Close Menu
Pineapples Update –Pineapples Update –

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ether short wipeout between $ 4K inspired Eric Trump smiling

    August 9, 2025

    RIP, microsoft lens, a simple app that is being replaced by AI

    August 9, 2025

    Stock questions? Google Finance tests new AI chatboats

    August 9, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Pineapples Update –Pineapples Update –
    • Home
    • Gaming
    • Gadgets
    • Startups
    • Security
    • How-To
    • AI/ML
    • Apps
    • Web3
    Pineapples Update –Pineapples Update –
    Home»Security»Winner Zero-Day Flaw was exploited by Romkom hackers in a fishing attack
    Security

    Winner Zero-Day Flaw was exploited by Romkom hackers in a fishing attack

    PineapplesUpdateBy PineapplesUpdateAugust 8, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Winner Zero-Day Flaw was exploited by Romkom hackers in a fishing attack
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Winner Zero-Day Flaw was exploited by Romkom hackers in a fishing attack

    Cive-2025–8088 recently a fixed Winrar vulnerability was tracked, exploited as zero-day in phishing attacks to install romomom malware.

    The defect is a directory traversal vulnerability that was fixed in Winrar 7.13, which allows the specially designed archives to remove files in the file path chosen by the attacker.

    “When removing a file, the previous version of the Winrar, the Windows version of the RAR, the Unarar, the portable UNRR Source Code and the UNRAR.DLL can be cheated in using a path, which is defined in a specially prepared collection, instead of the specified path,” Winner 7.13 Changelog,

    “RAR, Unarar, portable Unarar Source Code and Unix version of Unarar Library, are also not affected as RAR for Android.”

    Using this vulnerability, attackers can create archives that take out the executable in the autorun paths, such as located on the Windows Startup Folder:

    
    %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup (Local to user)
    %ProgramData%\Microsoft\Windows\Start Menu\Programs\StartUp (Machine-wide)

    The next time a user log in, the executable will run automatically, allowing the attacker to obtain distance code execution.

    As Winrar does not include an auto-update feature, it is strongly advised that all users manually download and install the latest version Win-Rar.com So they are safe from this vulnerability.

    In attacks, exploited as a zero-day

    The defect was discovered by acet by Anton Cherapanov, Peter Coinar, and Peter Strassic, in which Strakes told BlappingCoper that it was actively exploited in fishing attacks to install malware.

    “ESET has seen Spearfishing email with attachments with RAR files,” Strike told BlappingCopper.

    These archives exploited CVE-2025-8088 to give ROMCOMCOM backdages. Romomom is a Russian-federal group. ,

    ROMCOM (also tracked as Storm -0978, Tropical Scorpion, or UnC2596) is a Russian hacking group connected to ransomware and data -chori extortion attacks, as well as focuses on stealing credentials.

    The group is known for using zero-day weaknesses in attacks and the use of custom malware to act as data-chori attacks, perseverance, and backdoor.

    Romomom has previously been linked to several ransomware operations including Cuba and Industrial Steps.

    ESET is working on a report about exploitation, which will be published at a later date.


    Picus Red Report 2025

    Malware targeting password stores increased 3x as the attackers secretly carried out the perfect history landscape, infiltrated and exploited important systems.

    Search for the top 10 Metter Att & CK techniques behind the 93% attacks and how to defend them.

    Attack exploited Fishing Flaw hackers Romkom Winner zeroday
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleSamsung Galaxy Tab S10 Light Design and Listed on Google Play Console, can soon debut
    Next Article Book your exhibition table before disrupting 2025
    PineapplesUpdate
    • Website

    Related Posts

    Security

    After updating your iPhone on iOS 26, my biggest regrets (and how to fix it)

    August 9, 2025
    Security

    Openai to fix GPT-5 issues, dual rate limit for users paid after resentment

    August 9, 2025
    Security

    Black Hat: Researchers demonstrate zero-clicks early injection attacks in popular AI agents

    August 9, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Microsoft’s new text editor is a VIM and Nano option

    May 19, 2025797 Views

    The best luxury car for buyers for the first time in 2025

    May 19, 2025724 Views

    Massives Datenleck in Cloud-Spichenn | CSO online

    May 19, 2025650 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    10,000 steps or Japanese walk? We ask experts if you should walk ahead or fast

    June 16, 20250 Views

    FIFA Club World Cup Soccer: Stream Palmirus vs. Porto lives from anywhere

    June 16, 20250 Views

    What do chatbott is careful about punctuation? I tested it with chat, Gemini and Cloud

    June 16, 20250 Views
    Our Picks

    Ether short wipeout between $ 4K inspired Eric Trump smiling

    August 9, 2025

    RIP, microsoft lens, a simple app that is being replaced by AI

    August 9, 2025

    Stock questions? Google Finance tests new AI chatboats

    August 9, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms And Conditions
    • Disclaimer
    © 2025 PineapplesUpdate. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.