Talos Rules 2026-08-11
Talos is aware of vulnerabilities affecting products from Microsoft Corporation.

Microsoft Vulnerability CVE-2026-61348: A coding deficiency exists in Microsoft Windows Ancillary Function Driver for WinSock that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66903 through 66904, Snort 3: GID 1, SID 301589.

Microsoft Vulnerability CVE-2026-61358: A coding deficiency exists in Microsoft Windows Accessibility Infrastructure (ATBroker.exe) that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66905 through 66906, Snort 3: GID 1, SID 301590.

Microsoft Vulnerability CVE-2026-61359: A coding deficiency exists in Microsoft Windows Storage that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66943 through 66944, Snort 3: GID 1, SID 301605.

Microsoft Vulnerability CVE-2026-61929: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66914 through 66915, Snort 3: GID 1, SID 301594.

Microsoft Vulnerability CVE-2026-61930: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66916 through 66917, Snort 3: GID 1, SID 301595.

Microsoft Vulnerability CVE-2026-62688: A coding deficiency exists in Microsoft Windows MIDI Service Module Elevation of Privileges Vulnerability that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66939 through 66940, Snort 3: GID 1, SID 301603.

Microsoft Vulnerability CVE-2026-62696: A coding deficiency exists in Microsoft Windows Program Compatibility Assistant Service that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66918 through 66919, Snort 3: GID 1, SID 301596.

Microsoft Vulnerability CVE-2026-62698: A coding deficiency exists in Microsoft Digest Authentication that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66941 through 66942, Snort 3: GID 1, SID 301604.

Microsoft Vulnerability CVE-2026-62712: A coding deficiency exists in Microsoft Windows Win32k that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66937 through 66938, Snort 3: GID 1, SID 301602.

Microsoft Vulnerability CVE-2026-62713: A coding deficiency exists in Microsoft Windows Cloud Files Mini Filter Driver that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66907 through 66908, Snort 3: GID 1, SID 301591.

Microsoft Vulnerability CVE-2026-62721: A coding deficiency exists in Microsoft Windows User-Mode Power Service (UMPS) that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66929 through 66930, Snort 3: GID 1, SID 301599.

Microsoft Vulnerability CVE-2026-62735: A coding deficiency exists in Microsoft Windows HTTP.sys that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66931 through 66932, Snort 3: GID 1, SID 301600.

Microsoft Vulnerability CVE-2026-62737: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66909 through 66910, Snort 3: GID 1, SID 301592.

Microsoft Vulnerability CVE-2026-62766: A coding deficiency exists in Microsoft Windows Kerberos that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66912 through 66913, Snort 3: GID 1, SID 301593.

Microsoft Vulnerability CVE-2026-62783: A coding deficiency exists in Microsoft Windows Remote Access Connection Manager that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66920 through 66921, Snort 3: GID 1, SID 301597.

Microsoft Vulnerability CVE-2026-62788: A coding deficiency exists in Microsoft Windows Kernel that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66935 through 66936, Snort 3: GID 1, SID 301601.

Microsoft Vulnerability CVE-2026-62893: A coding deficiency exists in Microsoft Windows Deployment Services TFTP Server that may lead to remote code execution.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SID 66902, Snort 3: GID 1, SID 66902.

Microsoft Vulnerability CVE-2026-65775: A coding deficiency exists in Microsoft Windows Win32k that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66922 through 66923, Snort 3: GID 1, SID 301598.

Microsoft Vulnerability CVE-2026-65788: A coding deficiency exists in Microsoft Desktop Window Manager that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66947 through 66948, Snort 3: GID 1, SID 301607.

Microsoft Vulnerability CVE-2026-68820: A coding deficiency exists in Microsoft Windows Ancillary Function Driver for WinSock that may lead to an escalation of privilege.

Rules to detect attacks targeting these vulnerabilities are included in this release and are identified with: Snort 2: GID 1, SIDs 66945 through 66946, Snort 3: GID 1, SID 301606.

Talos also has added and modified multiple rules in the file-other, malware-cnc, os-windows and server-webapp rule sets to provide coverage for emerging threats from these technologies.

For information about Snort Subscriber Rulesets available for purchase, please visit the Snort product page.

