FeedExploreAsk AIAlertsSavedProfile

Categories

AICybersecurityInfrastructureDatabaseTech Updates

Tech news that matters.

FeedExploreAskAlertsSavedProfile
Back to feed
Cybersecurity·CriticalBreaking

Hackers Hid Inside Linux Login Tools for a Decade

A security analyst examines code on a computer screen in a data center control room.

TL;DR: A China-linked hacking group hid for nearly a decade by backdooring core Linux login tools. This gave them persistent access that was extremely difficult to detect and remove, bypassing typical security measures.

By Neeraj Dhiman·3h ago·2 min read·updated 1h ago
Source

Key facts

Category
Cybersecurity
Impact
Critical
Published
3h ago
Source
The Hacker News

Full summary

A China-linked group hid for nearly a decade inside the Linux login system itself, backdooring core components to maintain persistent, stealthy access.

A sophisticated, China-linked hacking group hid on target networks for nearly a decade by modifying fundamental login software on Linux systems. The group, tracked by security firm Sygnia as Velvet Ant, created backdoors directly inside Pluggable Authentication Modules (PAM) and the widely used OpenSSH software. These components are the gatekeepers for Linux, managing who can sign in and how they connect securely. By altering this core code, the attackers built a hidden entry point into the system that was deeply embedded in the trusted authentication process, allowing them to operate undetected.

This method of compromise is exceptionally dangerous because it is both stealthy and persistent. Modifying core system files means the backdoor becomes part of the operating system's normal functions and can survive reboots, file cleanups, and even some system updates. For security teams and system administrators, this type of attack is a nightmare scenario. It evades detection from tools that scan for suspicious files, as the backdoor’s activity can be disguised as legitimate login traffic. The attack highlights a critical vulnerability for any organization that relies on Linux infrastructure, forcing a re-evaluation of how to trust core system components.

The discovery of Velvet Ant's tactics serves as a stark reminder of the advanced capabilities employed by nation-state actors. These groups invest significant resources to create intrusions that are nearly impossible to find. For developers, CTOs, and IT teams, the incident underscores the importance of file integrity monitoring and behavioral analysis. It is no longer enough to simply scan for known malware. Organizations must now consider how to verify that the fundamental building blocks of their operating systems have not been tampered with. This attack proves that even the most trusted software can be turned into a hidden weapon.

Related on Notifire

  • ResearchKubernetes security
  • ResearchSupply-chain security
  • ResearchCritical CVEs of 2026
  • CompareSSO vs SCIM

✦ Notifire newsletter

Get more Cybersecurity intelligence

Join engineers getting Notifire’s verified tech briefings — short, sourced, and free. No spam, unsubscribe anytime.

The day's most important tech briefings. No spam, unsubscribe anytime.

Primary source: The Hacker News

Tech intelligence for engineering teams

Short, verified briefings on AI, cybersecurity, infrastructure, and data — with the analysis and action steps that matter. Every briefing is sourced, fact-checked, and bylined to a named editor.

[email protected]Story tips & corrections welcomeHow we report →

The Notifire briefing

Verified tech intelligence in your inbox — AI, security, infra, and data.

The day's most important tech briefings. No spam, unsubscribe anytime.

Sections

  • AI
  • Cybersecurity
  • Infrastructure
  • Database
  • Tech Updates
  • Web3 & Chains

Newsroom

  • About Notifire
  • Editorial team
  • Editorial standards
  • Methodology
  • AI disclosure
  • Corrections

Resources

  • Explore
  • Research hubs
  • Comparisons
  • Tech glossary
  • FAQ
  • Alerts & watchlists

Follow

  • RSS feed
© 2026 NotifirePrivacyTermsCorrections
An independent, AI-assisted publication. Built at </Alpheric>
IntelligenceLive panel
Live

Top trending

Last 24h

    Popular tags

    Add to watchlist

    +OpenAI+Claude+PostgreSQL+Kubernetes+Cloudflare+AWS+CVE Critical

    Notifire score

    0–100 priority signal — combines impact, freshness, trending velocity, and source credibility.

  1. Atom feed
  2. LinkedIn
  3. X / Twitter
  4. Facebook
  5. Instagram
  6. YouTube