several zero-day vulnerabilities in the Exchange Server software. Hafnium reportedly exploited these vulnerabilities to steal emails, among other malicious actions.

These new rules prevent a web shell upload attempt commonly seen with Hafnium.

Here's a breakdown of today's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
111122

Tuesday, March 16, 2021

Snort rule update for March 16, 2021

The newest SNORTⓇ rule release arrived this morning, courtesy of Cisco Talos.

Tuesday's release includes a new rule protecting against the exploitation of the critical vulnerabilities in F5 BIG-IP and BIG-IQ. An adversary could exploit these vulnerabilities, which F5 disclosed last week, to take complete control of affected systems to execute malicious code, disable services and create or delete files, among other malicious actions. 

The new Snort rule detects when attackers try to inject arbitrary commands via the iControl REST interface.

Here's a breakdown of today's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
8011

Thursday, March 11, 2021

Snort rule update for March 11, 2021

Cisco Talos released the newest rule update for SNORTⓇ Thursday afternoon.

This latest release includes multiple rules to protect against the DEWMODE malware. Attackers exploit vulnerabilities in Accellion’s legacy File Transfer Appliance (FTA) to install this web shell. This malware family was first discovered in late February.

Here's a breakdown of the rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
101211

Thursday, January 7, 2021

Snort rule update for Jan. 7, 2021

Cisco Talos released the latest SNORTⓇ rule update Thursday morning.

This release includes four rules to protect against the recently discovered TroubleGrabber malware. This credential stealer commonly spreads through Discord servers with malicious URLs. 

Here's a breakdown of this afternoon's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
00422

Thursday, December 17, 2020

Snort rule update for Dec. 17, 2020

The latest SNORTⓇ rule update is available now, courtesy of Cisco Talos.

Thursday's release contains numerous rules to protect against various malware families. Among the new rules is one to detect the Egregor ransomware, which is recently experiencing a surge and has even infected retail chain K-Mart's network.

If you haven't already, please check out all of Talos' coverage around the SolarWinds incident. We have new rules protecting against the exploitation of the backdoor in question. And we also have previous detection for the FireEye products affected by this attack.

Here's a breakdown of this morning's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
90524

Thursday, December 3, 2020

Snort rule update for Dec. 3, 2020

The latest SNORTⓇ rule release is out this morning, courtesy of Cisco Talos.

Today's rule update includes several new rules protecting against some of the most prevalent malware families in the wild. There are two rules, specifically, for the ever-present Emotet botnet, which is surging at the end of 2020 after a somewhat quiet summer and fall period.

Here's a breakdown of Tuesday's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
20154