Tag

Romcom

All articles tagged with #romcom

WinRAR ADS path-traversal flaw drives ongoing global intrusions
security29 days ago

WinRAR ADS path-traversal flaw drives ongoing global intrusions

Security researchers warn that WinRAR CVE-2025-8088, a high-severity path-traversal flaw abusing Alternate Data Streams to drop payloads, remains actively exploited by both state-backed groups and financially motivated criminals. The exploit chain hides malicious ADS inside decoy files and uses directory traversal to drop LNK/HTA/BAT/CMD payloads that execute on login. Actors such as RomCom/UNC4895, APT44, TEMP.Armageddon, Turla, and China-linked groups have used it for espionage and malware delivery, while criminals distribute RATs and info-stealers, with exploits marketed by underground actors. The activity underscores exploit commoditization and emphasizes the need to patch WinRAR promptly to mitigate ongoing risk.

Russian Hackers Exploit WinRAR Zero-Day to Spread RomCom Malware
cybersecurity6 months ago

Russian Hackers Exploit WinRAR Zero-Day to Spread RomCom Malware

Russia-linked attackers exploited a high-severity WinRAR vulnerability (CVE-2025-8088) before it was patched, using targeted spearphishing campaigns against European and Canadian companies. The vulnerability involves a path-traversal flaw that was exploited via malicious archives containing ADSes, leading to malware deployment and backdoors like Mythic, SnipBot, and RustyClaw. Multiple threat groups, including RomCom and Paper Werewolf, have used this zero-day in targeted attacks, highlighting the importance of timely updates and vigilance.

Russian Hackers Exploit Zero-Day Flaws in Windows and Firefox
cybersecurity1 year ago

Russian Hackers Exploit Zero-Day Flaws in Windows and Firefox

A Russian state-sponsored group known as RomCom has been confirmed to exploit a zero-click cyber attack using two zero-day vulnerabilities in Mozilla Firefox and Windows, with severity ratings of 9.8 and 8.8, respectively. This attack installs a backdoor on Windows systems, primarily targeting sectors in Europe and North America. The vulnerabilities have been patched, but organizations are urged to update their systems promptly to mitigate risks. RomCom, also known as Storm-0978, has been active since at least 2022, engaging in espionage and cybercrime operations.

Russian Hackers Exploit Firefox and Windows Zero-Days, Urgent Action Needed
technology1 year ago

Russian Hackers Exploit Firefox and Windows Zero-Days, Urgent Action Needed

Microsoft has issued a warning to 450 million Windows users to update their systems following the discovery of a critical vulnerability exploited by the RomCom cyber threat group. This vulnerability, now patched, allowed attackers to execute arbitrary code on PCs through a combination of Windows and browser flaws. With Windows 10 support ending in 2025, Microsoft offers a $30 extension for an additional year, but many users will need to upgrade to Windows 11 or new hardware to maintain security. The situation is expected to impact PC sales, with a forecasted recovery in 2025.

RomCom APT Targets Windows and Firefox with Zero-Day Exploits
technology1 year ago

RomCom APT Targets Windows and Firefox with Zero-Day Exploits

Microsoft has issued a warning to 450 million Windows users to update their systems following the discovery of a critical vulnerability exploited by the RomCom cyber threat group. The vulnerability, identified by ESET, involves a Windows flaw and a browser vulnerability that allow attackers to execute arbitrary code. While patches have been released, users on unsupported systems are at risk. Microsoft offers a $30 extension for Windows 10 support, but users are urged to upgrade to Windows 11 or update their hardware to maintain security.

Russian Hackers Exploit Firefox and Windows Zero-Days in Major Cyber Campaign
technology1 year ago

Russian Hackers Exploit Firefox and Windows Zero-Days in Major Cyber Campaign

Security researchers have discovered two zero-day vulnerabilities exploited by the Russian-linked hacking group RomCom, targeting Firefox and Windows users in Europe and North America. The group used these vulnerabilities to create a 'zero-click' exploit, allowing them to install malware without user interaction. Mozilla and Microsoft have since patched the vulnerabilities. RomCom is known for cyberattacks supporting Russian interests, including a recent ransomware attack on Casio.

RomCom Hackers Exploit Firefox and Windows Zero-Days in Cyberattacks
cybersecurity1 year ago

RomCom Hackers Exploit Firefox and Windows Zero-Days in Cyberattacks

The Russia-aligned threat actor RomCom has exploited zero-day vulnerabilities in Mozilla Firefox and Microsoft Windows to deliver a backdoor on victim systems. The vulnerabilities, CVE-2024-9680 in Firefox and CVE-2024-49039 in Windows, allow for zero-click code execution and privilege escalation, respectively. RomCom used a fake website to redirect victims to a server hosting the malicious payload, leading to the installation of RomCom RAT. The attacks primarily targeted users in Europe and North America, highlighting RomCom's sophisticated cybercrime and espionage capabilities.

Russian RomCom Hackers Exploit Firefox and Windows Zero-Day Vulnerabilities
cybersecurity1 year ago

Russian RomCom Hackers Exploit Firefox and Windows Zero-Day Vulnerabilities

ESET researchers have identified a critical zero-day vulnerability in Mozilla products, exploited by the Russia-aligned group RomCom, allowing arbitrary code execution in Firefox, Thunderbird, and Tor Browser. This vulnerability, CVE-2024-9680, when combined with another Windows zero-day, CVE-2024-49039, enables attackers to install the RomCom backdoor without user interaction. The attack targets various sectors globally, with patches released by Mozilla and Microsoft to address these vulnerabilities. RomCom is known for both cybercrime and espionage activities.

film1 year ago

Renée Zellweger Returns as Bridget Jones, Finds New Love in Final Film Trailer

Renée Zellweger returns in "Bridget Jones: Mad About the Boy," the fourth and final installment of the rom-com series, set to premiere on Peacock on February 13. The film, based on Helen Fielding's third novel, features returning stars Hugh Grant and Emma Thompson, alongside newcomers like Leo Woodall and Chiwetel Ejiofor. The plot follows Bridget as a widowed single mother navigating work, romance, and family life. Directed by Michael Morris, the film is co-financed by StudioCanal and Miramax.