[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fu0zcPiPieN6uKd_0tZyjkFWHtVBr7EwE7jsivr6rRC0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"fca33668-06df-47ba-a9f5-be07384264df","authentication-hijacking-enables-decade-long-espionage-in-air-gapped-network","ac324024-5644-4e19-9922-0cb8cd689c06","Authentication Hijacking Enables Decade-Long Espionage in Air-Gapped Network","The Velvet Ant group successfully compromised critical infrastructure by first breaching internet-facing systems, then pivoting to an isolated air-gapped network where they maintained access for over a decade. The attackers hijacked the authentication infrastructure by deploying backdoored PAM modules and trojanized OpenSSH components, allowing them to steal credentials and maintain persistent access. This demonstrates that air-gapped networks are not immune to sophisticated attackers who can establish initial footholds through connected systems and compromise core authentication mechanisms.","**Immediate actions:**\n- Audit all PAM modules and SSH components for unauthorized modifications or backdoors\n- Implement multi-factor authentication across all critical systems, especially for privileged accounts\n- Review and harden authentication flows with additional integrity checks\n\n**Long-term improvements:**\n- Establish strict network segmentation with monitoring at all transition points between networks\n- Deploy privileged access management solutions with session recording and behavioral analysis\n- Implement zero-trust architecture principles even within air-gapped environments\n\n**Detection measures:**\n- Monitor authentication logs for anomalous login patterns and credential usage\n- Deploy file integrity monitoring on critical authentication components and system binaries\n- Establish baseline behaviors for privileged account usage and alert on deviations",[12,13,14,15,16,17,18,19],"CIS Control 5","CIS Control 12","NIST AC-2","NIST AC-6","NIST SC-7","NIST AU-2","ISO 27001 A.9.2.1","ISO 27001 A.13.1.3","published","2026-06-13T16:20:44.545411+00:00","2026-06-13T16:20:44.449+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fchinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade\u002F","chinese-hackers-hijack-auth-flow-spy-on-isolated-network-for-a-decade-6e0d58","Chinese hackers hijack auth flow, spy on isolated network for a decade",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":35,"name":36,"slug":37,"description":38,"color":39},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[41],{"id":42,"date":43,"edition":44,"title":45,"audio_url":46},"b78eb2f3-f24b-43c6-a61d-10fa0473b28c","2026-06-14","morning","ThreatNoir Weekend Brief — June 14","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-14\u002Fthreatnoir-morning-brief-2026-06-14.mp3"]