Scworld Exploitation of WinRAR Path Traversal Flaw Continues Amid CISA Warning
Article Content
Browse articles
The CVE-2025-8088 vulnerability in WinRAR is being exploited by various threat actors for initial access and to deploy malware. The flaw allows attackers to use Alternate Data Streams to write malicious files to arbitrary locations, including the Windows Startup folder. In response to ongoing attacks, the vulnerability has been added to CISA's Known Exploited Vulnerabilities list, with federal agencies ordered to remediate it by December 30, 2025.
Ask AI about this cluster
Answers cite the sources they use
Updated 210d ago How this analysis works
More articles in this cluster (12)
Following this threat?
Track CVE-2023-38831 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Path Traversal Vulnerability in WinRAR Exploited by RomCom Group CVE-2025-8088 is a path traversal vulnerability in WinRAR versions up to 7.12, allowing attackers to exploit alternate data streams (ADSes) in RAR files to extract malicious payloads to sensitive system locations. Exploitation began in the wild on July 18, 2025, with attackers linked to the Russia-aligned RomCom…
DarkMe RAT Campaign Shifts to Phishing Tactics The DarkMe remote access trojan (RAT), previously associated with the Water Hydra threat group, has shifted its distribution method from exploiting zero-day vulnerabilities to using phishing emails. Victims receive emails containing links that appear to lead to image files but instead download a malicious executable…