A known WinRAR path traversal vulnerability continues to be exploited by numerous attackers despite the availability of a patch. The flaw allows specially crafted archive files to extract malicious content outside the intended directory, exposing systems to silent malware execution. WinRAR remains widely used across personal and enterprise environments. As a result, unpatched installations provide…
Attackers are actively exploiting a newly uncovered WinRAR zero-day flaw to deliver multiple malware strains. The attacks, linked to the Russia-aligned RomCom group, used specially crafted RAR archives to plant malicious files in sensitive system locations. How the Exploit Worked The vulnerability, tracked as CVE-2025-8088, is a path traversal flaw in WinRAR for Windows. Attackers…
A newly discovered WinRAR zero-day flaw has been exploited in active phishing campaigns by the RomCom hacking group. The vulnerability allows attackers to execute malicious files automatically at system startup. Security experts warn users to update immediately to avoid compromise. RomCom Hackers Weaponize WinRAR Vulnerability Security researchers from ESET revealed that the flaw, tracked as…