Snort mailing list archives

Re: Snort Subscriber Rules Update 2026-06-04


From: Jonathan Lee via Snort-sigs <snort-sigs () lists snort org>
Date: Sat, 6 Jun 2026 10:20:38 -0700

Hello Snort Team ET issued a bug last night and it was cause the engine to not start. 



Issue Summary:
Following the automated nightly rule update, the Snort service on the WAN interface crashed and failed to start. The 
issue was caused by two separate syntax errors introduced upstream in last night's Emerging Threats (ET) rule package 
release.

Technical Details & Root Causes:

Rule SID 2054074 (ET EXPLOIT Kingdee Cloud Star Deserialization): The rule authors introduced a logical paradox in the 
destination target field ([$EXTERNAL_NET,$HTTP_SERVERS]). Because our firewall defines $EXTERNAL_NET as a negation 
(!$HOME_NET), Snort encountered an unresolvable routing loop and threw a fatal compilation error.
Rule SID 2033776 (ET TROJAN NSO Group Pegasus Related Data Exfil): This rule contained a malformed regular expression 
(PCRE parsing conflict) that broke the trailing option block, causing Snort to drop the rule's closing parenthesis and 
crash on line 10111.
Resolution Action Taken:

The interface configuration was safely isolated and paused.

SID 2054074 Fix: Manually corrected the broken variable logic by swapping the conflicting $EXTERNAL_NET reference to 
$HOME_NET, allowing the engine to mathematically resolve the network paths cleanly.

SID 2033776 Fix: Cleaned up the broken trailing regular expression string parameters to satisfy the parser.

The rules file was updated, and the interface was toggled back on.

Current Status: The Snort engine has successfully verified the configurations, compiled the rule chains, and is now 
fully active and running on the WAN interface. No further action is required unless a subsequent rule update overwrites 
these manual patches before the vendor pushes official fixes.


On Jun 4, 2026, at 06:46, Research via Snort-sigs <snort-sigs () lists snort org> wrote:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1


Talos Snort Subscriber Rules Update

Synopsis:
This release adds and modifies rules in several categories.

Details:
Talos has added and modified multiple rules in the file-identify,
file-other, server-apache and server-webapp rule sets to provide
coverage for emerging threats from these technologies.


For a complete list of new and modified rules please see:

https://www.snort.org/advisories
-----BEGIN PGP SIGNATURE-----

iQIcBAEBAgAGBQJqIYGYAAoJEHB/DbSAg2dxiJUP+wXWvUgWICWGYpOFv/OcJ7RR
FLIKNbD6ESeD7s5BrZ4ayH2dHkgC9oAW4xMnfMeqI7SF3qup8YH09iMpQ60Qxg0s
WXII0CAGgFufoK4YG8X0qLNPxZHig94F+y6hUx/Xert6EU/AjCeNLJTW0es0INbU
OSOzuHOod3JCJQPf6Swd7wkjxJ2yQuW4zvZ5T0XloiDMWkcD+b8LtuNrRa/MeUo0
L8CWFJs7JQixQ+seYMy53SLITbKp5Lsl8+LDV8jSs/+SHpB4mQigLn+Mg+yr3v7H
JK583APs81RddpRN/aeCMVuJ64dnFZ6Am05Azx3Q5U3oabHDwgA26Ma2CYo+1m7j
2O+buB6KA7PbiZdaT+uAV3iaHOm/j1h+yFvEPoWBGg60vhHWu239fIKzkXEJG6ge
s0ZsCm0T8ysglJGoJxmX9RnI4WaG3en9706nTdL/iZV1/7/Jl++13MaA90ZA0FWW
xze4DkygTeKx6edKHXk4Locrmo2kkDMfbHukxIaNJafvAEkK6iOPxkWD3BNmDmLG
0PGrDPPR+3GPScAYi7yhofQ6xl/8xmsBGiDW3ZdTdFQB2pZELVJm9MseGJgAQq0f
e3fB1cRiY4QdJTC/zpI4dhr37vp8F9kqRuT3RggPTqOOLCU5HOOKVbCB8wCIDdzG
iwuJTeZOfFvjMPgWBCCP
=Hk6+
-----END PGP SIGNATURE-----

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

_______________________________________________
Snort-sigs mailing list
Snort-sigs () lists snort org
https://lists.snort.org/mailman/listinfo/snort-sigs

Please visit http://blog.snort.org for the latest news about Snort!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a 
href=" https://snort.org/downloads/#rule-downloads";>emerging threats</a>!

Current thread: