WinRAR Flaw Exploited by Russia-Aligned Groups to Deploy Stealers in Ukraine
2026-06-09T13:24:13Z•1db71cabbf9aa6693fc3d0bd38df8c5ef521cbe03d4b4df2564b36874b57ed86
AI-securityactive-exploitationmalwarenetwork-devicesprivilege-escalationself-replicating-wormstealersupply-chainvulnerability-managementzero-day
What happened
Multiple high-impact security incidents and active exploitations were reported: Russia-aligned groups are exploiting a WinRAR path-traversal (CVE-2025-8088) to deploy stealers in Ukraine; a Chrome V8 zero-day (CVE-2026-11645) is being actively exploited; LiteLLM (BerriAI) command-injection (CVE-2026-42271) is confirmed in the wild and added to CISA KEV; a one-character Linux kernel use-after-free (CVE-2026-23111) has a public local-root exploit; a critical Check Point IKEv1 certificate-validation bypass (CVE-2026-50751) is actively exploited; Cisco Catalyst SD-WAN Manager (CVE-2026-20245) and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 1db71cabbf9aa6693fc3d0bd38df8c5ef521cbe03d4b4df2564b36874b57ed86
- Enrichment time
- 2026-06-09T13:24:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.