home.social

#winrar — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #winrar, aggregated by home.social.

fetched live
  1. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  2. Hits Safe Mode: Ransomware Rebooting Around EDR

    An Akira ransomware affiliate gained initial access through an exposed SonicWall VPN without multi-factor authentication via credential spraying. After compromising the domain controller, the attacker performed Active Directory enumeration, collected and exfiltrated data using WinRAR and s5cmd to cloud storage. The affiliate employed a novel evasion technique by rebooting the victim host into Safe Mode with Networking to disable EDR and antivirus protection. AnyDesk was installed as a persistent remote access mechanism. However, the Safe Mode environment caused the ransomware to fail due to out-of-virtual-memory errors, preventing encryption. Despite the encryption failure, the attacker had already exfiltrated credentials and file shares, enabling extortion through data leak threats. This marks the first observed instance of Akira affiliates using Safe Mode boot as an anti-EDR technique.

    Pulse ID: 6a7ca262c4921e41ead16a57
    Pulse Link: otx.alienvault.com/pulse/6a7ca
    Pulse Author: AlienVault
    Created: 2026-08-12 16:42:10

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Akira #AnyDesk #Cloud #CyberSecurity #DomainController #EDR #Encryption #Extortion #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Troll #VPN #WinRAR #bot #AlienVault

  3. Analysis of a Modular Cyber Espionage Framework

    Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a

    Pulse ID: 6a75b204c9420179df545451
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:23:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault

  4. Analysis of a Modular Cyber Espionage Framework

    Security researchers have uncovered a sophisticated cyber espionage operation deploying two previously undocumented malware families, OctLurk and SilkLurk, targeting government and public-sector organizations across Central Asia and the Middle East. Both modular backdoors utilize victim-specific decryption mechanisms, extensive obfuscation, and in-memory execution to evade detection. The malware enables credential theft, remote access, network reconnaissance, and plugin-based expansion. Operations began in January 2025, affecting entities in Afghanistan, Kazakhstan, Kyrgyzstan, Syria, Tajikistan, and Uzbekistan. Victims include government offices, foreign affairs ministries, law enforcement agencies, healthcare providers, logistics organizations, research institutions, urban planning facilities, and educational establishments. Attackers deployed additional tools including Impacket's SecretsDump, Browser Password Decryptor, Pandora RC, Fscan, WinRAR, 7-Zip, and PlugX. A companion utility, LurkProxy, proxies a

    Pulse ID: 6a75b204c9420179df545451
    Pulse Link: otx.alienvault.com/pulse/6a75b
    Pulse Author: AlienVault
    Created: 2026-08-07 10:23:00

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Afghanistan #Asia #BackDoor #Browser #CentralAsia #CyberSecurity #Education #Espionage #Government #Healthcare #ICS #InfoSec #Kazakhstan #LawEnforcement #Malware #MiddleEast #OTX #Office #OpenThreatExchange #Password #PlugX #Proxy #RAT #RCE #SMS #Syria #WinRAR #Word #ZIP #bot #AlienVault

  5. Looks like BetterZip for Mac received another big update with new features and bug fixes. I like this!

    Link: macitbetter.com

    #MacOS #WinZip #WinRAR #BetterZip #Update #Apple #Macintosh

  6. Looks like BetterZip for Mac received another big update with new features and bug fixes. I like this!

    Link: macitbetter.com

    #MacOS #WinZip #WinRAR #BetterZip #Update #Apple #Macintosh

  7. WinRAR 7.23 foi lançado com um agradecimento irónico aos utilizadores que suportaram o projeto. O compactador de ficheiros agradeceu a todos que abriram a carteira para suportar o projeto. 📦

    🔗 tugatech.com.pt/t86872-winrar-

    #winrar 

  8. WinRAR 7.23 foi lançado com um agradecimento irónico aos utilizadores que suportaram o projeto. O compactador de ficheiros agradeceu a todos que abriram a carteira para suportar o projeto. 📦

    🔗 tugatech.com.pt/t86872-winrar-

    #winrar 

  9. Nova versão WinRAR 7.23 corrige falhas críticas de segurança no Windows. O descompactador de ficheiros WinRAR lançou uma atualização com o objetivo de resolver problemas de segurança graves.

