: Attackers hide malicious scripts in a folder with the same name as a harmless file (like photo.jpg ).
WinRAR and 7-Zip have recently been targeted by high-severity exploits that allow attackers to run malicious code when a user simply opens or views a file within an archive. CVE-2023-38831: Extension Spoofing
: When a user clicks the "safe" file, WinRAR mistakenly executes the malicious script instead.
: Groups like Sandworm (Russia) and APT40 (China) used this to steal browser data and passwords. CVE-2025-8088: Path Traversal
Stay up to date with our technology updates, events, special offers, news, publications and training
: Attackers hide malicious scripts in a folder with the same name as a harmless file (like photo.jpg ).
WinRAR and 7-Zip have recently been targeted by high-severity exploits that allow attackers to run malicious code when a user simply opens or views a file within an archive. CVE-2023-38831: Extension Spoofing
: When a user clicks the "safe" file, WinRAR mistakenly executes the malicious script instead.
: Groups like Sandworm (Russia) and APT40 (China) used this to steal browser data and passwords. CVE-2025-8088: Path Traversal
© 2026 — Trusted Nexus