
Two Russia-aligned groups, Earth Dahu and SHADOW-EARTH-066, exploit CVE-2025-8088 in WinRAR to target Ukrainian organizations nearly a year after the patch. The flaw uses NTFS Alternate Data Streams to deploy the GIFTEDCROOK stealer, which harvests browser passwords and documents via crafted RAR archives.
Tap to vote and see what everyone thinks.
Check Point fixes VPN zero-day exploited since May 7
Summary by ByteBrief