ET-3404
📛 Threat Title
Ruleset Update Summary - 2026/07/29 - v11245
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- Ruleset Update Summary - 2026/07/29 - v11245 Emerging Threats Community
Remediations (10)
-
web:community.emergingthreats.net
Summary : 8 new OPEN, 9 new PRO (8 + 1) Added rules: Open: 2071124 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (azevedo .lol) (exploit_kit.rules) 2071125 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (fra…
-
web:community.emergingthreats.net
2868019 - ETPRO WEB_SPECIFIC_APPS PTC Windchill/FlexPLM Unauthenticated Remote Code Execution (CVE-2026-12569) (web_specific_apps.rules) 2868020 - ETPRO PHISHING Generic Device Code Phish Landing Page M1 2026-07-21 (phishing.rules)
-
web:community.emergingthreats.net
Summary : 9 new OPEN, 37 new PRO (9 + 28) Added rules: Open: 2071268 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (appallf .pics) (malware.rules) 2071269 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (appallf .pics) in TLS SNI (malware.rules) 2071270 - ET WEB_SPECIFIC_APPS XWiki Groovy Script Command Injection Attempt M2 (CVE-2024-31982) (web_specific_apps.rules ...
-
web:community.emergingthreats.net
Summary : 9 new OPEN, 19 new PRO (9 + 10) Added rules: Open: 2071329 - ET WEB_SPECIFIC_APPS Veracore timeoutWarning PmSess1 Parameter SQL Injection Attempt (CVE-2025-25181) (web_specific_apps.rules) 2071336 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (phiplips .click) (exploit_kit.rules) 2071337 - ET EXPLOIT_KIT LandUpdate808 Domain in TLS SNI (phiplips .click) (exploit_kit.rules ...
-
web:community.emergingthreats.net
Summary : 4 new OPEN, 6 new PRO (4 + 2) Added rules: Open: 2071344 - ET WEB_SPECIFIC_APPS Alibaba fastjson2 Remote Code Execution (CVE-2026-16723) (web_specific_apps.rules) 2071345 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (kitchenfootballkiw .fun) (malware.rules) 2071346 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (kitchenfootballkiw .fun) in TLS SNI ...
-
web:learn.microsoft.com
Azure Web Application Firewall supports a defined set of managed ruleset versions to ensure strong security protections, predictable behavior, and a clear upgrade path for customers. Azure manages the Default Rule Set (DRS), Bot Management, and HTTP DDoS rulesets versions and periodically releases new rule set versions that include new protections, updated signatures, and rule improvements.
-
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
-
web:portal.msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
-
web:www.fedramp.gov
This section contains the entire Consolidated Rules for 2026 as a standalone reference for each ruleset .
-
web:www.fedramp.gov
Ruleset Reference Complete Rulesets Boundary Rulesets Vulnerability Detection and Response The Vulnerability Detection and Response rules require providers to continuously identify, analyze, prioritize, mitigate, and remediate vulnerabilities and related exposures through automated systems. These rules give providers flexibility in implementation while ensuring agencies receive the information ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.