China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor
China-linked threat actors tracked as UNC3569 have exploited a critical one-click remote code execution vulnerability in Tencentβs Sogou Input Method for Windows to deploy the GRAYRABBIT backdoor on targeted systems. Tracked as CVE-2026-51990, the vulnerability chains an insecure custom protocol handler, unrestricted embedded-browser navigation, and an obsolete Chromium build running without sandbox protections. Tencent addressed [β¦]
The post China-Linked Hackers Exploit Sogou One-Click RCE to Deploy GRAYRABBIT Backdoor appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
