Users who have not updated the WinRAR patch, despite being warned, continue to take advantage of the vulnerability to insert malicious code.
WinRAR, data compression and decompression software, is one of the most popular software for any computer user. Earlier this month, CheckPoint Software's security experts announced a serious vulnerability that lasted 19 years on WinRAR software, and hackers could easily take advantage of it to spread malicious code.
WinRAR programmers have released a patch update on version 5.70 beta 1, but because many users do not update to the latest version, the problem is not resolved at the root. Hackers can continue to take advantage of this vulnerability to embed malicious code in a compressed file, when the user decompresses the malicious code, it will be started and run in the background.
To easily deceive users into downloading and extracting, hackers have embedded malicious code into sexy photos to stimulate their curiosity. Hackers used this flaw to attack Middle Eastern countries or Korean government agencies before the day when the US-Trieu summit took place in Vietnam.
Once again, security experts recommend users to quickly update to the latest version of WinRAR 5.70 Beta 1 from their official website, and away from ACE-formatted files and image files. Sexy on the Internet to protect yourself.
- https://www.win-rar.com/affdownload/download.php
You should read it
- Detecting serious security flaws that exist for more than 19 years on WinRAR, can affect 500 million users
- Vulnerability in WinRAR puts users at risk of being attacked
- Detecting new malware on WinRAR can infiltrate computers and steal data
- WinRAR is really free version, please download and experience
- Why does Winrar give you a free trial for a lifetime?
- Instructions for notes with WinRAR
- WinRAR settings automatically delete the root directory after decompressing the data
- How to Use WinRAR
May be interested
- Malware sneaks into iOS through Apple's official distribution channelstaking advantage of distribution channels of unapproved applications for testing purposes, malicious code has quietly sneaked into ios users' devices.
- PrintNightMare vulnerability patch is flawed, attackers can still 'break through'yesterday, microsoft released a patch for the printnightmare zero-day vulnerability. this bug allows attackers to remotely execute code on fully patched print spooler devices.
- Microsoft urgently patched zero-day vulnerability after 2 years of refusing to acknowledge itmicrosoft has just released security updates to fix a high-severity zero-day vulnerability in windows.
- Warning: The new Facebook virus, a malicious code that is spreading rapidly through Messengerfrom yesterday (december 18, 2017), a new type of malicious code has appeared and raged in vietnam. this malicious code is not too sophisticated but is spreading very fast through facebook messenger because it is sent from the friends in the friend list.
- Microsoft updated Patch Tuesday in October 2020, patching the 'Ping of Death' vulnerability on Windows 10patch tuesday's security update by windows 10 this month fixes a fairly serious security hole.
- Dell computers became victims of RCE attacks by vulnerabilities in SupportAssistdell recently quietly released a new security update to patch the supportassist client software vulnerability, potentially allowing attackers to not authenticate on the same network access layer using executable malware from away from arbitrary privileges on the victim's computer.
- Microsoft urges Admin to patch PowerShell vulnerability on Windowsmicrosoft has just asked for it admins of organizations and businesses to immediately patch the vulnerability in powershell 7. the reason is that this vulnerability allows hackers to bypass windows defender application control (wdac) enforcement measures.
- Immediately patch CWP vulnerability that allows code execution as root on Linux serverssecurity researchers have discovered two new vulnerabilities affecting control web panel (cwp) software. hackers could chain these two vulnerabilities to gain remote code execution (rce) privileges as root on vulnerable linux servers.
- Hackers take advantage of the panic in the Corona virus epidemic to spread malware on the internetthe acute coronary pneumonia outbreak due to the new strain of corona virus - ncov-2019 (wuhan flu) is one of the world's top news.
- Apple Patches Zero-Day Vulnerability That Could Let iPhones, iPads, and MacBooks Get Hackedapple has just released a security update to patch two zero-day vulnerabilities. in it, one has been made public and another is being exploited by hackers to penetrate iphones and macs. these are the first zero-day vulnerabilities that apple will patch in 2022.