September 12, 2026
- China-linked UNC3569 exploited Sogou Input Method CVE-2026-51990 to install GRAYRABBIT. Gen Threat Labs traced a clicked link through three weaknesses:
sgbiz:argument injection, unrestricted navigation in a CEF webview, and an obsolete unsandboxed Chromium engine. The chain executed code with the logged-in user’s privileges. Tencent patched it within 12 days of the report. · Vulnerabilities & Active Exploitation
in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack