home.social

#chinese — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #chinese, aggregated by home.social.

  1. #Anthropic said that #Chinese security bureaus, and #russia-linked spies, among others, have exploited a web of fraudulent accounts and online services to access some of the company’s advanced #AI assistants, known as #Claude.

    politico.com/news/2026/09/10/b

  2. Gray Rabbits and the Tale of a One-Click Backdoor

    Gen Threat Labs identified CVE-2026-51990, a critical remote code execution vulnerability in Sogou Input Method, a widely-used Chinese-language input editor with hundreds of millions of installations. The exploit chains three weaknesses: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated unsandboxed Chromium browser engine from 2020. UNC3569 actively exploited this vulnerability in the wild, using a crafted link to deploy the GRAYRABBIT backdoor. The attack required only a single click, with the exploit leveraging CVE-2021-38003 to achieve code execution. The backdoor included anti-sandbox techniques, self-deletion capabilities, and command-and-control functionality. Tencent patched the vulnerability within twelve days of disclosure, though underlying browser components remain outdated and unsandboxed.

    Pulse ID: 6aa3c33464568cec4ec6b942
    Pulse Link: otx.alienvault.com/pulse/6aa3c
    Pulse Author: AlienVault
    Created: 2026-09-11 09:00:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chinese #CyberSecurity #ELF #InfoSec #OTX #OpenThreatExchange #RemoteCodeExecution #Vulnerability #bot #AlienVault

  3. Gray Rabbits and the Tale of a One-Click Backdoor

    Gen Threat Labs identified CVE-2026-51990, a critical remote code execution vulnerability in Sogou Input Method, a widely-used Chinese-language input editor with hundreds of millions of installations. The exploit chains three weaknesses: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated unsandboxed Chromium browser engine from 2020. UNC3569 actively exploited this vulnerability in the wild, using a crafted link to deploy the GRAYRABBIT backdoor. The attack required only a single click, with the exploit leveraging CVE-2021-38003 to achieve code execution. The backdoor included anti-sandbox techniques, self-deletion capabilities, and command-and-control functionality. Tencent patched the vulnerability within twelve days of disclosure, though underlying browser components remain outdated and unsandboxed.

    Pulse ID: 6aa3c33464568cec4ec6b942
    Pulse Link: otx.alienvault.com/pulse/6aa3c
    Pulse Author: AlienVault
    Created: 2026-09-11 09:00:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chinese #CyberSecurity #ELF #InfoSec #OTX #OpenThreatExchange #RemoteCodeExecution #Vulnerability #bot #AlienVault

  4. Gray Rabbits and the Tale of a One-Click Backdoor

    Gen Threat Labs identified CVE-2026-51990, a critical remote code execution vulnerability in Sogou Input Method, a widely-used Chinese-language input editor with hundreds of millions of installations. The exploit chains three weaknesses: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated unsandboxed Chromium browser engine from 2020. UNC3569 actively exploited this vulnerability in the wild, using a crafted link to deploy the GRAYRABBIT backdoor. The attack required only a single click, with the exploit leveraging CVE-2021-38003 to achieve code execution. The backdoor included anti-sandbox techniques, self-deletion capabilities, and command-and-control functionality. Tencent patched the vulnerability within twelve days of disclosure, though underlying browser components remain outdated and unsandboxed.

    Pulse ID: 6aa3c33464568cec4ec6b942
    Pulse Link: otx.alienvault.com/pulse/6aa3c
    Pulse Author: AlienVault
    Created: 2026-09-11 09:00:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chinese #CyberSecurity #ELF #InfoSec #OTX #OpenThreatExchange #RemoteCodeExecution #Vulnerability #bot #AlienVault

  5. Gray Rabbits and the Tale of a One-Click Backdoor

    Gen Threat Labs identified CVE-2026-51990, a critical remote code execution vulnerability in Sogou Input Method, a widely-used Chinese-language input editor with hundreds of millions of installations. The exploit chains three weaknesses: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated unsandboxed Chromium browser engine from 2020. UNC3569 actively exploited this vulnerability in the wild, using a crafted link to deploy the GRAYRABBIT backdoor. The attack required only a single click, with the exploit leveraging CVE-2021-38003 to achieve code execution. The backdoor included anti-sandbox techniques, self-deletion capabilities, and command-and-control functionality. Tencent patched the vulnerability within twelve days of disclosure, though underlying browser components remain outdated and unsandboxed.

