- Critical vulnerability in Tencent's Sogou Input Method for Windows exploited by UNC3569.
- GrayRabbitBackdoor malware deployed by UNC3569.
September 14, 2026 brings critical security developments across multiple fronts, with nation-state threat actors actively exploiting vulnerabilities in widely deployed enterprise and consumer software. Organizations face mounting pressure to patch critical flaws in VPN infrastructure, remote access tools, and supply chain components while defending against sophisticated exploit kits targeting zero-day vulnerabilities.
Threat actors linked to a China-aligned espionage group are actively exploiting a critical vulnerability in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. The vulnerability, tracked as CVE-2026-51990, represents a significant risk to Windows users who rely on this widely used input method application. The exploitation campaign demonstrates how threat actors continue to target popular software components that may be overlooked in security patching routines.
Source: Bleeping Computer
The U.S. Cybersecurity and Infrastructure Security Agency has added five security flaws to its Known Exploited Vulnerabilities catalog following confirmed reports of active exploitation. The affected products include JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, all critical components in enterprise infrastructure. The vulnerabilities tracked as CVE-2026-42016, CVE-2026-42018, CVE-2026-67277, CVE-2026-82329, CVE-2026-84869, and CVE-2026-86060 span multiple severity levels, with CVE-2026-42016 carrying a CVSS score of 8.1. The inclusion in CISA's KEV catalog signals that these flaws are being weaponized in the wild and require immediate patching.
Source: The Hacker News
The Dutch Nationaal Cyber Security Centrum is warning of imminent exploitation of two critical vulnerabilities in Check Point VPN solutions. The flaws, identified as CVE-2026-85102 and CVE-2026-85103, pose a direct threat to organizations relying on Check Point infrastructure for secure remote access. The warning from a national cybersecurity authority underscores the urgency of deploying patches before threat actors begin widespread exploitation campaigns.
Source: Bleeping Computer
Multiple espionage-motivated threat actors have adopted the BlueMoon exploit kit in opportunistic and rushed deployments targeting critical zero-day vulnerabilities. The toolkit chains recent Chrome and Windows zero-days, identified as CVE-2026-85046, CVE-2026-85880, and CVE-2026-87491, to maximize impact against unpatched systems. The rapid adoption by multiple threat actors indicates that BlueMoon represents a significant escalation in the threat landscape, enabling less sophisticated attackers to execute complex multi-stage attacks.
Source: SecurityWeek
Today's threat landscape reflects a coordinated campaign by nation-state and espionage-motivated actors to exploit both known vulnerabilities and zero-day flaws across enterprise and consumer platforms. Organizations must prioritize immediate patching of Check Point VPN, ScreenConnect, Artifactory, and RouterOS systems while monitoring for exploitation attempts targeting Chrome, Windows, and Tencent applications.
Source articles and extracted indicators (defanged where appropriate).