Skip to main content
Security

Gen Digital ties China-linked UNC3569 to Sogou input flaw used to plant GRAYRABBIT backdoor

Gen Digital ties China-linked UNC3569 to Sogou input flaw used to plant GRAYRABBIT backdoor Image: Primary
Gen Digital said a China-linked group it calls UNC3569 exploited a flaw in Tencent's Sogou Input Method for Windows to install the GRAYRABBIT backdoor, which gives attackers a remote command shell and can load additional modules. Gen reported the flaw to Tencent on April 9, 2026, and Tencent confirmed a fix that went out by automatic update on April 21, tracked as CVE-2026-51990. The fix hardens the link handler that launched Sogou components, but Gen found the bundled Chromium engine and its disabled sandbox unchanged. Tencent disputed the chain's simplicity, saying social engineering would be needed.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Policy
Security Policy

Florida confirms DMV driver database breach via stolen police credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed that its DAVID driver database was breached after the ShinyHunters extortion gang claimed to have compromised the system. The agency said it learned of the bre...

Security
Security

Wiz reports Artifactory flaw chain exploited to plant Rust backdoor

Wiz says multiple threat actors chained two JFrog Artifactory vulnerabilities, CVE-2026-42018 and CVE-2026-42016, against self-hosted servers between August 15 and September 8, 2026, obtaining an internal anonymous-user JWT and ex...

Security Infrastructure
Security Infrastructure

GitLab patches maximum-severity file-read flaw as probes hit exposed servers

GitLab released patches for a maximum-severity path traversal flaw in its repository commits API that lets an unauthenticated attacker read arbitrary files from a GitLab server under certain conditions, the company said. The vuln...