Threat Brief — 2026-09-13 — Sogou Input Method Exploitation Continues
Executive Summary
The only fresh finding in the last four hours is additional coverage of the China-aligned UNC3569 group exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. This story was first reported on 2026-09-11 by The Hacker News and has not advanced with new technical details since then. BleepingComputer's article appears to be an independent write-up of the same campaign and vulnerability rather than a new development.
Top items
- UNC3569 exploits CVE-2026-51990 in Tencent Sogou Input Method to deploy GrayRabbit backdoor. A China-aligned espionage group is exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deliver the GrayRabbit backdoor. This story was first reported on 2026-09-11 (src: The Hacker News); today's BleepingComputer article covers the same campaign without new technical developments (src: BleepingComputer).
Themes
No new cross-cutting themes emerged in this reporting window. The Sogou/GrayRabbit story is consistent with the broader pattern observed over the past two weeks of China-aligned actors abusing trusted consumer software as an initial-access vector.
