VLC opening suspicious PNG from untrusted source (CVE-2026-56711)

This rule detects potential exploitation attempts targeting VLC media player, specifically focusing on the CVE-2026-56711 integer overflow vulnerability. The rule identifies instances where VLC processes a PNG file originating from untrusted locations (such as Downloads, Temp, or removable media) shortly after that file was created or modified on the host.