The “Zeroplayer” Arsenal: WinRAR Flaw CVE-2025-8088 Weaponized by Spies
ID: 86bee296-fa79-5309-ac85-46795bdba41e
STIX ID: report--86bee296-fa79-5309-ac85-46795bdba41e
Feed Name: securityonline.info
GTIG warns that CVE-2025-8088, a WinRAR path traversal vulnerability leveraging Windows Alternate Data Streams to hide and place payloads (often into the Startup folder), is being actively exploited by Russia- and China-linked APTs and financially motivated cybercriminals to deliver malware (POISONIVY, XWorm, AsyncRAT) across military, government, and commercial sectors; a patch (WinRAR 7.13, 30 July 2025) exists but slow patching has enabled ongoing n-day exploitation and trafficked exploits from sellers like "zeroplayer" increase risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