    Pulse ID: 6aa3c33464568cec4ec6b942
    Pulse Link: otx.alienvault.com/pulse/6aa3c
    Pulse Author: AlienVault
    Created: 2026-09-11 09:00:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chinese #CyberSecurity #ELF #InfoSec #OTX #OpenThreatExchange #RemoteCodeExecution #Vulnerability #bot #AlienVault

  6. Gray Rabbits and the Tale of a One-Click Backdoor

    Gen Threat Labs identified CVE-2026-51990, a critical remote code execution vulnerability in Sogou Input Method, a widely-used Chinese-language input editor with hundreds of millions of installations. The exploit chains three weaknesses: unvalidated command-line argument injection in the sgbiz: custom protocol handler, unrestricted URL navigation in a CEF-based webview, and a severely outdated unsandboxed Chromium browser engine from 2020. UNC3569 actively exploited this vulnerability in the wild, using a crafted link to deploy the GRAYRABBIT backdoor. The attack required only a single click, with the exploit leveraging CVE-2021-38003 to achieve code execution. The backdoor included anti-sandbox techniques, self-deletion capabilities, and command-and-control functionality. Tencent patched the vulnerability within twelve days of disclosure, though underlying browser components remain outdated and unsandboxed.

    Pulse ID: 6aa3c33464568cec4ec6b942
    Pulse Link: otx.alienvault.com/pulse/6aa3c
    Pulse Author: AlienVault
    Created: 2026-09-11 09:00:36

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chinese #CyberSecurity #ELF #InfoSec #OTX #OpenThreatExchange #RemoteCodeExecution #Vulnerability #bot #AlienVault

  7. Melofee: a look back at a Linux implant and its new variants

    Three years after its initial discovery, the Melofee Linux implant has evolved with sophisticated new capabilities. The malware now features modularized architecture with hot-loadable components for shell functionality, file management, and command execution. New versions incorporate remote C2 infrastructure reconfiguration and enhanced stealth through a kernel rootkit based on the Reptile project. The implant uses RC4 encryption and supports multiple communication protocols including TCP, HTTP, HTTPS, and TLS. Analysis reveals two infrastructure clusters utilizing fake certificates impersonating Symantec and other entities. Code similarities establish links with Windows-targeting implants including CrowDoor, Hemigate, and RatelS, suggesting tool sharing among multiple Chinese state-linked threat groups. The modular design allows dynamic loading of up to eleven specialized modules via a common plugin interface.

    Pulse ID: 6aa32c68adf3f06777eb0318
    Pulse Link: otx.alienvault.com/pulse/6aa32
    Pulse Author: AlienVault
    Created: 2026-09-10 22:17:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Encryption #HTTP #HTTPS #InfoSec #Linux #Malware #OTX #OpenThreatExchange #RAT #Rootkit #Symantec #TCP #TLS #Windows #bot #AlienVault

  8. Melofee: a look back at a Linux implant and its new variants

    Three years after its initial discovery, the Melofee Linux implant has evolved with sophisticated new capabilities. The malware now features modularized architecture with hot-loadable components for shell functionality, file management, and command execution. New versions incorporate remote C2 infrastructure reconfiguration and enhanced stealth through a kernel rootkit based on the Reptile project. The implant uses RC4 encryption and supports multiple communication protocols including TCP, HTTP, HTTPS, and TLS. Analysis reveals two infrastructure clusters utilizing fake certificates impersonating Symantec and other entities. Code similarities establish links with Windows-targeting implants including CrowDoor, Hemigate, and RatelS, suggesting tool sharing among multiple Chinese state-linked threat groups. The modular design allows dynamic loading of up to eleven specialized modules via a common plugin interface.

    Pulse ID: 6aa32c68adf3f06777eb0318
    Pulse Link: otx.alienvault.com/pulse/6aa32
    Pulse Author: AlienVault
    Created: 2026-09-10 22:17:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Encryption #HTTP #HTTPS #InfoSec #Linux #Malware #OTX #OpenThreatExchange #RAT #Rootkit #Symantec #TCP #TLS #Windows #bot #AlienVault

  9. Melofee: a look back at a Linux implant and its new variants

    Three years after its initial discovery, the Melofee Linux implant has evolved with sophisticated new capabilities. The malware now features modularized architecture with hot-loadable components for shell functionality, file management, and command execution. New versions incorporate remote C2 infrastructure reconfiguration and enhanced stealth through a kernel rootkit based on the Reptile project. The implant uses RC4 encryption and supports multiple communication protocols including TCP, HTTP, HTTPS, and TLS. Analysis reveals two infrastructure clusters utilizing fake certificates impersonating Symantec and other entities. Code similarities establish links with Windows-targeting implants including CrowDoor, Hemigate, and RatelS, suggesting tool sharing among multiple Chinese state-linked threat groups. The modular design allows dynamic loading of up to eleven specialized modules via a common plugin interface.

