News

Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088

  • Pierluigi Paganini--Securityaffairs.com
  • published date: 2026-06-10 13:34:45 UTC

Despite a 2025 patch, Russian-linked groups still exploit a WinRAR flaw (CVE-2025-8088) to deploy malware via phishing archives. CVE-2025-8088 is a path traversal flaw in WinRAR that lets an attacker write files outside the extraction directory using NTFS Alt…

Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088 CVE-2025-8088 is a path traversal flaw in WinRAR that lets an attacker write files outside the extraction directory using NTFS Alterna… [+6747 chars]