YARA-X 1.14.0 Release, (Sat, Mar 7th)

2026-03-08T19:23:48Z4a4dc6d068b340d9cffe63aaaa356f0c244b047fb129499bedd1b22b9c9e9b10
CrushFTPRTFWiresharkXWormYARA-XZIPbrute-forceexploitmalwarepatchsecurity-updatevulnerability

What happened

SANS ISC diary roundup: YARA-X 1.14.0 released with four improvements and two bug fixes. Wireshark 4.6.4 released, addressing three vulnerabilities and multiple bugs. Reports of brute-force scanning targeting CrushFTP instances; the entry calls out a history of serious CrushFTP vulnerabilities (including CVE-2024-4040, CVE-2025-31161) and the July 2025 zero-day CVE-2025-54309 which was actively exploited. A new wave of XWorm multi-technology malware activity was observed. There are also brief how‑tos (e.g., extracting ZIP files embedded in RTF). Overall, multiple actively exploited or high‑con

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
4a4dc6d068b340d9cffe63aaaa356f0c244b047fb129499bedd1b22b9c9e9b10
Enrichment time
2026-03-08T19:23:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.