Hackers exploit Tencent app flaw to deploy GrayRabbit malware

2026-09-14T01:23:23Z•745177a28d706ea3f7c54fb697abc0b1ae9d08e2c9e05ebe62ba2142acfe101c
CVE-2026-51990CVE-2026-85102CVE-2026-85103CVE-2026-85706AI platform abuseAndroid malwareCheck Point VPNChina-aligned espionageGitLabGrayRabbitJFrog ArtifactoryMicrosoft 365active exploitationbackdoorcredential theftcritical vulnerabilitiesdata breachphishingransomwaresecurity updatessupply chain risk

What happened

A BleepingComputer security news feed covering active exploitation of critical vulnerabilities, malware campaigns, phishing and identity attacks, data breaches, ransomware, AI-platform abuse, and security update failures. Notable items include exploitation of Tencent Sogou Input Method (CVE-2026-51990), imminent exploitation of Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103), a maximum-severity GitLab path traversal flaw (CVE-2026-85706), Artifactory attacks, GrayRabbit and Mantax Otax malware, Microsoft 365 phishing, and breaches involving Florida DMV and Surfshark.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
745177a28d706ea3f7c54fb697abc0b1ae9d08e2c9e05ebe62ba2142acfe101c
Enrichment time
2026-09-14T01:23:23Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Hackers exploit Tencent app flaw to deploy GrayRabbit malware · Baitaphish