Change logs

2026-08-11 22:07:45 UTC

Snort Subscriber Rules Update

Date: 2026-08-11

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2092000.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:66900 <-> DISABLED <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt (policy-other.rules)
 * 1:66901 <-> ENABLED <-> SERVER-WEBAPP Langflow code validator remote code execution attempt (server-webapp.rules)
 * 1:66902 <-> DISABLED <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt (os-windows.rules)
 * 1:66903 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66904 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66905 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt (os-windows.rules)
 * 1:66906 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt (os-windows.rules)
 * 1:66907 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt (os-windows.rules)
 * 1:66908 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt (os-windows.rules)
 * 1:66909 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66910 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66911 <-> ENABLED <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt (server-webapp.rules)
 * 1:66912 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt (os-windows.rules)
 * 1:66913 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt (os-windows.rules)
 * 1:66914 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66915 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66916 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66917 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66918 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt (os-windows.rules)
 * 1:66919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt (os-windows.rules)
 * 1:66920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt (os-windows.rules)
 * 1:66921 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt (os-windows.rules)
 * 1:66922 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66923 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66924 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant download attempt (malware-cnc.rules)
 * 1:66925 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66926 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66927 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66928 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66929 <-> DISABLED <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt (os-windows.rules)
 * 1:66930 <-> DISABLED <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt (os-windows.rules)
 * 1:66931 <-> DISABLED <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt (os-windows.rules)
 * 1:66932 <-> DISABLED <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt (os-windows.rules)
 * 1:66933 <-> DISABLED <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt (file-other.rules)
 * 1:66934 <-> DISABLED <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt (file-other.rules)
 * 1:66935 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66936 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66937 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66938 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66939 <-> DISABLED <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt (os-windows.rules)
 * 1:66940 <-> DISABLED <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt (os-windows.rules)
 * 1:66941 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt (os-windows.rules)
 * 1:66942 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt (os-windows.rules)
 * 1:66943 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt (os-windows.rules)
 * 1:66944 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt (os-windows.rules)
 * 1:66945 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66946 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66947 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt (os-windows.rules)
 * 1:66948 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt (os-windows.rules)
 * 3:66949 <-> ENABLED <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt (server-webapp.rules)
 * 3:66950 <-> ENABLED <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt (server-webapp.rules)

Modified Rules:


 * 3:46897 <-> ENABLED <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt (server-webapp.rules)

2026-08-11 22:07:45 UTC

Snort Subscriber Rules Update

Date: 2026-08-11

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091801.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:66941 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt (os-windows.rules)
 * 1:66939 <-> DISABLED <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt (os-windows.rules)
 * 1:66900 <-> DISABLED <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt (policy-other.rules)
 * 1:66901 <-> ENABLED <-> SERVER-WEBAPP Langflow code validator remote code execution attempt (server-webapp.rules)
 * 1:66902 <-> DISABLED <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt (os-windows.rules)
 * 1:66903 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66904 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66905 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt (os-windows.rules)
 * 1:66906 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt (os-windows.rules)
 * 1:66907 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt (os-windows.rules)
 * 1:66908 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt (os-windows.rules)
 * 1:66909 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66910 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66911 <-> ENABLED <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt (server-webapp.rules)
 * 1:66912 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt (os-windows.rules)
 * 1:66913 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt (os-windows.rules)
 * 1:66914 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66915 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66916 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66917 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66918 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt (os-windows.rules)
 * 1:66919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt (os-windows.rules)
 * 1:66920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt (os-windows.rules)
 * 1:66921 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt (os-windows.rules)
 * 1:66922 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66923 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66924 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant download attempt (malware-cnc.rules)
 * 1:66925 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66926 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66927 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66928 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66929 <-> DISABLED <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt (os-windows.rules)
 * 1:66930 <-> DISABLED <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt (os-windows.rules)
 * 1:66931 <-> DISABLED <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt (os-windows.rules)
 * 1:66932 <-> DISABLED <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt (os-windows.rules)
 * 1:66933 <-> DISABLED <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt (file-other.rules)
 * 1:66934 <-> DISABLED <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt (file-other.rules)
 * 1:66935 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66936 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66937 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66938 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66942 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt (os-windows.rules)
 * 1:66943 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt (os-windows.rules)
 * 1:66944 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt (os-windows.rules)
 * 1:66945 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66946 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66947 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt (os-windows.rules)
 * 1:66948 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt (os-windows.rules)
 * 1:66940 <-> DISABLED <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt (os-windows.rules)
 * 3:66949 <-> ENABLED <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt (server-webapp.rules)
 * 3:66950 <-> ENABLED <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt (server-webapp.rules)

Modified Rules:


 * 3:46897 <-> ENABLED <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt (server-webapp.rules)

2026-08-11 22:07:45 UTC

Snort Subscriber Rules Update

Date: 2026-08-11

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 2091701.

The format of the file is:

gid:sid <-> Default rule state <-> Message (rule group)

New Rules:


