Multiple Threats Exploit WinRAR Zero-Day in Global Attacks

1 min read
Source: Ars Technica
Multiple Threats Exploit WinRAR Zero-Day in Global Attacks
Photo: Ars Technica
TL;DR Summary

A critical zero-day vulnerability in WinRAR has been actively exploited for weeks by two Russian cybercrime groups, RomCom and Paper Werewolf, through malicious archives in phishing attacks. The vulnerability, CVE-2025-8088, was exploited to plant malicious files and was patched within six days of discovery, highlighting the sophistication and resource investment of the attackers.

Share this article

Reading Insights

Total Reads

0

Unique Readers

3

Time Saved

2 min

vs 2 min read

Condensed

85%

35353 words

Want the full story? Read the original article

Read on Ars Technica