Multiple threat actors, both state-sponsored and financially motivated, are exploiting the CVE-2025-8088 high-severity vulnerability in WinRAR for initial access and to deliver various malicious payloads.
The security issue is a path traversal flaw that leverages Alternate Data Streams (ADS) to write malicious files to arbitrary locations. Attackers have exploited this in the past to plant malware in the Windows Startup folder, for persistence across reboots.
8 Comments
Kolanaki@pawb.social · 22 pts · 233d
7z ftw.
FauxLiving@lemmy.world · 3 pts · 232d
Also, there's the tactic of not using NTFS
If you're into that kind of thing
yesman@lemmy.world · 12 pts · 233d
FYI: the prefix "win" is software jargon for insecure software to let advanced users know to avoid.
woelkchen@lemmy.world · 10 pts · 233d
People who still use WinRAR kinda deserve that. Seriously. WinRAR in 2026? Like WTF.
RunningInRVA@lemmy.world · 4 pts · 233d
What, don’t you still use it to unpack warez?
Scrollone@feddit.it · 3 pts · 232d
7zip (or its modern GUI fork NanaZip) is free and open source.
guynamedzero@piefed.zeromedia.vip · 1 pts · 232d
Praise the lord Linus for the gift of Linux!
rav3n@ttrpg.network · -1 pts · 232d
Fuck winrar and all the morons who used it.