Showing posts with label vulnerabilities. Show all posts
Showing posts with label vulnerabilities. Show all posts

Tuesday, October 12, 2021

Snort rule update for Oct. 12, 2021 — Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for many of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this month, head to the Talos blog.

Here's a breakdown of this afternoon's rule release:

Shared object rulesModified shared object rulesNew rulesModified rules
10378

Thursday, August 5, 2021

Snort rule update for Aug. 5, 2021

The latest SNORTⓇ ruleset is available this morning from Cisco Talos.

Thursday's rule update includes protection against two pre-authorization vulnerabilities in the Cisco RV series of routers. The two vulnerabilities Cisco disclosed this week could allow an attacker to trigger a denial-of-service condition or execute commands and arbitrary code on vulnerable devices.

Here's a full breakdown of this release:

Shared object rulesModified shared object rulesNew rulesModified rules
100

Tuesday, April 7, 2020

Snort rule update for April 7, 2020

This morning, Cisco Talos released the latest rule update for SNORTⓇ.

The latest release includes 15 new rules, one modified rule and 12 new shared object rules.

Some of the new rules include new protections against two critical vulnerabilities in the popular ThemeREX WordPress plugin. There is also coverage for a pair of critical use-after-free vulnerabilities in Mozilla Firefox that have been used recently in targeted attacks.

Tuesday, December 10, 2019

Snort rule update for Dec. 10, 2019: Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for all of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this week, head to the Talos blog.

In all, this release includes 11 new rules, 10 new shared object rules and four modified rules.

Tuesday, November 26, 2019

Snort rule update for Nov. 26, 2019

Cisco Talos just released the latest SNORT® rule update for all users. Talos urges all users to implement these rules as soon as possible to keep their networks and machines protected.

Today's release contains 22 new rules and 17 modified rules.

Included in this new rule set are is coverage for a high-severity vulnerability in Apache Solr, as well as protection against the Ursnif trojan when it attempts to download malicious documents.

Tuesday, November 12, 2019

Snort rule update for Nov. 12, 2019: Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for all of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the vulnerabilities Microsoft disclosed this week, head to the Talos blog.

In all, this release includes 89 new rules, seven modified rules and three shared object rules.

Tuesday, October 8, 2019

Snort rule update for Oct. 8, 2019: Microsoft Patch Tuesday

The latest SNORT® rule release from Cisco Talos has arrived. This new round of rules provides coverage for all of the vulnerabilities covered in Microsoft Patch Tuesday.

For more details on the 60 vulnerabilities Microsoft disclosed this week, head to the Talos blog.

In all, this release includes 63 new rules, six modified rules and two new shared object rules.

Tuesday, July 30, 2019

Snort rule update for July 30, 2019

Cisco Talos just released the latest SNORT® rule update for all users. Talos urges all users to implement these rules as soon as possible to keep their networks and machines protected.

This release contains 21 new rules, nine new shared object rules, 138 modified rules and five modified shared object rules.

Thursday's release includes coverage for several different malware families recently used in the wild, including Godlua, Ratsnif and SoftCell.

Thursday, July 25, 2019

Snort rule update for July 25, 2019

Cisco Talos just released the latest SNORT® rule update for all users. Talos urges all users to implement these rules as soon as possible to keep their networks and machines protected.

This release contains six new rules, 13 new shared object rules and four modified rules.

Thursday's release provides protection against a series of vulnerabilities and exploits targeted toward Industrial Control Systems. Security researchers recently discovered 12 bugs in products from three different companies that could allow an attacker to take over SCADA software belonging to vital infrastructures such as water and power suppliers.

Tuesday, July 23, 2019

Snort rule update for July, 23, 2019

Cisco Talos just released the latest SNORT® rule update for all users. Talos urges all users to implement these rules as soon as possible to keep their networks and machines protected.

This release contains six new rules — two of which are shared object rules, as well as two modified rules.

Thursday's release provides protection against a vulnerability in Windows win32k that attackers have exploited in the wild.

Thursday, July 18, 2019

Snort rule update for July 18, 2019

Cisco Talos just released the latest SNORT® rule update for all users. Talos urges all users to implement these rules as soon as possible to keep their networks and machines protected.

This release contains 21 new rules — 10 of which are shared object rules, as well as five modified rules.

Thursday's release provides protection against a critical vulnerability in Cisco Vision Dynamic Signage Director, as well as a remote code execution bug in a popular plugin for WordPress.

Thursday, July 11, 2019

Snort rule update for July 11, 2019

Just released:
Snort Subscriber Rule Set Update for July 11, 2019

Cisco Talos released the latest SNORTⓇ rule set today. This release includes 28 new rules and four modified rules, none of which are shared object rules.

