Germán Fernández[verified]@1ZRR4HExploit
The post advertises an environment with AI-generated tools aimed at testing CVE‑2025‑6218 bypasses and includes links to potential exploit binaries, signalling possible exploitation activity without confirming real-world use.
Askar Dyussekeyev[verified]@askardyussActive Exploitation
The post reports an active cyber‑espionage campaign exploiting WinRAR’s CVE‑2025‑6218 via a malicious ZIP archive that uses NTFS ADS to drop an LNK to the Startup folder, delivering a payload and masking activity behind a legitimate URL.
Szabolcs Schmidt[verified]@smica83Active Exploitation
Malware sample linked to CVE-2025-6218 and CVE-2025-8088 has been observed in Ukraine, indicating active exploitation.
Szabolcs Schmidt[verified]@smica83Disclosure
A ransomware ZIP sample from Poland, containing CVE‑2025‑6218 and CVE‑8088, was posted on Abuse.ch; no PoC, exploit code, patch, or active‑exploitation details are provided.
Szabolcs Schmidt[verified]@smica83PoC
The post shares a sample linked to CVE‑2025‑6218 and references an 8088 exploit, but provides no patch, active exploitation info, or detailed technical data.
Szabolcs Schmidt[verified]@smica83Active Exploitation
The tweet reports that CVE-2025-6218 and CVE-2025-8088 exploits were seen in use in Argentina, providing a sample link and indicating active exploitation in the wild.
Szabolcs Schmidt[verified]@smica83PoC
The tweet references a malware sample linked on Abuse.ch Bazaar associated with CVE-2025-6218 and CVE-2025-8088, indicating that a PoC exists.
Szabolcs Schmidt[verified]@smica83General
The tweet references a sample linked to CVE‑2025‑6218 and 8088 but provides no concrete PoC, exploit code, patches, or technical details.