Talos has added and modified multiple rules in the malware-other and server-webapp rule sets to provide coverage for emerging threats from these technologies.
For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2092000.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:65973 <-> DISABLED <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt (server-webapp.rules) * 1:65974 <-> DISABLED <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt (server-webapp.rules) * 1:65975 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65976 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65977 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65978 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65979 <-> DISABLED <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected (malware-other.rules) * 1:65980 <-> DISABLED <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected (malware-other.rules) * 1:65981 <-> DISABLED <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt (server-webapp.rules) * 1:65982 <-> DISABLED <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt (server-webapp.rules) * 1:65983 <-> DISABLED <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt (server-webapp.rules) * 1:65984 <-> DISABLED <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt (server-webapp.rules) * 1:65985 <-> DISABLED <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt (server-webapp.rules) * 3:65972 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules) * 3:65963 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt (server-webapp.rules) * 3:65964 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt (policy-other.rules) * 3:65965 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt (policy-other.rules) * 3:65966 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt (policy-other.rules) * 3:65967 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt (policy-other.rules) * 3:65968 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt (policy-other.rules) * 3:65969 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules) * 3:65970 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules) * 3:65971 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules)
* 1:24339 <-> DISABLED <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt (server-webapp.rules)
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091801.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:65975 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65976 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65974 <-> DISABLED <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt (server-webapp.rules) * 1:65983 <-> DISABLED <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt (server-webapp.rules) * 1:65979 <-> DISABLED <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected (malware-other.rules) * 1:65973 <-> DISABLED <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt (server-webapp.rules) * 1:65977 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65980 <-> DISABLED <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected (malware-other.rules) * 1:65981 <-> DISABLED <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt (server-webapp.rules) * 1:65985 <-> DISABLED <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt (server-webapp.rules) * 1:65984 <-> DISABLED <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt (server-webapp.rules) * 1:65978 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65982 <-> DISABLED <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt (server-webapp.rules) * 3:65963 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt (server-webapp.rules) * 3:65964 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt (policy-other.rules) * 3:65965 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt (policy-other.rules) * 3:65966 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt (policy-other.rules) * 3:65967 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt (policy-other.rules) * 3:65968 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt (policy-other.rules) * 3:65969 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules) * 3:65970 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules) * 3:65971 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules) * 3:65972 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules)
* 1:24339 <-> DISABLED <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt (server-webapp.rules)
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091701.
The format of the file is:
gid:sid <-> Default rule state <-> Message (rule group)
* 1:65981 <-> DISABLED <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt (server-webapp.rules) * 1:65982 <-> DISABLED <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt (server-webapp.rules) * 1:65983 <-> DISABLED <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt (server-webapp.rules) * 1:65976 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65977 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65974 <-> DISABLED <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt (server-webapp.rules) * 1:65980 <-> DISABLED <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected (malware-other.rules) * 1:65973 <-> DISABLED <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt (server-webapp.rules) * 1:65975 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65978 <-> DISABLED <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt (server-webapp.rules) * 1:65985 <-> DISABLED <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt (server-webapp.rules) * 1:65979 <-> DISABLED <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected (malware-other.rules) * 1:65984 <-> DISABLED <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt (server-webapp.rules) * 3:65963 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt (server-webapp.rules) * 3:65964 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt (policy-other.rules) * 3:65965 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt (policy-other.rules) * 3:65966 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt (policy-other.rules) * 3:65967 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt (policy-other.rules) * 3:65968 <-> ENABLED <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt (policy-other.rules) * 3:65969 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules) * 3:65970 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules) * 3:65971 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules) * 3:65972 <-> ENABLED <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt (server-webapp.rules)
* 1:24339 <-> DISABLED <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt (server-webapp.rules)
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.2.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.3.5.1.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.3.6.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.3.7.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.7.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.9.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.11.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.15.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.18.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.20.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.21.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.35.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.44.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.47.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt
This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.11.0.0.
The format of the file is:
gid:sid <-> Message
* 1:301410 <-> MALWARE-OTHER Js.Backdoor.Amcowuap variant download detected * 1:301411 <-> SERVER-WEBAPP Synacor Zimbra Collaboration Suite server side request forgery attempt * 1:65973 <-> SERVER-WEBAPP GitLab AutolinkFilter regular expression denial of service attempt * 1:65974 <-> SERVER-WEBAPP Froxlor SImExporter.php arbitrary file upload attempt * 1:65975 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65976 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65977 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65978 <-> SERVER-WEBAPP Oracle E-Business Suite Sales Offline denial of service attempt * 1:65981 <-> SERVER-WEBAPP WordPress XML external entity parsing information disclosure attempt * 1:65982 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 1:65983 <-> SERVER-WEBAPP GitLab CI Lint server side request forgery attempt * 3:65963 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2369 attack attempt * 3:65964 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65965 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2338 attack attempt * 3:65966 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65967 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65968 <-> POLICY-OTHER TRUFFLEHUNTER TALOS-2026-2342 attack attempt * 3:65969 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65970 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65971 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt * 3:65972 <-> SERVER-WEBAPP TRUFFLEHUNTER TALOS-2026-2333 attack attempt
* 1:24339 <-> SERVER-WEBAPP Multiple products XML external entity parsing information disclosure attempt