Security Briefing | June 13, 2026 - Anthropic AI Models Restricted, 400+ Arch Linux Packages Hijacked, China-Linked Linux Backdoor Persists for a Decade
The U.S. government has ordered Anthropic to suspend access to its most advanced AI models for foreign nationals, marking a major development in AI export controls. At the same time, attackers compromised more than 400 Arch Linux AUR packages to distribute credential-stealing malware and an eBPF rootkit. In another significant discovery, security researchers uncovered a China-linked operation that maintained covert access to Linux systems for nearly a decade by backdooring PAM and OpenSSH authentication components.
By EACA Summit Content Team

1. U.S. Orders Anthropic to Suspend Fable 5 and Mythos 5 Access for Foreign Nationals
Anthropic has complied with a U.S. government directive requiring the company to restrict access to its Claude Fable 5 and Mythos 5 AI models for foreign nationals. The company disabled access globally while publicly disputing the rationale behind the order, arguing that the cited jailbreak technique is narrow in scope and that similar capabilities are already available elsewhere.
Verified Facts
- Anthropic received a U.S. government order at 5:21 p.m. ET on June 12, 2026
- The directive required suspension of access to Fable 5 and Mythos 5 for foreign nationals
- Anthropic disabled the models globally to comply with the order
- The company disputes the government's assessment of the associated risks
- The action was justified on national security grounds
Evidence
- Official Anthropic statement
- U.S. government directive
- Public statements regarding export control compliance
Impact
The decision establishes a significant precedent for AI export controls and could reshape how advanced AI systems are distributed internationally. Organizations, researchers, and developers outside the United States may face increasing restrictions on access to frontier AI technologies.
Confidence Level: High
The Hacker News | BleepingComputer | SecurityWeek
2. Over 400 Arch Linux AUR Packages Hijacked to Deploy Infostealer and eBPF Rootkit

Attackers compromised more than 400 packages within the Arch User Repository (AUR), modifying package build scripts to install a malicious Rust-based payload. The malware is designed to harvest credentials and authentication tokens from infected systems. When executed with elevated privileges, the malware also deploys an eBPF rootkit capable of concealing malicious activity and maintaining persistence.
Verified Facts
- More than 400 AUR packages were compromised
- Attackers modified package build scripts to distribute malware
- The malware consists of a credential-stealing Rust binary
- Access tokens and credentials are primary targets
- Systems running the malware as root may receive an eBPF rootkit
- The attack targeted the community-maintained AUR repository rather than official Arch Linux repositories
Evidence
- AUR package integrity investigations
- Security researcher malware analysis
- Package maintainer reports
Impact
This incident highlights the growing threat of software supply-chain attacks targeting open-source ecosystems. Developers and system administrators using affected packages may have exposed credentials, compromised development environments, and persistent malware infections.
Confidence Level: High
The Hacker News | BleepingComputer
3. China-Linked Hackers Backdoored Linux Login Software to Hide for Nearly a Decade
A China-linked threat group tracked as Velvet Ant maintained long-term access to compromised Linux environments by modifying core authentication components, including PAM and OpenSSH. According to security researchers, the attackers embedded their persistence mechanisms deep within the login process, enabling them to survive standard remediation efforts and remain undetected for nearly ten years.
Verified Facts
- The threat actor backdoored PAM and OpenSSH components
- The operation remained undetected for close to a decade
- Sygnia attributed the activity to a China-linked threat group known as Velvet Ant
- The attackers leveraged modified authentication software to maintain persistence
- Standard cleanup procedures failed to fully remove the backdoors
Evidence
- Sygnia threat intelligence report
- Forensic analysis of compromised Linux systems
- Authentication component modifications
Impact
The discovery demonstrates the effectiveness of long-term persistence techniques targeting core operating system authentication mechanisms. Organizations should review Linux authentication components for signs of tampering and conduct deeper forensic analysis following suspected compromises.
Confidence Level: High
All intelligence in this briefing is independently verified. Confidence levels reflect source reliability and corroboration at time of publishing.



