Researchers have released a report detailing how a recent WinRAR path traversal vulnerability tracked as CVE-2025-8088 was exploited in zero-day attacks by the Russian 'RomCom' hacking group to drop ...
WinRAR's 'trial forever' meme masks many users running outdated, vulnerable versions of the app. CVE-2025-8088 lets attackers hide malware in archives that install payloads to the startup app folder.
ESET Research discovered a zero-day vulnerability in WinRAR being exploited in the wild in the guise of job application documents; the weaponized archives exploited a path traversal flaw to compromise ...