Daily Cyber Threat Intel Brief — 2026-09-14
Generated: 2026-09-14 08:00:17 UTC
Executive summary
Priority technology watch items
- Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-51990` | Hackers exploit Tencent app flaw to deploy GrayRabbit malware | BleepingComputer Ransomware News |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `f80863cff7bd3f7607c6486f3615c67a133e57a0cd5f4b6d749c3f1f3c3a1a9e` | RansomLook: www.kashkha.com claimed by krybit | RansomLook Recent Listings |