Google Warns of WinRAR Vulnerability Exploited to Gain Control Over Windows System
ID: a2588c65-ee60-5c12-82ea-65181b5b50c1
STIX ID: report--a2588c65-ee60-5c12-82ea-65181b5b50c1
Feed Name: cybersecurityNews.com
A critical WinRAR vulnerability (CVE-2025-8088) enabling path traversal and abuse of Alternate Data Streams is being actively exploited in the wild to write malicious files (often to the Windows Startup folder) and achieve persistent execution; attacks since July 2025 involve nation-state actors (e.g., UNC4895, APT44), Chinese-linked groups, and criminal operators targeting governments, military, technology firms, and commercial sectors worldwide despite a patch released on July 30, 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
