s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

ET-3376

📛 Threat Title

Ruleset Update Summary - 2026/07/06 - v11227

Category: forum-post First seen: Last updated: Source: Emerging Threats Community

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:cloud.ibm.com

    This update introduces 11 new detections in the CIS Managed Ruleset (all currently set to Disabled mode to preserve remediation logic and allow quick activation if needed).

  • web:community.emergingthreats.net

    Summary : 754 new OPEN, 796 new PRO (754 + 42) Added rules: Open: 2070360 - ET INFO DYNAMIC_DNS HTTP Request to a *.patf .net domain (info.rules) 2070361 - ET INFO DYNAMIC_DNS Query to a *.ronindev .ru domain (info.rules) 2070362 - ET INFO DYNAMIC_DNS HTTP Request to a *.ronindev .ru domain (info.rules) 2070363 - ET INFO DYNAMIC_DNS Query to a *.bretonmeadowfarm .org domain (info.rules) 2070364 ...

  • web:community.emergingthreats.net

    Summary : 14 new OPEN, 16 new PRO (14 + 2) Added rules: Open: 2071214 - ET WEB_SPECIFIC_APPS Sonicwall SMA1000 AMC Authenticated Path Traversal (CVE-2026-15410) (web_specific_apps.rules) 2071215 - ET WEB_SPECIFIC_APPS Splunk Cloud & Enterprise edit_user Capability Privilege Escalation (CVE-2023-32707) (web_specific_apps.rules) 2071216 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup ...

  • web:community.emergingthreats.net

    Summary : 7 new OPEN, 7 new PRO (7 + 0) Added rules: Open: 2071228 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (meltedpleasandtws .shop) (malware.rules) 2071229 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (meltedpleasandtws .shop) in TLS SNI (malware.rules) 2071230 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (deckerh .cyou) (malware.rules ...

  • web:learn.microsoft.com

    Azure Web Application Firewall supports a defined set of managed ruleset versions to ensure strong security protections, predictable behavior, and a clear upgrade path for customers. Azure manages the Default Rule Set (DRS), Bot Management, and HTTP DDoS rulesets versions and periodically releases new rule set versions that include new protections, updated signatures, and rule improvements.

  • web:learn.microsoft.com

    Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.

  • web:msrc.microsoft.com

    The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.

  • web:releasebot.io

    Browse a full list of updates made to Application Security by Cloudflare. Follow to get all release notes by email, RSS, and more.

  • web:techcommunity.microsoft.com

    On May 14, 2026, Microsoft disclosed CVE-2026-42897, a reported vulnerability affecting Exchange Outlook Web Access (OWA). An attacker could exploit this issue by sending a specially crafted email to a user.

  • web:www.fedramp.gov

    This section contains the entire Consolidated Rules for 2026 as a standalone reference for each ruleset .

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.