June 21, 2026
- Gamaredon is exploiting the WinRAR path-traversal flaw CVE-2025-8088 against Ukrainian targets: military/conscription-themed
.rarlures use a malicious NTFS alternate data stream to silently plant a.lnkinto the Startup folder on extraction, executing a hidden PowerShell stager on next logon. Active since February 2026 and ongoing (Nextron). · Vulnerabilities & Exploits