Guan, associated with Sichuan Silence Information Technology Company, allegedly developed CVE-2020−12271, which allows remote code execution and data theft on Sophos firewalls.
The flaw was first reported to Sophos by researchers affiliated with Sichuan Silence’s Double Helix research institute, a day before it was used in actual attacks. Attackers used malware to leak sensitive data, including usernames and passwords, through firewalls.
The US Department of Justice indicted Guan and his associates, and the US Treasury Department imposed sanctions against them. The attack also affected critical infrastructure in the United States.
The United States is offering a reward of up to $10 million for information about him.
Source: Ferra

I am a professional journalist and content creator with extensive experience writing for news websites. I currently work as an author at Gadget Onus, where I specialize in covering hot news topics. My written pieces have been published on some of the biggest media outlets around the world, including The Guardian and BBC News.