Snort mailing list archives

Snort Subscriber Rules Update 2023-11-16


From: Research <research () sourcefire com>
Date: Thu, 16 Nov 2023 14:26:27 GMT

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Microsoft Vulnerability CVE-2023-36017:
A coding deficiency exists in Microsoft Windows Scripting Engine that
may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in
this release and are identified with:
Snort 2: GID 1, SIDs 62659 through 62660,
Snort 3: GID 1, SID 300762.  

Talos has added and modified multiple rules in the browser-ie,
malware-cnc, malware-other and server-webapp rule sets to provide
coverage for emerging threats from these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJlViaMAAoJEMzg39Iewam/l3MP/i0oEzqyIJ7XOddmg/0uQl3O
8VXMTL2GF/omcgr6qRR+5PZtT7uGoHfz3s6Zdf3CdDUSC8tNbtLKOI8hAjgSvXsD
uAPzgaOQv0Cu01tRXrAX3P6eMXokh/1crXnuJ8xIc5U/2SqH2Shs/ZPVZ4AEqBiy
KPCs473UglNwacT5phz98eR1tFOK5HXCurS2o/CHDFTLsptblP342ngFON6FzDVJ
4ozn8NtCmQNu7flKjJL6PGD3pqv2PFihppF+jDMGnKH4SAJvGSSByfOpvWL9Rn3y
hHmNGX1xcXPnf8TeSePIhqNf9KYQ+e4hRE+Nwjt+LmwpGtSkLE8ngssul4SobXIU
lT1wwD6lJQ7Z2zcuMoR0yVLRz/9onACK6xkZ8H+emcwkyUjVy1Zdv1ldb0iFv+zV
G0GF7aeo6wUfNJEFK5E/64Q609dmlfZrXbZF3AmIkSA2OxJ6y5RkdGfOHcx1ZVcp
aGiHPBJF/B9hfRZ+/jlDEAjuVtjX22xK2pxUCkHXK+S4/slA0Hg+oZIpUsbhCsaO
ih0V34ULKG0sCFFwVgfl9+uuV+GupRSHvfqO9lwWZsxoxp0mgmSXVllvbNfyqj8z
c0UqaRhlrZatuYGL8CAn+QSJ0pjLKNEXBVeg4UwkwsAs/XqA1i329r4FCjxrUkbr
/4YA8t49IcLQ8RPXi/uf
=MOLs
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!


Current thread: