Suricata Newsletter for September 2026
Welcome
Hello, and welcome to the September 2026 edition of the Suricata Newsletter!
Please consider subscribing to this newsletter by email. To do so, head on over to https://newsletter.suricata.io/ and enter your email address.
Message from OISF’s President, Kelley Misata
Earlier this month I had the chance to speak at Cybr.Sec.Con in Houston, and the message I brought is one I want to share here too: in open source, code is only half the battle. Everyone sees the releases, the features, the rules. What they don’t see is everything below the waterline that keeps a project like Suricata standing: licensing and legal oversight, governance, security audits, funding, and above all, people. This year at OISF we’ve lived every one of those, from writing a real AI contribution policy for Suricata to taking on new stewardship questions across our ecosystem. None of it shows up in a changelog, and all of it matters.
One line from the talk got more nods than any other: a download is not a relationship. Suricata runs in networks all over the world, but the organizations that make it possible are our consortium members. They fund the developers, the infrastructure, and the security work that everyone else relies on. To every one of our members, thank you. Your membership isn’t charity. It’s an investment in software your business depends on, and it pays off in every release.
That brings me to something new. Our membership pricing hasn’t changed since 2019, and in early 2027 we’ll be refreshing our consortium tiers, benefits, and pricing. We’re looking closely at what members value most, including closer engagement with our development team and more visibility into what’s coming. If your organization relies on Suricata and you’ve been meaning to get involved, now is a great time to talk. We offer multiyear terms that lock in current rates ahead of the refresh. Reach out to me directly.
You can see why this matters in this month’s releases. Suricata 8.0.7 fixes many security issues, and the Special Thanks list at the end of this newsletter is longer than ever: independent researchers, universities, government partners, and security teams. More reports mean more work for our team, because every one still gets reviewed by a human who knows this code. That’s what your investment supports.
Finally, Lisbon! The agenda is packed, training seats are almost gone, and the roadmap sessions are where Suricata’s future gets shaped. I can’t wait to see you all there in November.
SuriCon
- The SuriCon 2026 speakers and agenda have been published! We have 29 confirmed speakers, 36 talks (including lightning talks & sponsor spots), and so many good submissions that we extended each day by 30 minutes. Come be a part of it! :)
- Still don’t have a ticket for SuriCon in Lisbon? Go get one now at https://suricon.net!
- There is also still time to register for some awesome training. Pick one of the 3 options for this year and get a bundled discount. But don’t wait long, rooms are almost full!
- The Suricata Roadmap discussions will happen on Wednesday and Friday at SuriCon 2026. Come with your ideas and tickets prepared to share suggestions and feedback. ;)
Release Announcements
Over the last 3 months, Suricata 8.0.6 and 7.0.17 were released in July, and Suricata 8.0.7 in September. Suricata 8.0.7 fixes many security issues; please upgrade as soon as possible.
IMPORTANT: The Suricata 7.0 release branch is now end-of-life. No more releases will be made. Please upgrade to Suricata 8.0.7. Please see our EOL Policy for more details.
Recent Suricata and OISF Blog Posts
- Why Vectorscan Matters to Suricata – and Why We’re Supporting It
- Suricata keyword highlight: subslice, part 2 — transforms, the prefilter, and what’s next, by Jeff Lucovsky
Upcoming Events and Webinars
- October 16: Juliana Fajardini will be speaking at the 23rd Latinoware in Foz do Iguaçu, Brazil: Suricata 101: the Good, the Basic and the Packets. She’ll also attend all three days of the event, and bring stickers: go grab some!
- October 21: OISF’s Peter Manev and OISF board member Éric Leblond will be at Hack.lu, introducing HHAMMERRing the Noise: AI-Agentic Threat Hunting with Suricata and the Power of EVE Metadata
- October 22: Pre-SuriCon Webinar The Proof Is in the Packets: Working with an LLM to Triage Suricata Alerts with Zach Chadwick, from QA Cafe
Recent Webinars and Events
- DNS Did it! - with Suricata 8 and Peter Manev
- OISF’s Shivani was at IndiaFOSS last weekend; did you manage to find her for some swag?!
- OISF’s Peter Manev, Jeff Lucovsky, and Lukas Sismis attended hacker summer camp 2026. Congratulations to Lukas for winning the Telecom Village CTF at DEFCON 34!
The Suricata team at Black Hat Arsenal 2026.
In the Community
- OISF’s president, Kelley Misata, recently spoke at Cybr.Sec.Con in Houston, while no recording is available, Bill Brenner captured her message over at his blog:
- The Hunter’s Ledger ruleset has been added to the Suricata ruleset index!
- Congratulations to the Zeek team on the release of Zeek 9!
- Learn about Suricata at LinuxDays.cz in Prague on October 4:
- Riešenie kybernetických incidentov pomocou IDS Suricata (Handling Cybersecurity Incidents using Suricata IDS), with Ladislav Bačo
- Suriconf: konfigurační asistent Suricaty (Suriconf: a configuration assistant for Suricata), with Eliška Červinková
Special Thanks
Thank you to everyone involved in the recent Suricata releases!
Aaron Chen, Adam Kiripolsky, Alexander Stadnikov, Andreas Dolp, Antoine Abou Faysal, aramosf, Arthur Chan, Bin Luo (University of Electronic Science and Technology of China (UESTC)), Binbin Xu of Tencent YUNDING LAB CodeBuddy Security, Changcheng Wu of Clouditera, Chris Ramos, Denis Balashov, Feng Xue, Kevin Valerio and Quan Nguyen from Trail of Bits in collaboration with OpenAI, Kuniyoshi Noguchi (野口晋義), Lucas Ariel Sotomayor, Luukas Larinkoski, Maksim Hayder, Pim Sanders, Riyan Dhiman, Samaresh Kumar Singh, Shane Dugan, Stephen Donnelly, Urval Kheni, Yash Datre, Yazan Balawneh, Yazdan Soltani, z00xcv, Ada Logics in collaboration with Anthropic Research, Communications Security Establishment Canada (CSE), Corelight, Nozomi Networks Labs Advisory, Trail of Bits in collaboration with Anthropic, OSS-Fuzz, Coverity.