Follow the latest coverage, related explainers and connected technology stories.
Attackers linked to a China-aligned espionage group are exploiting a one-click remote code execution vulnerability in Sogou Input Method for Windows, enabling the installation of the GrayRabbit backdoor. Tencent released an update that addresses the attack path, but researchers warn that the embedded browser engine remains outdated and lacks security isolation.