s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

ET-3267

📛 Threat Title

Ruleset Update Summary - 2026/04/20 - v11175

Category: forum-post First seen: Last updated: Source: Emerging Threats Community

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (8)

  • web:community.emergingthreats.net

    Summary : 17 new OPEN, 34 new PRO (17 + 17) Added rules: Open: 2068359 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (anteria .pics) (malware.rules) 2068360 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (anteria .pics) in TLS SNI (malware.rules) 2068361 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (ossifvg .click) (malware.rules) 2068362 - ET ...

  • web:community.emergingthreats.net

    Summary : 9 new OPEN, 19 new PRO (9 + 10) Added rules: Open: 2068808 - ET INFO DYNAMIC_DNS Query to a *.fiedleracres .com domain (info.rules) 2068809 - ET INFO DYNAMIC_DNS HTTP Request to a *.fiedleracres .com domain (info.rules) 2068810 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (cankgmr .cyou) (malware.rules) 2068811 - ET MALWARE Observed Win32/Lumma Stealer Related ...

  • web:community.emergingthreats.net

    Summary : 33 new OPEN, 56 new PRO (33 + 23) Added rules: Open: 2068817 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (analipr .cyou) (malware.rules) 2068818 - ET MALWARE Observed Win32/Lumma Stealer Related Domain (analipr .cyou) in TLS SNI (malware.rules) 2068819 - ET MALWARE Win32/Lumma Stealer Related CnC Domain in DNS Lookup (famiszp .cyou) (malware.rules) 2068820 - ET ...

  • web:community.emergingthreats.net

    Summary : 49 new OPEN, 79 new PRO (49 + 30) Added rules: Open: 2068850 - ET WEB_SPECIFIC_APPS nginx-ui MCP Module Authentication Bypass (CVE-2026-33032) (web_specific_apps.rules) 2068851 - ET INFO DYNAMIC_DNS Query to a *.sulekutlay .com domain (info.rules) 2068852 - ET INFO DYNAMIC_DNS HTTP Request to a *.sulekutlay .com domain (info.rules) 2068853 - ET MALWARE Win32/Lumma Stealer Related CnC ...

  • web:learn.microsoft.com

    In addition, some types of remediation actions can occur automatically, whereas other types of remediation actions are taken manually by your organization's security team. When an automated investigation results in one or more remediation actions, the investigation completes only when the remediation actions are taken, approved, or rejected.

  • web:public.cyber.mil

    The SRG/STIG Library Compilation comprises all DOD Security Requirements Guides (SRGs) and DOD Security Technical Implementation Guides (STIGs) housed on Cyber Exchange. Excluded are Security Readiness Review (SRR) Tools (scripts and OVAL Benchmarks), Group Policy Objects, and draft SRGs and STIGs. The SRG/STIG Library Compilation is updated quarterly to capture all newly updated or released ...

  • web:www.cisa.gov

    The CISA Vulnerability Bulletin provides a summary of new vulnerabilities that have been recorded in the past week. In some cases, the vulnerabilities in the bulletin may not yet have assigned CVSS scores. Vulnerabilities are based on the Common Vulnerabilities and Exposures

  • web:www.cisco.com

    Remediation is a program that the system launches in response to a correlation policy violation. Create at least one remediation instance for a module. Add multiple remediations to each instance, describing the actions you want to perform when a policy is violated. Finally, associate remediations with rules in correlation policies for the system to launch the remediations in response to ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.