 * 1:66939 <-> DISABLED <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt (os-windows.rules)
 * 1:66938 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66934 <-> DISABLED <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt (file-other.rules)
 * 1:66935 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66947 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt (os-windows.rules)
 * 1:66948 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt (os-windows.rules)
 * 1:66940 <-> DISABLED <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt (os-windows.rules)
 * 1:66941 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt (os-windows.rules)
 * 1:66942 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt (os-windows.rules)
 * 1:66943 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt (os-windows.rules)
 * 1:66944 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt (os-windows.rules)
 * 1:66945 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66946 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66900 <-> DISABLED <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt (policy-other.rules)
 * 1:66901 <-> ENABLED <-> SERVER-WEBAPP Langflow code validator remote code execution attempt (server-webapp.rules)
 * 1:66902 <-> DISABLED <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt (os-windows.rules)
 * 1:66903 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66904 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt (os-windows.rules)
 * 1:66905 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt (os-windows.rules)
 * 1:66906 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt (os-windows.rules)
 * 1:66907 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt (os-windows.rules)
 * 1:66908 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt (os-windows.rules)
 * 1:66909 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66910 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66911 <-> ENABLED <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt (server-webapp.rules)
 * 1:66912 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt (os-windows.rules)
 * 1:66913 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt (os-windows.rules)
 * 1:66914 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66915 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66916 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66917 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66918 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt (os-windows.rules)
 * 1:66919 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt (os-windows.rules)
 * 1:66920 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt (os-windows.rules)
 * 1:66921 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt (os-windows.rules)
 * 1:66922 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66923 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66924 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant download attempt (malware-cnc.rules)
 * 1:66925 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66926 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66927 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66928 <-> ENABLED <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection (malware-cnc.rules)
 * 1:66929 <-> DISABLED <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt (os-windows.rules)
 * 1:66930 <-> DISABLED <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt (os-windows.rules)
 * 1:66931 <-> DISABLED <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt (os-windows.rules)
 * 1:66932 <-> DISABLED <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt (os-windows.rules)
 * 1:66937 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt (os-windows.rules)
 * 1:66936 <-> DISABLED <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt (os-windows.rules)
 * 1:66933 <-> DISABLED <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt (file-other.rules)
 * 3:66949 <-> ENABLED <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt (server-webapp.rules)
 * 3:66950 <-> ENABLED <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt (server-webapp.rules)

Modified Rules:


 * 3:46897 <-> ENABLED <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt (server-webapp.rules)

2026-08-11 22:13:53 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.2.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:53 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.3.5.1.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:53 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.3.6.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:53 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.3.7.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:53 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.7.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:53 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.9.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.11.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.15.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.18.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.12.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.21.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.35.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.44.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.1.47.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.11.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt


2026-08-11 22:13:54 UTC

Snort Subscriber Rules Update

Date: 2026-08-10-001

This is the complete list of rules modified and added in the Cisco Talos Certified rule pack for Snort version 3.12.0.0.

The format of the file is:

gid:sid <-> Message

New Rules:

* 1:301589 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301590 <-> OS-WINDOWS Microsoft Windows Accessibility Infrastructure elevation of privilege attempt
* 1:301591 <-> OS-WINDOWS Microsoft Windows Cloud Files Mini Filter Driver elevation of privilege attempt
* 1:301592 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301593 <-> OS-WINDOWS Microsoft Windows Kerberos elevation of privilege attempt
* 1:301594 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301595 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301596 <-> OS-WINDOWS Microsoft Windows Program Compatibility Assistant Service elevation of privilege attempt
* 1:301597 <-> OS-WINDOWS Microsoft Windows Remote Access Connection Manager elevation of privilege attempt
* 1:301598 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301599 <-> OS-WINDOWS Microsoft Windows User-Mode Power Service elevation of privilege attempt
* 1:301600 <-> OS-WINDOWS Microsoft Windows HTTP.sys elevation of privilege attempt
* 1:301601 <-> OS-WINDOWS Microsoft Windows Kernel elevation of privilege attempt
* 1:301602 <-> OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt
* 1:301603 <-> OS-WINDOWS Microsoft Windows MIDI Service Module elevation of privilege attempt
* 1:301604 <-> OS-WINDOWS Microsoft Windows Microsoft Digest Authentication elevation of privilege attempt
* 1:301605 <-> OS-WINDOWS Microsoft Windows Storage elevation of privilege attempt
* 1:301606 <-> OS-WINDOWS Microsoft Windows Ancillary Function Driver for WinSock elevation of privilege attempt
* 1:301607 <-> OS-WINDOWS Microsoft Windows Desktop Window Manager elevation of privilege attempt
* 1:66900 <-> POLICY-OTHER KNX Association BCU KeyWrite request attempt
* 1:66901 <-> SERVER-WEBAPP Langflow code validator remote code execution attempt
* 1:66902 <-> OS-WINDOWS Windows Deployment Services TFTP remote code execution attempt
* 1:66911 <-> SERVER-WEBAPP fastjson AutoType remote code execution attempt
* 1:66924 <-> MALWARE-CNC Js.Phishing.JWR variant download attempt
* 1:66925 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66926 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66927 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66928 <-> MALWARE-CNC Js.Phishing.JWR variant outbound connection
* 1:66933 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 1:66934 <-> FILE-OTHER Schneider Electric IGSS Dashboard insecure deserialization attempt
* 3:66949 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt
* 3:66950 <-> SERVER-WEBAPP Cisco SD-WAN Manager cypher query language injection attempt

Modified Rules:

* 3:46897 <-> SERVER-WEBAPP Cisco Adaptive Security Appliance directory traversal attempt