Analyzing "Zombie Zip" Files (CVE-2026-0866), (Wed, Mar 11th)
ID: c32312a9-9b85-5c6d-82cd-1a34caf35b28
STIX ID: report--c32312a9-9b85-5c6d-82cd-1a34caf35b28
Feed Name: SANS ISC Diary
Threat Score
A vulnerability (CVE-2026-0866, "Zombie Zip") is detailed that abuses ZIP headers by marking files as STORED while the payload remains DEFLATED, allowing compressed malicious content to evade many antivirus engines and requiring a custom loader to extract. The author demonstrates analysis and detection workarounds using search-for-compression.py and an updated zipdump.py (with a forcedecompress option) and uses an EICAR test file as proof-of-concept.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
