Hackers exploit Tencent app flaw to deploy GrayRabbit malware

2026-09-13T19:23:22Z•247983e572b126af1a9fdbb70bd9581429142b78c12548a0d4f8fb639ad744c3
CVE-2026-51990CVE-2026-85102CVE-2026-85103CVE-2026-85706AI abuseAndroid malwareChina-aligned espionageContiGitLabGrayRabbitJFrog ArtifactoryMantax OtaxMicrosoft 365ShinyHuntersVPN securityactive exploitationbackdoorcredential theftcritical vulnerabilitiesdata breachpatch managementphishingransomwaresupply chainzero-day

What happened

BleepingComputer security feed covering active exploitation of critical vulnerabilities, ransomware and malware campaigns, phishing-led account compromise, data breaches, AI platform abuse, and significant software update disruptions. The highest-priority items include exploitation of Tencent Sogou Input Method, imminent exploitation of Check Point VPN flaws, Artifactory authentication bypass and privilege escalation chains, and a maximum-severity GitLab path traversal vulnerability.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
247983e572b126af1a9fdbb70bd9581429142b78c12548a0d4f8fb639ad744c3
Enrichment time
2026-09-13T19:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers exploit Tencent app flaw to deploy GrayRabbit malware · Baitaphish