Google Threat Intelligence Group reports widespread exploitation of CVE-2025-8088, a critical path traversal vulnerability in WinRAR patched in July 2025. State-sponsored actors from Russia and China, along with financially motivated groups, are actively exploiting this n-day vulnerability to drop malicious payloads into

7m read time From cloud.google.com
Post cover image
Table of contents
IntroductionVulnerability and Exploit MechanismState-Sponsored Espionage Activity

Sort: