
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors are exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. The vulnerability, reported as CVE-2026-51990, is being exploited by actors linked to a China-aligned espionage group. Successful exploitation may result in unauthorized access and control of affected systems. As of the report, specific patch details and the full exploitation vector have not been disclosed. Users are advised to update Sogou Input Method to the latest version and monitor official Tencent security advisories.
