63
submitted 4 months ago by tyrant@lemmy.world to c/technology@lemmy.world

Multiple threat actors, both state-sponsored and financially motivated, are exploiting the CVE-2025-8088 high-severity vulnerability in WinRAR for initial access and to deliver various malicious payloads.

The security issue is a path traversal flaw that leverages Alternate Data Streams (ADS) to write malicious files to arbitrary locations. Attackers have exploited this in the past to plant malware in the Windows Startup folder, for persistence across reboots.

top 6 comments
sorted by: hot top controversial new old
[-] yesman@lemmy.world 15 points 4 months ago

FYI: the prefix "win" is software jargon for insecure software to let advanced users know to avoid.

[-] woelkchen@lemmy.world 13 points 4 months ago

People who still use WinRAR kinda deserve that. Seriously. WinRAR in 2026? Like WTF.

[-] RunningInRVA@lemmy.world 4 points 4 months ago

What, don’t you still use it to unpack warez?

[-] Scrollone@feddit.it 3 points 4 months ago

7zip (or its modern GUI fork NanaZip) is free and open source.

[-] guynamedzero@piefed.zeromedia.vip 1 points 4 months ago

Praise the lord Linus for the gift of Linux!

[-] rav3n@ttrpg.network 1 points 4 months ago

Fuck winrar and all the morons who used it.

this post was submitted on 27 Jan 2026
63 points (100.0% liked)

Technology

85464 readers
3721 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS