Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNC3569 Sogou Input Method exploitation campaign

Campaign
First reported
Last updated
Happening score
H score 89
1 unique sources, 1 articles

Summary

Hide ▲

The UNC3569 campaign abused a crafted sgbiz: link to exploit Sogou Input Method on Windows, giving the operator code execution and a foothold for the GRAYRABBIT backdoor. The chain let the attacker act with the logged-in user's privileges, turning a link click into remote access. Gen Digital linked the activity to a live intrusion and said UNC3569 has targeted government, education, technology, and finance sectors in East and Southeast Asia since 2021. Tencent fixed the flaw in April 2026 and pushed version 16.3.0.3498 to close the link-handler path.

Cases

Related Happenings

Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)

Vulnerability
H score89 First: 11.09.2026 10:14 Last: 11.09.2026 10:14 Sources 1

How related: Gen reported the flaw to Tencent on April 9, 2026, and it is tracked as CVE-2026-51990. Tencent replied the next day and confirmed on April 21 that a fix was complete and would go out to all users via an automatic update in version 16.3.0.3498.

About this happening: Sogou Input Method on Windows had a link-handler flaw in the `sgbiz:` path that let attacker-controlled arguments and browser navigation reach code execution under the...

GRAYRABBIT backdoor deployment via Sogou Input Method exploit

Malware Activity
H score89 First: 11.09.2026 10:14 Last: 11.09.2026 10:14 Sources 1

How related: The backdoor it installed is GRAYRABBIT, a small program the group has used for years and that Google describes as its first step onto a machine. It gives an attacker a remote command shell, allows files to be moved in both directions, and can load additional modules from the attacker's server at any time.

About this happening: The GRAYRABBIT backdoor was deployed in a live intrusion against Sogou Input Method users, giving attackers a remote command shell and the ability to stage additional...

Atlassian Rovo Chat rovoChatPrompt prompt-injection security flaw

Vulnerability
H score1 First: 08.08.2026 11:54 Last: 08.08.2026 11:54 Sources 1

About this happening: The Atlassian Rovo Chat rovoChatPrompt vulnerability let attacker-supplied instructions preload into the assistant and exfiltrate Jira, Confluence, and connected-a...

ClickLock ClickFix macOS targeting campaign

Campaign
H score33 First: 16.07.2026 15:33 Last: 16.07.2026 15:33 Sources 1

About this happening: Group-IB reported a ClickLock macOS campaign that uses ClickFix paste-a-command lures and coercive app-killing loops to force victims to enter their system login...

UniFi OS Server unauthenticated root RCE chain (multiple vulnerabilities)

Vulnerability
H score25 First: 08.06.2026 18:51 Last: 08.06.2026 18:51 Sources 1

About this happening: UniFi OS Server is exposed to an unauthenticated root RCE chain that combines CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910, putting versions 5.0.6 and...

Latest development: 24.06.2026 15:32

CISA added CVE-2026-34908, CVE-2026-34909, and CVE-2026-34910 to the Known Exploited Vulnerabilities (KEV) catalog after warnings that threat actors were targeting UniFi OS Server devices and multiple users reported in-the-wild exploitation that created rogue administrator accounts named 'John Sim' on affected Ubiquiti systems.

Timeline

  1. 11.09.2026 03:00 2 articles · 9h ago

    UNC3569 uses crafted sgbiz: link to deploy GRAYRABBIT

    Technical Analysis Update

    Gen Digital published research on September 11, 2026 describing a China-linked UNC3569 intrusion that used a crafted sgbiz: link against Sogou Input Method on Windows to install the GRAYRABBIT backdoor and execute code with the logged-in user's privileges.

    Show sources