    Pulse ID: 6aa32c68adf3f06777eb0318
    Pulse Link: otx.alienvault.com/pulse/6aa32
    Pulse Author: AlienVault
    Created: 2026-09-10 22:17:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Encryption #HTTP #HTTPS #InfoSec #Linux #Malware #OTX #OpenThreatExchange #RAT #Rootkit #Symantec #TCP #TLS #Windows #bot #AlienVault

  10. Melofee: a look back at a Linux implant and its new variants

    Three years after its initial discovery, the Melofee Linux implant has evolved with sophisticated new capabilities. The malware now features modularized architecture with hot-loadable components for shell functionality, file management, and command execution. New versions incorporate remote C2 infrastructure reconfiguration and enhanced stealth through a kernel rootkit based on the Reptile project. The implant uses RC4 encryption and supports multiple communication protocols including TCP, HTTP, HTTPS, and TLS. Analysis reveals two infrastructure clusters utilizing fake certificates impersonating Symantec and other entities. Code similarities establish links with Windows-targeting implants including CrowDoor, Hemigate, and RatelS, suggesting tool sharing among multiple Chinese state-linked threat groups. The modular design allows dynamic loading of up to eleven specialized modules via a common plugin interface.

    Pulse ID: 6aa32c68adf3f06777eb0318
    Pulse Link: otx.alienvault.com/pulse/6aa32
    Pulse Author: AlienVault
    Created: 2026-09-10 22:17:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Encryption #HTTP #HTTPS #InfoSec #Linux #Malware #OTX #OpenThreatExchange #RAT #Rootkit #Symantec #TCP #TLS #Windows #bot #AlienVault

  11. Melofee: a look back at a Linux implant and its new variants

    Three years after its initial discovery, the Melofee Linux implant has evolved with sophisticated new capabilities. The malware now features modularized architecture with hot-loadable components for shell functionality, file management, and command execution. New versions incorporate remote C2 infrastructure reconfiguration and enhanced stealth through a kernel rootkit based on the Reptile project. The implant uses RC4 encryption and supports multiple communication protocols including TCP, HTTP, HTTPS, and TLS. Analysis reveals two infrastructure clusters utilizing fake certificates impersonating Symantec and other entities. Code similarities establish links with Windows-targeting implants including CrowDoor, Hemigate, and RatelS, suggesting tool sharing among multiple Chinese state-linked threat groups. The modular design allows dynamic loading of up to eleven specialized modules via a common plugin interface.

    Pulse ID: 6aa32c68adf3f06777eb0318
    Pulse Link: otx.alienvault.com/pulse/6aa32
    Pulse Author: AlienVault
    Created: 2026-09-10 22:17:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Chinese #CyberSecurity #Encryption #HTTP #HTTPS #InfoSec #Linux #Malware #OTX #OpenThreatExchange #RAT #Rootkit #Symantec #TCP #TLS #Windows #bot #AlienVault

  12. 我不喝有酒精的饮料。 Wǒ bù hē yǒu jiǔjīng de yǐnliào. I don’t drink alcohol. #Chinese vocabulary for Restaurants. #LearnChinese #Languages. Click to learn more.
    thelanguagegarage.com/chinese-

  13. A bit sad that the "Spring and Autumn Period" of #Chinese #history (Approximately 771–476 BC) was followed by the "Warring States Period" (Approximately 475–221 BC) - But that is what history is all about.

