Tuesday, February 26, 2019

Time to patch WINRAR (to version 5.70 beta 1) - A critical 19-year-old WinRAR vulnerability disclosed last week has now been spotted actively being exploited in a spam campaign spreading malware.



If a bad actor used spear-phishing tactics to send an unknowing victim a disguised ACE file, and the victim opened the file in WinRAR, the file would automatically extract in the victim’s startup folder and malware could then be quickly planted on the system.

https://threatpost.com/critical-winrar-flaw-found-actively-being-exploited/142204/

No comments:

Post a Comment