    🔗 tugatech.com.pt/t86572-nova-ve

    #windows #winrar 

  10. Nova versão WinRAR 7.23 corrige falhas críticas de segurança no Windows. O descompactador de ficheiros WinRAR lançou uma atualização com o objetivo de resolver problemas de segurança graves.

    🔗 tugatech.com.pt/t86572-nova-ve

    #windows #winrar 

  11. Version 7.23 de WinRAR, popular aplicación de compresión y descompresión de archivos para Windows, macOS, Linux y Android: dekazeta.net/foro/files/file/4

    #Winrar #Windows #macOS #Linux #Android

  12. Version 7.23 de WinRAR, popular aplicación de compresión y descompresión de archivos para Windows, macOS, Linux y Android: dekazeta.net/foro/files/file/4

    #Winrar #Windows #macOS #Linux #Android

  13. • 7-Zip: 26.02
    • WinRAR: 7.22 → 7.23 🆕
    • RAR Linux: 7.22 → 7.23 🆕
    • RAR macOS: 7.22 → 7.23 🆕
    • RAR Android: 7.20 → 7.22 🆕
    #7zip #WinRAR

  14. • 7-Zip: 26.02
    • WinRAR: 7.22 → 7.23 🆕
    • RAR Linux: 7.22 → 7.23 🆕
    • RAR macOS: 7.22 → 7.23 🆕
    • RAR Android: 7.20 → 7.22 🆕
    #7zip #WinRAR

  15. • 7-Zip: 26.01 → 26.02 🆕
    • WinRAR: 7.22
    • RAR Linux: 7.22
    • RAR macOS: 7.22
    • RAR Android: 7.20
    #7zip #WinRAR

  16. • 7-Zip: 26.01 → 26.02 🆕
    • WinRAR: 7.22
    • RAR Linux: 7.22
    • RAR macOS: 7.22
    • RAR Android: 7.20
    #7zip #WinRAR

  17. 🚨 Google has linked Turla to a new .NET backdoor.

    STOCKSTAY was used in espionage campaigns targeting #Ukraine government and military organizations.

    It overlaps with Kazuar and reached targets through phishing, RDP files, MSI installers, and #WinRAR CVE-2025-8088 lures.

    See the full attack details 🠖 thehackernews.com/2026/06/goog

  18. A WinRAR está a celebrar a compra de licenças pelos seus clientes com posts na rede social X. A marca aproveitou para relembrar os tempos em que os utilizadores tentavam extrair ficheiros durante o período de teste 📦

    🔗 tugatech.com.pt/t85533-winrar-

    #compra #winrar 

  19. A WinRAR está a celebrar a compra de licenças pelos seus clientes com posts na rede social X. A marca aproveitou para relembrar os tempos em que os utilizadores tentavam extrair ficheiros durante o período de teste 📦

    🔗 tugatech.com.pt/t85533-winrar-

    #compra #winrar 

  20. Gamaredon sfrutta CVE-2025-8088 in WinRAR per distribuire GammaWorm e GammaSteel contro l’Ucraina

    Sekoia documenta una campagna di gennaio 2026 del gruppo APT russo Gamaredon: sfruttando CVE-2025-8088 in WinRAR, gli operatori dell'FSB distribuiscono GammaPhish, GammaLoad, GammaWorm e GammaSteel contro target governativi e militari ucraini. La catena usa Telegram come dead drop resolver per il C2 e NTFS Alternate Data Streams per l'evasione, con esfiltrazione finale verso AWS S3.

    insicurezzadigitale.com/gamare

  21. Gamaredon sfrutta CVE-2025-8088 in WinRAR per distribuire GammaWorm e GammaSteel contro l’Ucraina

    Sekoia documenta una campagna di gennaio 2026 del gruppo APT russo Gamaredon: sfruttando CVE-2025-8088 in WinRAR, gli operatori dell'FSB distribuiscono GammaPhish, GammaLoad, GammaWorm e GammaSteel contro target governativi e militari ucraini. La catena usa Telegram come dead drop resolver per il C2 e NTFS Alternate Data Streams per l'evasione, con esfiltrazione finale verso AWS S3.

