threat-intel China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade A China-linked threat actor, identified as Velvet Ant, has been discovered backdooring Linux login software for nearly a decade, gaining persistent access to a network with no direct internet connectivity. The group’s tactic involved modifying core system components like PAM and OpenSSH to silently record user credenti… The Hacker News · Jun 12, 2026 CVE-2024-20399