Tuesday , August 4 2026
Windows

WinRAR Vuln Exploited in the wild to Gain Control Over Windows System

A serious security flaw in WinRAR, a popular file compression tool for Windows, is being exploited by attackers to gain unauthorized access to systems. CVE-2025-8088 is a vulnerability that lets attackers insert harmful files into sensitive system folders unnoticed, giving them control over Windows computers.

The security flaw was first exploited in July 2025 and still poses a risk to millions, even though a patch has been available since July 30, 2025.

CVE-2026-18574
Check Point Authentication Bypass Hits Management Server

Check Point fixed a flaw that allowed bypassing authentication on its Security Management and Multi-Domain Security Management servers. This issue...
Read More
CVE-2026-18574  Check Point Authentication Bypass Hits Management Server

TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

TP-Link has shared a security warning about a serious problem with its TL-WR940N V6 wireless router. This problem, known as...
Read More
TP-Link RCE and SonicWall Zero-Click Flaws Enable Complete Device Compromise

ExfilSquad releases info of over 100,000 UK police officers, staff

A cyberattack on the U.K.'s Police National Legal Database (PNLD) has put the contact information of over 100,000 police officers...
Read More
ExfilSquad releases info of over 100,000 UK police officers, staff

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves
                                                    imeline of notable observed exploitation (Source – Google Cloud)

The flaw has drawn interest from various attackers, including government-backed espionage groups from Russia and China, as well as financially motivated criminals targeting global businesses.

These adversaries exploit vulnerabilities to spread malware, steal login information, and maintain access to hacked systems. The attack uses specially designed RAR files to exploit a path traversal vulnerability, letting files be written to any location on victim computers.

Google Cloud researchers found that this vulnerability is being widely exploited in campaigns against Ukrainian military and government bodies, as well as technology, hospitality, and banking sectors.

Researchers found that attackers exploit a flaw to place malicious files in the Windows Startup folder, making the malware run every time the victim logs in. This method is similar to the tactic used in a prior WinRAR vulnerability (CVE-2023-38831) in 2023, showing how attackers take advantage of unpatched software.

This vulnerability’s quick spread shows that effective defense needs prompt patching and a shift to identifying consistent post-exploitation tactics.

Check Also

water

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks …