
hackers have gone TOO FAR
Source: YouTube · John Hammond · published Aug 26, 2025 · 23:46
A new zero-day vulnerability in WinRAR (CVE-2025-8088) is being actively exploited by Russia-aligned threat actor group Romcom through weaponized job application archives 0:00. The vulnerability affects WinRAR versions up to 7.12 on Windows systems and exploits path traversal through NTFS alternate data streams 3:11.
Key Takeaways:
• The vulnerability allows attackers to place malicious files like DLLs and LNK shortcuts in system directories, gaining persistence 3:37
• Romcom has previously exploited similar zero-days in Microsoft Word and other software 1:06
• The attack campaign uses fake job application documents (resumes/CVs) as social engineering lures 5:14
• WinRAR 7.13, released July 30th, patches the vulnerability 2:11
Users should immediately update to WinRAR 7.13 or later to protect against this vulnerability being exploited in the wild 23:36.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Question for you. Actually, two questions. Do you have WinRAR installed on your Windows computer? Second question. Do you know what version of WinRAR? Because if you haven't updated in a little bit, you might have to update WinRAR tools now because a thread actor group romcom and others are exploiting a new zeroday vulnerability. This is very new in recent research from ESET. They discovered a new vulnerability in WinRAR being exploited in the wild under the guise of job application documents like resumes or cover letters that uses weaponized archives exploiting a path traversal flaw to compromise targets. Big shout out, big kudos. Credit where credit is due, Anton, Peter, and Damian. Of course, these are the individuals putting out this blog post, and I'll have that linked for you to revi…