Skip to content
Threat Feed

Product

WinRAR

6 briefs RSS
critical threat

TA488 Exploits Zimbra Mailservers with Half-Click Vulnerability CVE-2025-66376

Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear) exploited CVE-2025-66376, a critical XSS vulnerability in Zimbra Collaboration Suite webmail, for at least five months in 2025 via crafted emails to gain persistent access, exfiltrate user credentials, 2FA codes, and bulk emails from Ukrainian government and US defense industrial base targets.

PoC Zimbra Collaboration Suite +10 TA488 +2 espionage xss zimbra apt state-sponsored half-click cve-2025-66376
2r 9t 3c 7i updated
high advisory

CVE-2026-14191 WinRAR / UnRAR RAR5 recovery-volume (.rev) out-of-bounds heap write in RecVolumes5::ReadHeader

CVE-2026-14191 describes an out-of-bounds heap write vulnerability in WinRAR and UnRAR when processing RAR5 recovery volumes (.rev), allowing an unauthenticated attacker to achieve remote code execution on a victim's system by tricking a user into opening a specially crafted archive.

WinRAR +1 cve vulnerability archive client-side windows
1c
high advisory

Microsoft Security Updates — July 2026

Roundup of Microsoft security advisories published in July 2026.

PoC PowerShell +516 roundup
10c 227i updated
high threat

FrostyNeighbor Targets Ukraine with Updated PicassoLoader Chain

The FrostyNeighbor threat actor is targeting Ukrainian governmental organizations with spearphishing emails containing malicious PDFs that deliver a JavaScript dropper (PicassoLoader) and ultimately a Cobalt Strike beacon.

PoC Cobalt Strike +8 FrostyNeighbor cyberespionage cobaltstrike picassoloader ukraine
2r 3t 5c 16i updated
medium advisory

WinRAR and 7-Zip Encryption Abuse for Data Exfiltration Preparation

Adversaries use WinRAR or 7-Zip to create encrypted archives in preparation for data exfiltration, using command-line arguments to enable encryption functionality.

WinRAR +1 data-exfiltration archive encryption windows
3r 2t
medium advisory

Windows Script Execution from Archive File

This rule detects attempts to execute Jscript/Vbscript files from archive files, a common method for delivering malicious scripts by identifying unusual parent-child process relationships where scripting utilities are launched from archive programs, indicating potential exploitation.

Windows Script Host +2 execution archive scripting windows
2r 3t