CyberHighSingle-sourceBuilding
6.9
JFrog Artifactory Flaws Exploited in Backdoor Campaign
SecurityWeekLO·about 10 hours ago
Threat actors tied to a China-aligned espionage group are exploiting CVE-2026-51990, a critical flaw in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor. The attack chain is active and targets specific users, though the full scope and victim profile remain unclear. This highlights the risk of supply-chain and software vulnerabilities in widely used Chinese applications.