ET-3376
📛 Threat Title
Ruleset Update Summary - 2026/07/06 - v11227
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (1)
- Ruleset Update Summary - 2026/07/06 - v11227 Emerging Threats Community
Remediations (10)
-
web:cloud.ibm.com
This update introduces 11 new detections in the CIS Managed Ruleset (all currently set to Disabled mode to preserve remediation logic and allow quick activation if needed).
-
web:community.emergingthreats.net
Summary : 754 new OPEN, 796 new PRO (754 + 42) Added rules: Open: 2070360 - ET INFO DYNAMIC_DNS HTTP Request to a *.patf .net domain (info.rules) 2070361 - ET INFO DYNAMIC_DNS Query to a *.ronindev .ru domain (info.rules) 2070362 - ET INFO DYNAMIC_DNS HTTP Request to a *.ronindev .ru domain (info.rules) 2070363 - ET INFO DYNAMIC_DNS Query to a *.bretonmeadowfarm .org domain (info.rules) 2070364 ...
-
web:community.emergingthreats.net
Summary : 14 new OPEN, 16 new PRO (14 + 2) Added rules: Open: 2071214 - ET WEB_SPECIFIC_APPS Sonicwall SMA1000 AMC Authenticated Path Traversal (CVE-2026-15410) (web_specific_apps.rules) 2071215 - ET WEB_SPECIFIC_APPS Splunk Cloud & Enterprise edit_user Capability Privilege Escalation (CVE-2023-32707) (web_specific_apps.rules) 2071216 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup ...
-
web:community.emergingthreats.net
Summary : 7 new OPEN, 7 new PRO (7 + 0) Added rules: Open: 2071228 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (meltedpleasandtws .shop) (malware.rules) 2071229 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (meltedpleasandtws .shop) in TLS SNI (malware.rules) 2071230 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (deckerh .cyou) (malware.rules ...
-
web:learn.microsoft.com
Azure Web Application Firewall supports a defined set of managed ruleset versions to ensure strong security protections, predictable behavior, and a clear upgrade path for customers. Azure manages the Default Rule Set (DRS), Bot Management, and HTTP DDoS rulesets versions and periodically releases new rule set versions that include new protections, updated signatures, and rule improvements.
-
web:learn.microsoft.com
Remediate security weaknesses discovered through security recommendations, and create exceptions if needed, in Defender Vulnerability Management.
-
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
-
web:releasebot.io
Browse a full list of updates made to Application Security by Cloudflare. Follow to get all release notes by email, RSS, and more.
-
web:techcommunity.microsoft.com
On May 14, 2026, Microsoft disclosed CVE-2026-42897, a reported vulnerability affecting Exchange Outlook Web Access (OWA). An attacker could exploit this issue by sending a specially crafted email to a user.
-
web:www.fedramp.gov
This section contains the entire Consolidated Rules for 2026 as a standalone reference for each ruleset .
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.