Get the latest tech news

Newly discovered WinRAR exploit linked to Russian hacking group, can plant backdoor malware — zero day hack requires manual update to fix


WinRAR flaw CVE-2025-8088 has been fixed in version 7.13.

A new vulnerability in file archiving software WinRAR has come to light that can potentially install backdoor malware on Windows PCs. The zero-day vulnerability was discovered by security researchers at ESET and has been tracked as CVE-2025-8088 which is said to be actively exploited by the Russian-linked hacking group RomCom. A similar directory traversal flaw was spotted back in June, when independent security researcher “whs3-detonator” reported CVE-2025-6218 to Trend Micro’s Zero Day Initiative.

Get the Android app

Or read this on r/technology

Read more on:

Photo of Russian

Russian

Photo of backdoor malware

backdoor malware

Photo of day hack

day hack

Related news:

News photo

Microsoft catches Russian hackers targeting foreign embassies

News photo

Microsoft: Russian hackers use ISP access to hack embassies in AiTM attacks

News photo

Russian Hackers Pose as Cyber Firm to Spy on Embassies