    #china #Zhou
  14. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

    Pulse ID: 6aa3b2954797ae28018be984
    Pulse Link: otx.alienvault.com/pulse/6aa3b
    Pulse Author: Tr1sa111
    Created: 2026-09-11 07:49:41

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #0Day #Chinese #Chrome #CyberSecurity #InfoSec #OTX #OpenThreatExchange #Windows #bot #Tr1sa111

  15. #Chinese #electric vehicle maker #XPeng reported a 4% year-over-year increase in #vehicle deliveries for August 2026, reaching 39,107 units. The #company, headquartered in #Guangzhou, #China, also announced progress in its #robotaxi program and the #launch of a new #SUV #model in the Chinese #market. cnbusinessforum.com/xpeng-augu

  16. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  17. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  18. Mainland #Chinese #enterprises are increasingly adopting comprehensive #global #business #strategies, targeting both advanced #economies and #emerging #markets, according to new research from the #HongKong #Trade Development Council (HKTDC). The #survey highlights #HK’s pivotal role in helping these #China #firms navigate challenges such as shifting trade #policies, #protectionism, and #SupplyChain reconfigurations. cnbusinessforum.com/hong-kong-

  19. The 15th #China #Innovation & #Entrepreneurship #Competition has opened #registration for its “#AI + #Construction #Machinery” division, running from Aug 13 to Sep 15, with project submissions due by September 25 (Beijing Time). Co-organized by #XCMG, a leading #Chinese construction machinery #manufacturer, the competition focuses on advancing #intelligent and #green #technologies for the #industry under the theme “Green Intelligence for a #Better #World.” cnbusinessforum.com/china-laun

  20. The 15th #China #Innovation & #Entrepreneurship #Competition has opened #registration for its “#AI + #Construction #Machinery” division, running from Aug 13 to Sep 15, with project submissions due by September 25 (Beijing Time). Co-organized by #XCMG, a leading #Chinese construction machinery #manufacturer, the competition focuses on advancing #intelligent and #green #technologies for the #industry under the theme “Green Intelligence for a #Better #World.” cnbusinessforum.com/china-laun

  21. The 15th #China #Innovation & #Entrepreneurship #Competition has opened #registration for its “#AI + #Construction #Machinery” division, running from Aug 13 to Sep 15, with project submissions due by September 25 (Beijing Time). Co-organized by #XCMG, a leading #Chinese construction machinery #manufacturer, the competition focuses on advancing #intelligent and #green #technologies for the #industry under the theme “Green Intelligence for a #Better #World.” cnbusinessforum.com/china-laun

  22. Build bridges with #Chinese.
    $55/hour private tutoring, small group classes under $20/hour, tons of #free self study material.Visit us to see how we can help you learn Chinese! thelanguagegarage.com/choose-y

  23. Build bridges with #Chinese.
    $55/hour private tutoring, small group classes under $20/hour, tons of #free self study material.Visit us to see how we can help you learn Chinese! thelanguagegarage.com/choose-y

  24. Build bridges with #Chinese.
    $55/hour private tutoring, small group classes under $20/hour, tons of #free self study material.Visit us to see how we can help you learn Chinese! thelanguagegarage.com/choose-y

  25. 你最喜欢的科目是什么? Nǐ zuì xǐhuān de kēmù shì shénme? What’s your favorite subject? #Chinese vocabulary for school. #LearnChinese. Visit the #Language Garage to learn more. thelanguagegarage.com/chinese-

  26. 你最喜欢的科目是什么? Nǐ zuì xǐhuān de kēmù shì shénme? What’s your favorite subject? #Chinese vocabulary for school. #LearnChinese. Visit the #Language Garage to learn more. thelanguagegarage.com/chinese-

  27. 你最喜欢的科目是什么? Nǐ zuì xǐhuān de kēmù shì shénme? What’s your favorite subject? #Chinese vocabulary for school. #LearnChinese. Visit the #Language Garage to learn more. thelanguagegarage.com/chinese-

  28. 4 groups caught using the same #Chrome and #Windows #exploit kit

    A nearly identical exploit kit that targets critical #vulnerabilities in both #Chromium -based #browsers and older versions of Windows is being actively used by at least four #hacking groups, some of which have ties to the #Chinese government.
    #China #security #privacy

    arstechnica.com/information-te

  29. 4 groups caught using the same #Chrome and #Windows #exploit kit

    A nearly identical exploit kit that targets critical #vulnerabilities in both #Chromium -based #browsers and older versions of Windows is being actively used by at least four #hacking groups, some of which have ties to the #Chinese government.
    #China #security #privacy

    arstechnica.com/information-te

  30. 4 groups caught using the same and kit

    A nearly identical exploit kit that targets critical in both -based and older versions of Windows is being actively used by at least four groups, some of which have ties to the government.

