Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

Tencent patched its keyboard app in April. Attackers are still getting in.

A China-aligned group is exploiting CVE-2026-51990, a one-click remote code execution flaw in the Sogou Input Method for Windows, BleepingComputer reported.

ERP LEADERS news desk · · First reported by BleepingComputer · Edition no. 8

Developed by Tencent, the app has hundreds of millions of installations in China.

The attack starts with command-line argument injection in the sgbiz URI handler. Unrestricted URL navigation in a webview then reaches an outdated browser engine. A victim only has to click a crafted link.

BleepingComputer attributes the activity to UNC3569, described as a "China-based threat actor" working across cybercrime and contractor-for-hire.

The payload is a backdoor called GrayRabbit. It opens reverse shells and moves files, while plugins are loaded in memory.

Tencent shipped the fix in Sogou Input Method version 16.3.0.3498 on 21 April 2026. The patch validates URL arguments and restricts navigation to HTTPS. Navigation is also limited to approved domains. The article carries no comment from Tencent.

A keyboard sits on every desk in the office, often outside anyone's asset register.

Does your endpoint inventory include the input software your staff installed themselves?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story
Tencent

For your next steering committee

Questions for your own programme. They are not findings about any company in this story.

  1. 1Ask when systems of this kind in your landscape were last patched, and who confirms it.
  2. 2Ask which finance and ERP accounts can be reached from outside, and how each sign-in is protected.
  3. 3Ask how long a restore took the last time it was tested.

Issue 01 of the ERP LEADERS brief puts a timeline, the three-number review and six questions on one page. Read issue 01

Founding reader view is on in this browser. It is a reading view, not secure access. Print the working sheet

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01