[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f8Lw18ZdsPdC333kZc9EmKiD8403kf_MGPK228Kv8464":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"f778a00a-474b-4956-bb93-d2e14ebcf08d","unpatched-tencent-sogou-flaw-exploited-to-deploy-grayrabbit-backdoor","46ae7fdb-374b-4ff6-b92f-a75a22927dca","Unpatched Tencent Sogou Flaw Exploited to Deploy GrayRabbit Backdoor","UNC3569, a China-aligned threat actor, is actively exploiting CVE-2026-51990, a critical one-click remote code execution vulnerability in Tencent's Sogou Input Method for Windows. The attack chains multiple weaknesses — including a vulnerable protocol handler, webview component, and an outdated Chromium engine — to deploy the GrayRabbit backdoor without meaningful user interaction. This highlights the compounding risk of shipping software with embedded, outdated third-party engines that expand the attack surface far beyond what organizations typically track. The incident underscores that widely deployed productivity and input tools are increasingly targeted as soft entry points into enterprise environments, and that delayed patching of non-obvious software creates critical blind spots in vulnerability programs.","**Immediate actions:**\n- Apply the latest Tencent Sogou Input Method patch or remove the application from enterprise endpoints until a fix is confirmed safe.\n- Run an authenticated vulnerability scan across all endpoints to identify instances of outdated Chromium-based embedded engines in third-party applications.\n- Block or restrict custom protocol handlers (URI schemes) associated with Sogou Input Method at the endpoint and network perimeter until patched.\n\n**Long-term improvements:**\n- Maintain a comprehensive Software Bill of Materials (SBOM) to track embedded third-party libraries and engines (e.g., Chromium) across all deployed applications.\n- Establish a formal patch prioritization process that includes non-traditional software such as input methods, utilities, and productivity tools — not just OS and browsers.\n- Enforce application allowlisting policies to limit execution of unexpected binaries spawned by input method or webview processes.\n\n**Detection measures:**\n- Deploy EDR rules to alert on suspicious child processes spawned by input method applications or embedded webview components.\n- Monitor network traffic for C2 communication patterns associated with GrayRabbit backdoor indicators of compromise (IoCs).\n- Enable enhanced logging for protocol handler invocations and webview activity on endpoints to support rapid forensic investigation.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","CIS Control 10: Malware Defenses","CIS Control 13: Network Monitoring and Defense","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST SI-2: Flaw Remediation","NIST SA-12: Supply Chain Risk Management","NIST CM-7: Least Functionality (restrict protocol handlers)","MITRE ATT&CK T1203: Exploitation for Client Execution","MITRE ATT&CK T1071: Application Layer Protocol (C2)","ITIL: Change and Release Management (emergency patch procedures)","published","2026-09-13T16:20:19.994939+00:00","2026-09-13T16:20:19.871+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware\u002F","hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware-b2a972","Hackers exploit Tencent app flaw to deploy GrayRabbit malware",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[50],{"id":51,"date":52,"edition":53,"title":54,"audio_url":55},"42d94a5f-ed53-45bb-a488-044c82b7320f","2026-09-14","morning","ThreatNoir Morning Brief — September 14","https:\u002F\u002Fcdn.threatnoir.com\u002Fpodcasts\u002F2026-09-14\u002Fthreatnoir-morning-brief-2026-09-14.mp3"]