Snort mailing list archives
Re: Snort Subscriber Rules Update 2026-06-04
From: Jonathan Lee via Snort-sigs <snort-sigs () lists snort org>
Date: Sat, 6 Jun 2026 10:20:38 -0700
Hello Snort Team ET issued a bug last night and it was cause the engine to not start. Issue Summary: Following the automated nightly rule update, the Snort service on the WAN interface crashed and failed to start. The issue was caused by two separate syntax errors introduced upstream in last night's Emerging Threats (ET) rule package release. Technical Details & Root Causes: Rule SID 2054074 (ET EXPLOIT Kingdee Cloud Star Deserialization): The rule authors introduced a logical paradox in the destination target field ([$EXTERNAL_NET,$HTTP_SERVERS]). Because our firewall defines $EXTERNAL_NET as a negation (!$HOME_NET), Snort encountered an unresolvable routing loop and threw a fatal compilation error. Rule SID 2033776 (ET TROJAN NSO Group Pegasus Related Data Exfil): This rule contained a malformed regular expression (PCRE parsing conflict) that broke the trailing option block, causing Snort to drop the rule's closing parenthesis and crash on line 10111. Resolution Action Taken: The interface configuration was safely isolated and paused. SID 2054074 Fix: Manually corrected the broken variable logic by swapping the conflicting $EXTERNAL_NET reference to $HOME_NET, allowing the engine to mathematically resolve the network paths cleanly. SID 2033776 Fix: Cleaned up the broken trailing regular expression string parameters to satisfy the parser. The rules file was updated, and the interface was toggled back on. Current Status: The Snort engine has successfully verified the configurations, compiled the rule chains, and is now fully active and running on the WAN interface. No further action is required unless a subsequent rule update overwrites these manual patches before the vendor pushes official fixes.
On Jun 4, 2026, at 06:46, Research via Snort-sigs <snort-sigs () lists snort org> wrote: -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Talos Snort Subscriber Rules Update Synopsis: This release adds and modifies rules in several categories. Details: Talos has added and modified multiple rules in the file-identify, file-other, server-apache and server-webapp rule sets to provide coverage for emerging threats from these technologies. For a complete list of new and modified rules please see: https://www.snort.org/advisories -----BEGIN PGP SIGNATURE----- iQIcBAEBAgAGBQJqIYGYAAoJEHB/DbSAg2dxiJUP+wXWvUgWICWGYpOFv/OcJ7RR FLIKNbD6ESeD7s5BrZ4ayH2dHkgC9oAW4xMnfMeqI7SF3qup8YH09iMpQ60Qxg0s WXII0CAGgFufoK4YG8X0qLNPxZHig94F+y6hUx/Xert6EU/AjCeNLJTW0es0INbU OSOzuHOod3JCJQPf6Swd7wkjxJ2yQuW4zvZ5T0XloiDMWkcD+b8LtuNrRa/MeUo0 L8CWFJs7JQixQ+seYMy53SLITbKp5Lsl8+LDV8jSs/+SHpB4mQigLn+Mg+yr3v7H JK583APs81RddpRN/aeCMVuJ64dnFZ6Am05Azx3Q5U3oabHDwgA26Ma2CYo+1m7j 2O+buB6KA7PbiZdaT+uAV3iaHOm/j1h+yFvEPoWBGg60vhHWu239fIKzkXEJG6ge s0ZsCm0T8ysglJGoJxmX9RnI4WaG3en9706nTdL/iZV1/7/Jl++13MaA90ZA0FWW xze4DkygTeKx6edKHXk4Locrmo2kkDMfbHukxIaNJafvAEkK6iOPxkWD3BNmDmLG 0PGrDPPR+3GPScAYi7yhofQ6xl/8xmsBGiDW3ZdTdFQB2pZELVJm9MseGJgAQq0f e3fB1cRiY4QdJTC/zpI4dhr37vp8F9kqRuT3RggPTqOOLCU5HOOKVbCB8wCIDdzG iwuJTeZOfFvjMPgWBCCP =Hk6+ -----END PGP SIGNATURE----- _______________________________________________ Snort-sigs mailing list Snort-sigs () lists snort org https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
_______________________________________________ Snort-sigs mailing list Snort-sigs () lists snort org https://lists.snort.org/mailman/listinfo/snort-sigs Please visit http://blog.snort.org for the latest news about Snort! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette Visit the Snort.org to subscribe to the official Snort ruleset, make sure to stay up to date to catch the most <a href=" https://snort.org/downloads/#rule-downloads">emerging threats</a>!
Current thread:
- Snort Subscriber Rules Update 2026-06-04 Research via Snort-sigs (Jun 04)
- Re: Snort Subscriber Rules Update 2026-06-04 Jonathan Lee via Snort-sigs (Jun 08)
