A flaw in 7Zip software has been actively exploited by Russian hacker groups since September 2024, targeting Ukrainian users and bypassing Windows' Mark of the Web feature, but a fix has been released in version 24.09 and users are advised to update to protect against potential attacks.
- Fix for the flaw has been implemented in the latest version of 7Zip
- Provides an extra layer of protection against potentially unknown files
- Staying up to date with software patches and security updates is crucial
A flaw in the popular software 7Zip has been actively exploited since September 2024, with Ukrainian users being the primary targets. This vulnerability is associated with a Windows feature called Mark of the Web (MotW), which applies restrictions to downloaded files from the internet. The intention is to provide an extra layer of protection against potentially unknown files.
Now, MotW doesn’t prevent malware from running, but it can help prevent executables from directly launching on the system, requiring user confirmation first. However, according to researchers at the security company Trend Micro, hacker groups are exploiting a flaw in 7Zip to remove this file marking and bypass the imposed limitations.
The flaw was discovered on September 25, 2024, and it’s believed that Russian groups have been using it to target entities in Ukraine. By exploiting this flaw, they aim to increase the success rates of their attacks. These malicious files, designed to exploit the 7Zip vulnerability, are typically sent as suspicious email attachments or phishing attempts, disguised as Word documents or PDFs.
Fortunately, a fix for this flaw has been implemented in the 7Zip version 24.09, which was released on November 30. While the vulnerability has been confirmed with specific attacks, it is still highly recommended for users to update their 7Zip software as soon as possible. It’s worth noting that the program does not have an automatic update system, so users will need to manually download and install the latest version.
In a world where cyber threats are constantly evolving, staying up to date with software patches and security updates is crucial. So, if you’re a 7Zip user, take a moment to ensure you’re running the latest version. It’s a small step that can go a long way in protecting your digital world. Stay safe out there!
About Our Team
Our team comprises industry insiders with extensive experience in computers, semiconductors, games, and consumer electronics. With decades of collective experience, we’re committed to delivering timely, accurate, and engaging news content to our readers.
Trending Posts
ASRock Addresses AMD Platform Issues: No Boot and CPU Damage Concerns Explained
Sharkoon introduces Rebel P10 Series: A Fresh Take on ATX 3.1 Power Supplies
NVIDIA’s Latest Update Introduces Project G-Assist and Enhanced DLSS Customization Options
SMART Modular introduces New Non-Volatile CXL E3.S Memory Module for Data Centers
DrayTek Routers Unexpectedly Restart: Possible Coordinated Attack
Evergreen Posts
NZXT about to launch the H6 Flow RGB, a HYTE Y60’ish Mid tower case
Intel’s CPU Roadmap: 15th Gen Arrow Lake Arriving Q4 2024, Panther Lake and Nova Lake Follow
HYTE teases the “HYTE Y70 Touch” case with large touch screen
NVIDIA’s Data-Center Roadmap Reveals GB200 and GX200 GPUs for 2024-2025
Intel introduces Impressive 15th Gen Core i7-15700K and Core i9-15900K: Release Date Imminent