USN-8766-1: Suricata-Update vulnerability
Ubuntu patches Suricata-Update path validation flaw allowing arbitrary file writes outside the rules directory from malicious rule archives.
Ubuntu security notice USN-8766-1 fixes a Suricata-Update vulnerability discovered by Guillem Lefait. The tool did not properly validate destination paths when extracting files referenced by downloaded rule archives, allowing an attacker to write arbitrary files outside the configured rules directory. Users are advised to update the suricata-update package.
When Agents Look Like Beacons: NIDS Evasion by Model Context Protocol Traffic
Research shows Model Context Protocol agent traffic structurally resembles C2 beaconing and evades Suricata signatures and RITA behavioral scoring in testbeds.
An arXiv study demonstrates that Model Context Protocol (MCP) JSON-RPC traffic over Streamable HTTP mimics the polling patterns of C2 frameworks like Cobalt Strike and is not flagged as anomalous by standard enterprise defenses. In a Docker testbed with eleven traffic profiles across three TLS conditions, Suricata with the Emerging Threats Open ruleset produced near-zero alerts and RITA assigned a consistent 0.0 beacon score, regardless of jitter or TLS inspection. The authors propose an agent-native network indication standard using Agent-Native ALPN and out-of-band headers.