US sanctions Chinese cybersecurity firm for firewall hacks targeting critical infrastructure


The U.S. sanctioned a Chinese cybersecurity company and one of its employees for exploiting a zero-day vulnerability in Sophos firewalls to target U.S. organizations.

On Tuesday, the U.S. Treasury Department said Guan Tianfeng, an employee of Sichuan Silence, used the vulnerability to compromise approximately 81,000 firewalls in April 2020. The hacking campaign, detailed by Sophos in November, led to the compromise of more than 23,000 firewalls in the U.S., dozens of which were used at a government agency, and critical infrastructure companies. One of these was an energy company involved in drilling operations. The Treasury noted that the incident could have caused “significant loss in human life” if the attack had been successful.

Read more…
Source: TechCrunch


Sign up for our Newsletter


Related:

  • Health insurance firm Blue Shield data breach exposed data of over 4.7 million members

    April 24, 2025

    Health insurance firm Blue Shield has revealed a data breach has exposed protected health data of over 4.7 million members. The information was leaked to Google’s analytics and advertisement platforms following a misconfiguration of Google analytics on Blue Shield sites. “On February 11, 2025, Blue Shield discovered that, between April 2021 and January 2024, Google Analytics ...

  • CISA, DHS S&T, INL, LSU Help Energy Industry Partners Strengthen Incident Response and OT Cybersecurity

    April 23, 2025

    The Cybersecurity and Infrastructure Security Agency (CISA), Department of Homeland Security (DHS) Science and Technology Directorate (S&T) and the Idaho National Laboratory (INL) hosted Louisiana State University (LSU) and several energy industry and critical infrastructure partners to train against simulated, high-impact cyberattacks on operational technology (OT) and traditional information technology (IT) at CISA’s Control Environment ...

  • FOG Ransomware Spread by Cybercriminals Claiming Ties to DOGE

    April 21, 2025

    During trend Micro researchers monitoring of the ransomware threat landscape, they discovered samples with infection chain characteristics and payloads that can be attributed to FOG ransomware. A total of nine samples were uploaded to VirusTotal between March 27 and April 2, which the researchers recently discovered were multiple ransomware binaries with .flocked extension and readme.txt notes. ...

  • Two Pentagon officials fired amid sweeping leak investigation

    April 20, 2025

    The week of turmoil affecting the Pentagon’s inner circle continued Friday, when two political appointees suspended earlier this week were terminated, multiple officials told CBS News. Secretary of Defense Pete Hegseth’s chief of staff, Joe Kasper, ordered an investigation into unauthorized disclosures in March. His memo said the investigation would seek “a complete record” of leaks ...

  • FBI Warns of Scammers Impersonating the IC3

    April 18, 2025

    The Federal Bureau of Investigation (FBI) warns the public about an ongoing fraud scheme where criminal scammers are impersonating FBI Internet Crime Complaint Center (IC3) employees to deceive and defraud individuals. Between December 2023 and February 2025, the FBI received more than 100 reports of IC3 impersonation scams. How It Works Complainants report initial contact from the ...

  • Over 1.6 million customers now hit in massive insurance data breach

    April 17, 2025

    More than 1.6 million people are now thought to have been affected by the May 2024 cyberattack at Landmark Admin, twice as many as originally thought. The company confirmed the news in an updated report filed with the Office of the Maine Attorney General. “The forensic investigation determined that data was encrypted and exfiltrated from Landmark’s ...