Follow the latest coverage, related explainers and connected technology stories.
Attackers linked to a China-aligned espionage group are exploiting a one-click remote code execution vulnerability in Sogou Input Method for Windows, enabling the installation of the GrayRabbit backdoor. Tencent released an update that addresses the attack path, but researchers warn that the embedded browser engine remains outdated and lacks security isolation.
Tencent announced the release of the open-source Hy4 Preview model, with a context window exceeding one million tokens and the ability to activate 49 billion parameters per operation. The company says the model outperformed GLM-5.3 and Kimi K3 in an internal blind test, while the results remain limited to Tencent’s evaluation and the model is an initial release.