(IN BRIEF) ESET has discovered CVE-2025-8088, a zero-day path traversal vulnerability in WinRAR exploited by the Russia-aligned RomCom group in targeted spearphishing campaigns against organizations in Europe and Canada. The flaw, patched on July 30, 2025, was used to deliver … Read the full press release →
Posted in Business, Financial, Government, Industrial, Investment, Management, Marketing, News, Russia, Security & Safety, Slovakia, Technology
Tagged Advanced Persistent Threat, alternate data streams, Anton Cherepanov, APT, Canadian cybersecurity, CVE-2025-8088, cyberespionage, ESET, European cybersecurity, malware, Mythic agent, path traversal, Peter Strýček, RomCom, RustyClaw, SnipBot, software patch, spearphishing, Storm-0978, Tropical Scorpius, UNC2596, vulnerability disclosure, WinRAR, Zero-Day Vulnerability