Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088

2026-06-10T20:51:46Z3ceb3f1bdf114f7648797b0cbe8eab354b394d66414fa80cc829fd7aaad5e2f8
AI-wormArista EOSBerriAICISACVE-2025-8088CVE-2026-11645CVE-2026-44963Chaotic EclipseCheck PointChromeCisco Catalyst SD-WANFranceGitHub-compromiseGoogle V8Miasma-wormMicrosoft DefenderMicrosoft Patch TuesdayRoguePlanetTchapV8Veeamautonomous-malwareknown-exploited-vulnerabilitieswinrarzero-day

What happened

A batch of high-impact security developments: Russian-linked APTs continue exploiting a patched WinRAR path-traversal (CVE-2025-8088) via phishing archives; CISA added multiple flaws (including Check Point and BerriAI LiteLLM entries) to its Known Exploited Vulnerabilities catalog; a public PoC for the RoguePlanet Microsoft Defender zero-day (local race condition to obtain SYSTEM on fully patched Windows) was released; researchers demonstrated AI-powered autonomous “worms” that adapt to Windows, Linux and IoT targets; France’s government messaging app Tchap was breached through a single-compom

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
3ceb3f1bdf114f7648797b0cbe8eab354b394d66414fa80cc829fd7aaad5e2f8
Enrichment time
2026-06-10T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Russian APTs Still Exploiting Patched WinRAR Flaw CVE-2025-8088 · Baitaphish