Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chinese Hackers Exploit Sogou Input Flaw for Attack

Chinese Hackers Exploit Sogou Input Flaw for Attack

Posted on September 14, 2026 By CWS

A recent cybersecurity breach has been identified involving a severe vulnerability in the Sogou Input Method, according to Gen Threat Labs. The flaw, exploited by a Chinese threat group, allowed for the deployment of a backdoor, raising significant security concerns.

Sogou Input Method Vulnerability

Developed by Tencent, the Sogou Input Method serves as a widely-used Chinese-language input method editor for Windows. With a user base numbering in the hundreds of millions, any vulnerabilities in this software could have extensive implications. The software employs a set of executables that communicate via a custom protocol known as sgbiz, which is vulnerable to exploitation.

The vulnerability, designated as CVE-2026-51990, involves a complex exploit that combines three key weaknesses: improper validation of command-line arguments, unrestricted navigation of URLs, and reliance on an outdated Chromium browser engine lacking necessary security features.

Exploitation Methodology

Gen Threat Labs highlighted that the primary issue arises during the URL parsing process, where the protocol handler fails to validate the ‘param’ parameter. This oversight permits attackers to inject command-line arguments, redirecting the system to a malicious ‘skincenter’ page without user knowledge.

Furthermore, the Sogou Input Method’s browser, based on an outdated version of Chromium, exacerbates the risk. This outdated browser lacks six years’ worth of security updates, leaving it vulnerable to multiple threats, including unauthorized local file access.

Implications and Response

The Chinese-linked group UNC3569 has been identified as the exploit’s primary user, utilizing crafted sgbiz URLs to trick victims into executing malicious code. This exploit chain enabled the deployment of the GrayRabbit backdoor, facilitating unauthorized system access and data control.

Gen Threat Labs reported the vulnerability to Tencent on April 9, prompting a fix in the form of an updated Sogou Input Method version 16.3.0.3498. This update addressed the protocol handler issues but did not upgrade the underlying Chromium configuration, leaving some security concerns unresolved.

The persistence of these vulnerabilities underscores the need for continued vigilance and timely software updates to safeguard against similar threats in the future.

Security Week News Tags:Backdoor, Chinese hackers, Chromium, CVE-2026-51990, Cybersecurity, Gen Threat Labs, GRAYRABBIT, Sogou Input Method, Tencent, UNC3569, Vulnerability

Post navigation

Previous Post: Casbaneiro Trojan Targets Latin American Banks
Next Post: Cybercriminals Exploit AI to Steal Android App Secrets

Related Posts

Fortra Patches Critical GoAnywhere MFT Vulnerability Fortra Patches Critical GoAnywhere MFT Vulnerability Security Week News
Ransomware Groups May Shift Back to Encryption Strategies Ransomware Groups May Shift Back to Encryption Strategies Security Week News
President Trump Orders Divestment in .9 Million Chips Deal to Protect US Security Interests President Trump Orders Divestment in $2.9 Million Chips Deal to Protect US Security Interests Security Week News
Minnesota Water Systems Targeted by Cyberattacks Amid Iranian Hacker Concerns Minnesota Water Systems Targeted by Cyberattacks Amid Iranian Hacker Concerns Security Week News
Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries Chinese Hacking Group ‘Earth Lamia’ Targets Multiple Industries Security Week News
Inti De Ceukelaire: Crafting Ethical Hacks Inti De Ceukelaire: Crafting Ethical Hacks Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Microsoft Warns of Remote Desktop Issues After Security Update
  • Revolut Data Breach Exposes User Information
  • AI’s Role in Evolving Cybersecurity Validation
  • Cybercriminals Exploit AI to Steal Android App Secrets
  • Chinese Hackers Exploit Sogou Input Flaw for Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Microsoft Warns of Remote Desktop Issues After Security Update
  • Revolut Data Breach Exposes User Information
  • AI’s Role in Evolving Cybersecurity Validation
  • Cybercriminals Exploit AI to Steal Android App Secrets
  • Chinese Hackers Exploit Sogou Input Flaw for Attack

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark