<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>tamper detection &#8211; Noise</title>
	<atom:link href="https://noise.getoto.net/tag/tamper-detection/feed/" rel="self" type="application/rss+xml" />
	<link>https://noise.getoto.net</link>
	<description>The collective thoughts of the interwebz</description>
	<lastBuildDate>Wed, 03 Feb 2021 03:54:01 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.8.2</generator>
	<item>
		<title>More SolarWinds News</title>
		<link>https://noise.getoto.net/2021/02/03/more-solarwinds-news/</link>
		
		<dc:creator><![CDATA[Bruce Schneier]]></dc:creator>
		<pubDate>Wed, 03 Feb 2021 12:10:45 +0000</pubDate>
				<category><![CDATA[attribution]]></category>
		<category><![CDATA[Forensics]]></category>
		<category><![CDATA[hacking]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[russia]]></category>
		<category><![CDATA[tamper detection]]></category>
		<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.schneier.com/?p=61881</guid>

					<description><![CDATA[<p>Microsoft <a href="https://www.zdnet.com/article/microsoft-this-is-how-the-sneaky-solarwinds-hackers-hid-their-onward-attacks-for-so-long/">analyzed details</a> of the SolarWinds attack:</p>
<blockquote><p>Microsoft and FireEye only detected the <a href="https://www.fireeye.com/blog/threat-research/2020/12/sunburst-additional-technical-details.html">Sunburst</a> or <a href="https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/">Solorigate</a> malware in December, but <a href="https://www.zdnet.com/article/third-malware-strain-discovered-in-solarwinds-supply-chain-attack/">Crowdstrike reported this month that another related piece of malware, Sunspot</a>, was deployed in September 2019, at the time hackers breached SolarWinds’ internal network. Other related malware includes <a href="https://www.zdnet.com/article/fireeye-releases-tool-for-auditing-networks-for-techniques-used-by-solarwinds-hackers/">Teardrop</a> aka <a href="https://www.zdnet.com/article/fourth-malware-strain-discovered-in-solarwinds-incident/">Raindrop</a>.</p></blockquote>
<p><a href="https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/">Details</a> are in the Microsoft blog:</p>
<blockquote><p>We have published our in-depth analysis of the <a href="https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect/">Solorigate backdoor malware</a> (also referred to as <a href="https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html">SUNBURST</a> by FireEye), the compromised DLL that was deployed on networks as part of SolarWinds products, that allowed attackers to gain backdoor access to affected devices. We have also detailed the ...</p></blockquote>]]></description>
		
		
		<enclosure url="" length="0" type="" />

			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/

Object Caching 31/51 objects using Memcached
Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Database Caching using Memcached

Served from: noise.getoto.net @ 2025-12-09 01:08:05 by W3 Total Cache
-->