Wednesday , June 24 2026
Windows

WinRAR Vuln Exploited in the wild to Gain Control Over Windows System

A serious security flaw in WinRAR, a popular file compression tool for Windows, is being exploited by attackers to gain unauthorized access to systems. CVE-2025-8088 is a vulnerability that lets attackers insert harmful files into sensitive system folders unnoticed, giving them control over Windows computers.

The security flaw was first exploited in July 2025 and still poses a risk to millions, even though a patch has been available since July 30, 2025.

LastPass says hackers stole customer data via Klue, supply chain breach

LastPass has reported a security issue with its vendor, Klue. This incident allowed an attacker unauthorized access to customer data....
Read More
LastPass says hackers stole customer data via Klue, supply chain breach

New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

Researchers at cybersecurity firm Paradigm Shift found a new flaw called usbliter8. This flaw can get around main boot protections...
Read More
New Apple Exploit Bypasses Boot Defenses, Possibly Affects Millions of iPhones Worldwide

India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

A cyber attack seems to have affected one of India's top electronics companies. Tata Electronics has said there was a...
Read More
India’s Tata Electronics hit by cyber breach: Hacker target 630 GB record

Anthropic’s Mythos reportedly broke NSA classified systems in hours

The recent finding shows how powerful Mythos is: the AI can access the US government's secret networks in just a...
Read More
Anthropic’s Mythos reportedly broke NSA classified systems in hours

OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

Test before going live is important for AI developers. But there's a problem: testing usually uses fake scenarios that often...
Read More
OpenAI New Method “Deployment Simulation” Predicts AI Risks Before Deployment

AryStinger botnet infected thousands of D-Link routers globally

AryStinger has taken control of over 4,000 old D-Link routers to use them as proxies for harmful traffic. The team...
Read More
AryStinger botnet infected thousands of D-Link routers globally

Hacker suspected of sending alerts across Brazil

Brazil's government suspects a hacking attack triggered an unauthorized ‌alert sent to cell phones across parts of the country early...
Read More
Hacker suspected of sending alerts across Brazil

CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

A new open-source cybersecurity tool named CyberSentinel AI v3.0 has come out. It is an important step in self-operated security...
Read More
CyberSentinel AI features 33 security tools like Nmap, SQLMap, and ZAP, utilizing Claude and GPT

Barracuda hosts Dhaka roundtable on cyber resilience

Barracuda gathered industry people in Dhaka on 18 June 2026 for a roundtable talk about cyber resilience. The company shared...
Read More
Barracuda hosts Dhaka roundtable on cyber resilience

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on Thursday to act to protect...
Read More
CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices
                                                    imeline of notable observed exploitation (Source – Google Cloud)

The flaw has drawn interest from various attackers, including government-backed espionage groups from Russia and China, as well as financially motivated criminals targeting global businesses.

These adversaries exploit vulnerabilities to spread malware, steal login information, and maintain access to hacked systems. The attack uses specially designed RAR files to exploit a path traversal vulnerability, letting files be written to any location on victim computers.

Google Cloud researchers found that this vulnerability is being widely exploited in campaigns against Ukrainian military and government bodies, as well as technology, hospitality, and banking sectors.

Researchers found that attackers exploit a flaw to place malicious files in the Windows Startup folder, making the malware run every time the victim logs in. This method is similar to the tactic used in a prior WinRAR vulnerability (CVE-2023-38831) in 2023, showing how attackers take advantage of unpatched software.

This vulnerability’s quick spread shows that effective defense needs prompt patching and a shift to identifying consistent post-exploitation tactics.

Check Also

FortiGate

CISA Alerts Fortinet Users as FortiBleed Affects 86,644 FortiGate Devices

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) asked Fortinet users with FortiGate devices on …