ET-3282
📛 Threat Title
Ruleset Update Summary - 2026/05/07 - v11188
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- Ruleset Update Summary - 2026/05/07 - v11188 Emerging Threats Community
Remediations (8)
-
web:community.emergingthreats.net
Summary : 16 new OPEN, 26 new PRO (16 + 10) Added rules: Open: 2069192 - ET WEB_SPECIFIC_APPS LiteLLM Arbitrary File Read (CVE-2026-35029) (web_specific_apps.rules) 2069193 - ET INFO Rust HTTP Client User-agent Observed (ureq) (info.rules) 2069194 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (brakyfaw .cyou) (malware.rules) 2069195 - ET MALWARE Observed Win32/Lumma Stealer ...
-
web:community.emergingthreats.net
Summary : 29 new OPEN, 55 new PRO (29 + 26) Added rules: Open: 2069208 - ET EXPLOIT_KIT ZPHP Domain in DNS Lookup (calmvector .top) (exploit_kit.rules) 2069209 - ET EXPLOIT_KIT ZPHP Domain in TLS SNI (calmvector .top) (exploit_kit.rules) 2069210 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (files .dsbaux .com) (malware.rules) 2069211 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI ...
-
web:github.com
Session Handoff — 2026-05-07 Skill Hardening + Re-plan Wave TL;DR for the next session The 67% plan-drift problem from the 2026-05-06 wave was addressed at the source: issue-planning-mode skill grew a Step 1.5 (verify-against-repo-state) that requires reproduction of any alleged runtime failure before plan drafting.
-
web:learn.microsoft.com
Defender for Business includes several remediation actions. These actions include manual response actions, actions following automated investigation, and live response actions. The following table lists remediation actions that are available.
-
web:msrc.microsoft.com
Access Microsoft Security Response Center's guide to address vulnerabilities, manage security risks, and keep your systems protected with the latest updates .
-
web:www.cisco.com
Remediation is a program that the system launches in response to a correlation policy violation. Create at least one remediation instance for a module. Add multiple remediations to each instance, describing the actions you want to perform when a policy is violated. Finally, associate remediations with rules in correlation policies for the system to launch the remediations in response to ...
-
web:www.defendedge.com
Vulnerability Summary for the Week of May 4, 2026 Posted by:
-
web:www.microsoft.com
Monday, February 9, 2026 Cross‑site scripting (XSS) remains one of the most frequently reported web vulnerabilities—not because developers are unaware of it, but because many deployed mitigations address symptoms rather than root causes.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.