Security
Velvet Ant Spent a Decade Inside an Air-Gapped Network by Subverting Authentication
Sygnia's 'Operation Highland' investigation reveals how Velvet Ant chained Nginx proxy modifications and a FastCGI execution bridge to reach an isolated network, then replaced PAM and OpenSSH binaries to harvest credentials and observe every administrative session.