    insicurezzadigitale.com/gamare

  22. Gamaredon Exploits WinRAR Flaw to Deliver GammaWorm, GammaSteel Malware

    Cyber attackers have cleverly exploited a WinRAR flaw to unleash a potent malware duo, GammaWorm and GammaSteel, with the goal of taking control of infected systems and executing malicious scripts. This sneaky tactic, spotted by French cybersecurity firm Sekoia, allows hackers to fingerprint host systems, manipulate network settings, and…

    osintsights.com/gamaredon-expl

    #Gamaredon #Winrar #Cve20258088 #Gammaworm #Gammasteel

  23. FSB-Linked Worm Exploits Windows Flaw to Evade Detection

    Cyber attackers have cleverly exploited a known Windows flaw, CVE-2025-8088, to sneak a malicious payload into victims' systems, allowing them to gain access and lay the groundwork for further attacks. This stealthy move was uncovered by Sekoia, which tracked the initial access stage as GammaPhish.

    osintsights.com/fsb-linked-wor

    #WindowsFlaw #Cve20258088 #Winrar #Gammaphish #Gammaworm

  24. Storing my GOG.com gaming library on my local harddisk drive. Oh, wow... WinRAR sure eats up these CPU cores for dinner. Flawless multi-threading! 😎

    #WinRAR #CPU #Processor #AMD #Ryzen #Windows #GOG #Preservation #Archiving

  25. Storing my GOG.com gaming library on my local harddisk drive. Oh, wow... WinRAR sure eats up these CPU cores for dinner. Flawless multi-threading! 😎

    #WinRAR #CPU #Processor #AMD #Ryzen #Windows #GOG #Preservation #Archiving

  26. • 7-Zip: 26.01
    • WinRAR: 7.21 → 7.22 🆕
    • RAR Linux: 7.21 → 7.22 🆕
    • RAR macOS: 7.21 → 7.22 🆕
    • RAR Android: 7.20
    #7zip #WinRAR

  27. • 7-Zip: 26.01
    • WinRAR: 7.21 → 7.22 🆕
    • RAR Linux: 7.21 → 7.22 🆕
    • RAR macOS: 7.21 → 7.22 🆕
    • RAR Android: 7.20
    #7zip #WinRAR

  28. • 7-Zip: 26.00 → 26.01 🆕
    • WinRAR: 7.20
    • RAR Linux: 7.20
    • RAR macOS: 7.20
    • RAR Android: 7.20
    #7zip #WinRAR

  29. New XWorm 7.1 and Remcos RAT campaigns are abusing trusted #Windows utilities and memory-based execution to evade detection, giving attackers remote access to infected systems. The campaign also exploits a #WinRAR vulnerability to gain initial access.

    Read: hackread.com/xworm-7-1-remcos-

    #CyberSecurity #Malware #XWorm #RemcosRAT

  30. • 7-Zip: 25.01 → 26.00 🆕
    • WinRAR: 7.20
    • RAR Linux: 7.20
    • RAR macOS: 7.20
    • RAR Android: 7.20
    #7zip #WinRAR

  31. Nowa kampania cyberszpiegowska. Grupa Amaranth-Dragon atakuje strategiczne cele przy użyciu luki w WinRAR (CVE-2025-8088)

    Nie tak dawno, bo w ubiegłym roku została wykryta podatność w dobrze znanym WinRAR o czym pisaliśmy tutaj. I choć mogłoby się wydawać, że wraz z wydaniem aktualizacji problem został rozwiązany, to rzeczywistość pokazała, że nie do końca tak jest. Zwłaszcza, gdy do gry wkraczają grupy APT. W najnowszym wpisie...

    #Aktualności #Teksty #Apt #Cve #Winrar

    sekurak.pl/nowa-kampania-cyber

  32. #Peazip sigue mejorando. Es un señor programón para trabajar con archivos comprimidos y cifrados. Si seguís usando #WinRAR notaréis mucha diferencia. Si ya veníais de usar #7zip quizá no notéis inmediatamente muchas funciones adicionales (que las hay) pero sí una mayor facilidad de uso e interfaz más agradable.

    alternativeto.net/news/2026/2/

    #Actualizacion #Actualizaciones #FOSS

  33. • 7-Zip: 25.01
    • WinRAR: 7.13 → 7.20 🆕
    • RAR Linux: 7.12 → 7.20 🆕
    • RAR macOS: 7.12 → 7.20 🆕
    • RAR Android: 7.20
    #7zip #WinRAR