Two Russian APT groups are exploiting a WinRAR flaw patched nearly a year ago to hit Ukraine

Wait 5 sec.

Two Russian state-linked hacking groups are actively exploiting a path traversal vulnerability in WinRAR that was patched nearly a year ago, using it to deploy credential-stealing malware against Ukrainian government and military targets, according to research published by Trend Micro. The flaw, tracked as CVE-2025-8088 and rated 8.4 on the CVSS scale, allows attackers to […]This story continues at The Next Web