US sanctions Chinese cybersecurity firm for firewall hacks targeting critical infrastructure


The U.S. sanctioned a Chinese cybersecurity company and one of its employees for exploiting a zero-day vulnerability in Sophos firewalls to target U.S. organizations.

On Tuesday, the U.S. Treasury Department said Guan Tianfeng, an employee of Sichuan Silence, used the vulnerability to compromise approximately 81,000 firewalls in April 2020. The hacking campaign, detailed by Sophos in November, led to the compromise of more than 23,000 firewalls in the U.S., dozens of which were used at a government agency, and critical infrastructure companies. One of these was an energy company involved in drilling operations. The Treasury noted that the incident could have caused “significant loss in human life” if the attack had been successful.

Read more…
Source: TechCrunch


Sign up for our Newsletter


Related:

  • Five Eyes governments get even tougher on encryption

    September 2, 2018

    “The governments of the United States, the United Kingdom, Canada, Australia, and New Zealand are committed to personal rights and privacy, and support the role of encryption in protecting those rights,” began a document agreed to last week. Sounds good. But wait. The government ministers who met on Australia’s Gold Coast last week went on to ...

  • DHS awards Booz Allen $1 billion cybersecurity contract

    August 21, 2018

    The Department of Homeland Security announced Tuesday it is awarding a $1.03 billion contract to Booz Allen Hamilton to boost cybersecurity vulnerability detection and mitigation in six federal agencies. Why it matters: Almost 75% of agencies are vulnerable to cyberattacks because they don’t understand their risk, the Office of Management and Budget found earlier this year. This is not Booz Allen’s first ...

  • ​China aims to narrow cyberwarfare gap with US

    August 17, 2018

    China is looking to narrow the gap with the US in terms of cyberwarfare capabilities, according to an assessment of Chinese military capabilities published by the Department of Defense (DoD). The Pentagon report said that in recent years the Chinese army has emphasized the importance of cyberspace for national security because of the country’s increasing reliance on ...

  • US voting systems: Full of holes, loaded with pop music, and ‘hacked’ by an 11-year-old

    August 13, 2018

    DEF CON Hackers of all ages have been investigating America’s voting machine tech, and the results weren’t great. For instance, one 11-year-old apparently managed to hack and alter a simulated Secretary of State election results webpage in 10 minutes. The Vote Hacking Village, one of the most packed-out locations at this year’s DEF CON hacking conference in Las ...

  • DOJ Nab Three FIN7 Cybercrime Suspects in Europe

    August 1, 2018

    Three people believed to be member of the FIN7 (or Carbanak) hacking group have been arrested in Europe, according to the US DOJ. Three suspected members of the FIN7 cybercrime group have been arrested in Europe and accused of hacking more than 120 U.S.-based companies with the intent of stealing bank cards. In total, U.S. Department of ...

  • New Homeland Security Center to Guard Against Cyberattacks

    July 31, 2018

      Homeland Security Secretary Kirstjen Nielsen says the growing cyber threat cannot be underestimated and government and the public must work together to battle it. Nielsen spoke at a cybersecurity summit Tuesday. She announced the creation of the National Risk Management Center at the department. It’s aimed at guarding energy companies, banks and other industries against cyberattacks. ...