So this story has been floating around for a while, but if you haven't heard already several Red Hat servers, including some used for Fedora, were compromised in the last couple of weeks. Details were slow in emerging, but Red Hat has finally confirmed that some OpenSSH packages for Red Hat Enterprise (RHEL) 4 and 5 could have been compromised. Full details, including how to detect bad packages and updates, can be found at http://www.redhat.com/security/data/openssh-blacklist.html. The full Red Hat advisory can be found at https://rhn.redhat.com/errata/RHSA-2008-0855.html.