    arstechnica.com/information-te

  31. 4 groups caught using the same #Chrome and #Windows #exploit kit

    A nearly identical exploit kit that targets critical #vulnerabilities in both #Chromium -based #browsers and older versions of Windows is being actively used by at least four #hacking groups, some of which have ties to the #Chinese government.
    #China #security #privacy

    arstechnica.com/information-te

  32. 4 groups caught using the same #Chrome and #Windows #exploit kit

    A nearly identical exploit kit that targets critical #vulnerabilities in both #Chromium -based #browsers and older versions of Windows is being actively used by at least four #hacking groups, some of which have ties to the #Chinese government.
    #China #security #privacy

    arstechnica.com/information-te

  33. Smear Campaign Says Anti-Flock Movement Is #Chinese #Propaganda

    Over the weekend, more than a dozen local #TVnews stations ran a video report called “Far-left network behind ‘No Kings’ protests targeting #AI data centers, #Flock cams.” The report paints those opposing Flock not as a diverse, decentralized, bipartisan group of ordinary citizens who oppose mass #surveillance, but as well-funded #radicalLeftists who are spreading propaganda at the behest of #China and rich #billionaires. The opposite is true, of course: The entities defending Flock and painting their opponents as cynical, paid #influencers have a specific agenda, have deep pockets, and are connected to some of the most powerful people in the world.
    #privacy #security #alpr

    > I wonder if these TV stations have common ownership 🤔

    404media.co/smear-campaign-say

  34. Smear Campaign Says Anti-Flock Movement Is #Chinese #Propaganda

    Over the weekend, more than a dozen local #TVnews stations ran a video report called “Far-left network behind ‘No Kings’ protests targeting #AI data centers, #Flock cams.” The report paints those opposing Flock not as a diverse, decentralized, bipartisan group of ordinary citizens who oppose mass #surveillance, but as well-funded #radicalLeftists who are spreading propaganda at the behest of #China and rich #billionaires. The opposite is true, of course: The entities defending Flock and painting their opponents as cynical, paid #influencers have a specific agenda, have deep pockets, and are connected to some of the most powerful people in the world.
    #privacy #security #alpr

    > I wonder if these TV stations have common ownership 🤔

    404media.co/smear-campaign-say

  35. Smear Campaign Says Anti-Flock Movement Is #Chinese #Propaganda

    Over the weekend, more than a dozen local #TVnews stations ran a video report called “Far-left network behind ‘No Kings’ protests targeting #AI data centers, #Flock cams.” The report paints those opposing Flock not as a diverse, decentralized, bipartisan group of ordinary citizens who oppose mass #surveillance, but as well-funded #radicalLeftists who are spreading propaganda at the behest of #China and rich #billionaires. The opposite is true, of course: The entities defending Flock and painting their opponents as cynical, paid #influencers have a specific agenda, have deep pockets, and are connected to some of the most powerful people in the world.
    #privacy #security #alpr

    > I wonder if these TV stations have common ownership 🤔

    404media.co/smear-campaign-say

  36. Smear Campaign Says Anti-Flock Movement Is

    Over the weekend, more than a dozen local stations ran a video report called “Far-left network behind ‘No Kings’ protests targeting data centers, cams.” The report paints those opposing Flock not as a diverse, decentralized, bipartisan group of ordinary citizens who oppose mass , but as well-funded who are spreading propaganda at the behest of and rich . The opposite is true, of course: The entities defending Flock and painting their opponents as cynical, paid have a specific agenda, have deep pockets, and are connected to some of the most powerful people in the world.

    > I wonder if these TV stations have common ownership 🤔

    404media.co/smear-campaign-say

  37. Smear Campaign Says Anti-Flock Movement Is #Chinese #Propaganda

    Over the weekend, more than a dozen local #TVnews stations ran a video report called “Far-left network behind ‘No Kings’ protests targeting #AI data centers, #Flock cams.” The report paints those opposing Flock not as a diverse, decentralized, bipartisan group of ordinary citizens who oppose mass #surveillance, but as well-funded #radicalLeftists who are spreading propaganda at the behest of #China and rich #billionaires. The opposite is true, of course: The entities defending Flock and painting their opponents as cynical, paid #influencers have a specific agenda, have deep pockets, and are connected to some of the most powerful people in the world.
    #privacy #security #alpr

    > I wonder if these TV stations have common ownership 🤔

    404media.co/smear-campaign-say

  38. 我对甲壳类海鲜过敏。 Wǒ duì jiǎkélèi hǎixiān guòmǐn. I’m allergic to shellfish. #Chinese vocabulary for Restaurants. #LearnChinese #Languages. Click to learn more.
    thelanguagegarage.com/chinese-