This release provides new coverage for CVE-2017-11882, CVE-2018-0802 and CVE-2018-0798. These vulnerabilities in Microsoft Equation Editor — which have previous patches — are being exploited by a threat actor to deliver malware and send malicious RTF documents to users. Based on this new intelligence, this latest update includes new coverage for these bugs: SIDs 50684, 50685 and 50689-50695.

There were no changes made to the snort.conf in this release.

Thursday, June 20, 2019

Snort rule update for June 19, 2019

Just released:
Snort Subscriber Rule Set Update for June 19, 2019

Cisco Talos released the latest SNORTⓇ rule set overnight. This release includes 24 new rules, 10 of which are shared object rules. There are also four modified rules, two of which are shared object rules.

This release provides coverage for several vulnerabilities Cisco recently disclosed in its Prime Service Catalog and some RV routers. Several different models of RV routers contain bugs in their web-based interface that could allow malicious actors to carry out denial-of-service attacks.

There were no changes made to the snort.conf in this release.

Tuesday, June 18, 2019

Snort rule update for June 18, 2019

Just released:
Snort Subscriber Rule Set Update for June 18, 2019

Cisco Talos released the latest SNORTⓇ rule set today. This release includes 12 new rules and 10 modified, none of which are shared object rules.

This release provides protection against the new HiddenWasp malware, which has been spotted in the wild targeting Linux systems. This attack shares similarities with other, previous Linux malware. Researchers believe some of the code may have even copy and pasted from other actors.

There were no changes made to the snort.conf in this release.

Thursday, June 6, 2019

Snort rule update for June 6, 2019

Just released:
Snort Subscriber Rule Set Update for June 6, 2019

Cisco Talos released the latest SNORTⓇ rule set today. This release includes 46 new rules, two of which are shared object rules. There are no modified rules in this release.

In this release, we have new protections for a series of serious vulnerabilities in the Kace K1000 systems management appliance from Quest, as well as bugs in VMware.

There were no changes made to the snort.conf in this release.

Tuesday, May 21, 2019

Snort rule update for May 20, 2019

Just released:
Snort Subscriber Rule Set Update for May 20, 2019

Last night, Cisco Talos released the latest SNORTⓇ rule set. This release includes 18 new rules, three of which are shared object rules. There are also eight modified rules.

This release includes coverage for indicators associated with CVE-2019-0708, a remote code execution vulnerability in Microsoft Remote Desktop Services — formerly known as Terminal Services. This is a highly publicized vulnerability from Microsoft, which the company disclosed last week as part of its monthly security update. The vulnerability is wormable, meaning future malware that exploits this bug could spread from system to system.

There were no changes made to the snort.conf in this release.

Tuesday, April 30, 2019

Snort rule update for April 30, 2019

Just released:
Snort Subscriber Rule Set Update for April 30, 2019

Cisco Talos just released the newest SNORT® rule set. This release includes 34 new rules, four of which are shared object rules. There are also seven modified rules, one of which is a shared object rules.

This release provides protection from attackers exploiting a zero-day vulnerability in Oracle WebLogic servers. Attackers are exploiting this bug to deliver a new ransomware called "Sodinokibi."

There were no changes made to the snort.conf in this release.

Tuesday, April 9, 2019

Snort rule update for April 9, 2019 — Microsoft Patch Tuesday

Just released:
Snort Subscriber Rule Set Update for April 9, 2019

The newest SNORTⓇ rule set is here from Cisco Talos. In this release, we introduced 80 new rules, eight of which are shared object rules. There are also 10 modified rules.

This release covers Microsoft Patch Tuesday, which included fixes for 74 vulnerabilities. You can read more about the bugs that Microsoft disclosed over at the Talos blog.

Tuesday, April 2, 2019

Snort rule update for April 2, 2019

Just released:
Snort Subscriber Rule Set Update for April 2, 2019

Cisco Talos just released the newest SNORT® rule set. This release includes 33 new rules, three of which are shared object rules. There are also three modified rules and four modified shared object rules.

This release provides coverage for a bug in Huawei's PCManager software that could allow an attacker to bypass security protections in the Windows kernel. There's also a new rule to protect the RV series of Cisco routers, which have been under attack for several months.

Thursday, March 21, 2019

Snort rule update for March 21, 2019

Just released:
Snort Subscriber Rule Set Update for March 21, 2019

Cisco Talos just released the newest SNORT® rule set. This release includes 20 new rules, three new shared object rules and one modified rule.

In this release, we have coverage for a new variant of the Mirai botnet. Recently, researchers discovered a new wave of attacks targeting presentation software and devices. There is also protection against several critical vulnerabilities Cisco recently patched in some of its IP phones.