ET-3268
📛 Threat Title
Ruleset Update Summary - 2026/04/21 - v11176
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- Ruleset Update Summary - 2026/04/21 - v11176 Emerging Threats Community
Remediations (8)
-
web:community.emergingthreats.net
Summary : 33 new OPEN, 56 new PRO (33 + 23) Added rules: Open: 2068817 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (analipr .cyou) (malware.rules) 2068818 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (analipr .cyou) in TLS SNI (malware.rules) 2068819 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (famiszp .cyou) (malware.rules) 2068820 - ET ...
-
web:community.emergingthreats.net
Summary : 49 new OPEN, 79 new PRO (49 + 30) Added rules: Open: 2068850 - ET WEB_SPECIFIC_APPS nginx-ui MCP Module Authentication Bypass (CVE-2026-33032) (web_specific_apps.rules) 2068851 - ET INFO DYNAMIC_DNS Query to a *.sulekutlay .com domain (info.rules) 2068852 - ET INFO DYNAMIC_DNS HTTP Request to a *.sulekutlay .com domain (info.rules) 2068853 - ET MALWARE Win32/Lumma Stealer Related CnC ...
-
web:feedly.com
Sploitus.com Exploits RSS Feed / 12d Ruleset Update Summary - 2026/04/21 - v11176 Emerging Threats - Latest posts / 13d 2068856 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (bammyanwjo .shop) in TLS SNI (malware.rules) 2068855 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (bammyanwjo .shop) (malware.rules)
-
web:learn.microsoft.com
The bot mitigation ruleset list of known bad IP addresses updates multiple times per day from the Microsoft Threat Intelligence feed to stay in sync with the bots.
-
web:public.cyber.mil
The SRG/STIG Library Compilation comprises all DOD Security Requirements Guides (SRGs) and DOD Security Technical Implementation Guides (STIGs) housed on Cyber Exchange. Excluded are Security Readiness Review (SRR) Tools (scripts and OVAL Benchmarks), Group Policy Objects, and draft SRGs and STIGs. The SRG/STIG Library Compilation is updated quarterly to capture all newly updated or released ...
-
web:sec.cloudapps.cisco.com
To learn about Cisco security vulnerability disclosure policies and publications, see the Security Vulnerability Policy. This document also contains instructions for obtaining fixed software and receiving security vulnerability information from Cisco. Cisco Security Advisories and other Cisco security content are provided on an "as is" basis and do not imply any kind of guarantee or warranty ...
-
web:support.microsoft.com
In this article Summary Take action Timing of updates Deployment guidelines Registry settings Audit events Frequently asked questions (FAQ) Resources Change log Summary Windows updates released on and after January 13, 2026, contain protections for a vulnerability with the Kerberos authentication protocol. The Windows updates address an information disclosure vulnerability in CVE-2026-20833 ...
-
web:www.cisco.com
Remediation is a program that the system launches in response to a correlation policy violation. Create at least one remediation instance for a module. Add multiple remediations to each instance, describing the actions you want to perform when a policy is violated. Finally, associate remediations with rules in correlation policies for the system to launch the remediations in response to ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.