I've had quite a lot ssh bruteforce attacks on my server(Arch Linux).
I recently checked the auth log in which I found one suspicous entry (but no sucessful login by anyone that wasn't me):
passwd[#####]: password for 'polkitd' changed by 'root'
I am quite confident that I didn't change it myself as I'm not using polkit. But I think that i ran a pacman -Syu that day. Also polkitd is not running and no process sarted by the polkit user is running. Could it be that pacman was responsible for that?