Dark Web Intelligence[verified]@DailyDarkWebActive Exploitation
The text reports active in-the-wild exploitation of CVE-2026-51990 in Tencent's Sogou Input Method by UNC3569, leading to RCE and GRAYRABBIT deployment. It also notes that the vulnerability has been patched in Sogou Input Method version 16.3.0.3498.
Machina Record[verified]@MachinaRecordActive Exploitation
The text reports multiple CVEs, highlighting active exploitation (e.g., GitLab CVE-2026-85706, CISA KEV additions) and mitigation steps (patches by Check Point and GitLab) without detailing exploit tools or technical specifics.
SecureChap[verified]@SecureChapActive Exploitation
UNC3569 has actively exploited CVE‑2021‑38003 via the sgbiz handler in Sogou Input Method, dropping a GRAYRABBIT loader with detailed DLL and network indicators. A new CVE‑2026‑51990 is introduced to restrict future handler usage, but no patch for the original CVE is mentioned.
The Daily Tech Feed[verified]@dailytechonxActive Exploitation
Criminals tied to UNC3569 exploited a CVE‑2021‑38003 flaw in Sogou Input Method, using custom link handling to drop the GRAYRABBIT backdoor, while urging users to update to a patched version to mitigate the risk.
The Hacker News@TheHackersNewsActive Exploitation
China-linked UNC3569 used a malicious Sogou Input Method link to deliver GRAYRABBIT malware by exploiting CVE-2021-38003 in the built-in Chromium 80 browser, demonstrating active exploitation of the vulnerability.
CTIWatch@ctiwatchcloudActive Exploitation
The tweet reports confirmed wild exploitation of CVE-2021-38003 on the Chromium V8 Engine, describing a JSON.stringify bug, but offers no patch, PoC, or exploit code.