As cited
Copy frozen at (site build).
vulnerabilities
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors associated with a China-aligned espionage group are actively exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to install the GrayRabbit backdoor. The flaw provides a direct path to compromise systems running the widely deployed input tool.
Why it matters: Organizations with Sogou Input Method deployed in Windows environments face immediate risk of backdoor installation and potential data exfiltration by state-sponsored actors; patching CVE-2026-51990 is urgent.
- Source published
- First seen by Cybersecurity Tracker