s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

ET-3338

📛 Threat Title

Ruleset Update Summary - 2026/05/27 - v11201

Category: forum-post First seen: Last updated: Source: Emerging Threats Community

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:community.emergingthreats.net

    Summary : 16 new OPEN, 26 new PRO (16 + 10) Added rules: Open: 2069192 - ET WEB_SPECIFIC_APPS LiteLLM Arbitrary File Read (CVE-2026-35029) (web_specific_apps.rules) 2069193 - ET INFO Rust HTTP Client User-agent Observed (ureq) (info.rules) 2069194 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (brakyfaw .cyou) (malware.rules) 2069195 - ET MALWARE Observed Win32/Lumma Stealer ...

  • web:community.emergingthreats.net

    Summary : 29 new OPEN, 31 new PRO (29 + 2) Added rules: Open: 2069237 - ET INFO DYNAMIC_DNS Query to a *.redlight .li domain (info.rules) 2069238 - ET INFO DYNAMIC_DNS HTTP Request to a *.redlight .li domain (info.rules) 2069239 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (meiddlesrsnzop .shop) (malware.rules) 2069240 - ET MALWARE Observed Win32/Lumma Stealer Related ...

  • web:community.emergingthreats.net

    Summary : 7 new OPEN, 24 new PRO (7 + 17) Note: There will be no rule release on Monday, May 25th on account of it being both a US and UK holiday. Added rules: Open: 2069388 - ET MALWARE TA569 Gholoader CnC Domain in DNS Lookup (dl .emergencepsychservices .com) (malware.rules) 2069389 - ET MALWARE TA569 Gholoader CnC Domain in TLS SNI (dl .emergencepsychservices .com) (malware.rules) 2069390 ...

  • web:community.emergingthreats.net

    Summary : 49 new OPEN, 59 new PRO (49 + 10) Added rules: Open: 2069395 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (lolfler .lol) (exploit_kit.rules) 2069396 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (dalindo .lol) (exploit_kit.rules) 2069397 - ET EXPLOIT_KIT LandUpdate808 Domain in DNS Lookup (vandenheuvll .lol) (exploit_kit.rules) 2069398 - ET EXPLOIT_KIT LandUpdate808 ...

  • web:community.emergingthreats.net

    Summary : 21 new OPEN, 24 new PRO (21 + 3) Added rules: Open: 2060957 - ET MALWARE Windows Shortcut Link Padded Whitespace in Command Line Arguments (ZDI-CAN-25373) (malware.rules) 2069444 - ET MALWARE MacSync Stealer Exfil (PUT) (malware.rules) 2069445 - ET ATTACK_RESPONSE MacSync Stealer Payload Inbound (attack_response.rules) 2069446 - ET ATTACK_RESPONSE MacSync Stealer Stage 2 Payload ...

  • web:community.emergingthreats.net

    Summary : 14 new OPEN, 21 new PRO (14 + 7) Added rules: Open: 2069464 - ET MALWARE Gh0st RAT Variant CnC Domain in DNS Lookup (kele12 .vip) (malware.rules) 2069465 - ET MALWARE Gh0st RAT Variant CNC Checkin Attempt (malware.rules) 2069466 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (weekfoc .cyou) (malware.rules) 2069467 - ET MALWARE Observed Win32/Lumma Stealer Related ...

  • web:docs.azure.cn

    Ruleset update The bot mitigation ruleset list of known bad IP addresses updates multiple times per day from the Microsoft Threat Intelligence feed to stay in sync with the bots. Your web applications are continuously protected even as the bot attack vectors change.

  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates , helping users understand and address potential vulnerabilities effectively.

  • web:public.cyber.mil

    The SRG/STIG Library Compilation comprises all DOD Security Requirements Guides (SRGs) and DOD Security Technical Implementation Guides (STIGs) housed on Cyber Exchange. Excluded are Security Readiness Review (SRR) Tools (scripts and OVAL Benchmarks), Group Policy Objects, and draft SRGs and STIGs. The SRG/STIG Library Compilation is updated quarterly to capture all newly updated or released ...

  • web:www.cisco.com

    Remediation is a program that the system launches in response to a correlation policy violation. Create at least one remediation instance for a module. Add multiple remediations to each instance, describing the actions you want to perform when a policy is violated. Finally, associate remediations with rules in correlation policies for the system to launch the remediations in response to ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.