[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fLmUudJp2Yd3UHeHTwq1_Op-kOFS7UqFUKYXYgsX4Xbs":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"3b4cdf50-446f-46c8-9555-a3c19a2b71f1","china-linked-group-maintains-decade-long-access-through-backdoored-linux-login-components","7789d580-7ce2-4005-81a4-552c49359b93","China-Linked Group Maintains Decade-Long Access Through Backdoored Linux Login Components","The Velvet Ant threat group successfully compromised PAM and OpenSSH components on Linux systems, creating backdoors that logged credentials and commands while remaining undetected for nearly a decade. This supply chain attack demonstrates how adversaries can modify trusted system components to bypass traditional security controls and maintain persistent access. The incident highlights critical gaps in software integrity verification and system monitoring that allowed such extensive compromise to go unnoticed for years.","**Immediate actions:**\n- Implement file integrity monitoring on critical system components like PAM and SSH\n- Verify cryptographic signatures and checksums of all installed system software\n- Audit recent logins and system access patterns for anomalies\n\n**Long-term improvements:**\n- Deploy endpoint detection and response (EDR) solutions with behavioral monitoring\n- Establish software supply chain security controls including trusted repositories\n- Create baseline configurations for critical system components with regular validation\n\n**Detection measures:**\n- Enable comprehensive logging of authentication events and command execution\n- Implement network monitoring to detect unusual outbound connections from compromised systems\n- Schedule regular integrity checks of core system binaries and libraries",[12,13,14,15,16,17],"CIS Control 2","CIS Control 8","NIST SI-7","NIST AU-6","NIST SA-12","ISO 27001 A.12.6.1","published","2026-06-12T20:21:10.492852+00:00","2026-06-12T20:21:10.409+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fchina-linked-hackers-backdoored-linux.html","china-linked-hackers-backdoored-linux-login-software-to-hide-for-nearly-a-decade-5dff80","China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1732a005-556e-411c-a9db-5edec3058571","Logging & Monitoring","logging-monitoring","Missing logs, no alerting, blind spots","#a855f7",{"id":33,"name":34,"slug":35,"description":36,"color":37},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[39],{"id":40,"date":41,"edition":42,"title":43,"audio_url":44},"1dbc6cb7-d7db-4a2e-ac11-7b23eec195cb","2026-06-13","morning","ThreatNoir Weekend Brief — June 13","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-06-13\u002Fthreatnoir-morning-brief-2026-06-13.mp3"]