A serious security flaw has been discovered in WinRAR, a widely used file compression tool.
Hackers from the RomCom group are actively exploiting this vulnerability through phishing emails containing malicious RAR files. When opened using outdated versions of WinRAR, these files can install malware on victims’ computers.
The flaw allows attackers to place harmful programs into the Windows Startup folder, enabling the malware to run automatically whenever the user logs in, without their knowledge.
WinRAR has fixed this vulnerability in the latest version 7.13. Since WinRAR does not update automatically, users must manually download and install the update to protect their systems.
Security experts advise caution when opening email attachments, especially from unknown sources. Regularly updating WinRAR and other software is essential to defend against such cyberattacks.





