Back to news

WinRAR Bug Hits Ukraine; Meta AI Bot Exploited to Hijack Instagram Accounts

Two separate threat campaigns this week exposed critical gaps in patch management and AI-assisted account security.

WinRAR Bug Hits Ukraine; Meta AI Bot Exploited to Hijack Instagram Accounts

What happened

Russia-aligned threat groups Earth Dahu and SHADOW-EARTH-066 — better known as Gamaredon and UAC-0226 — have been actively exploiting a path traversal vulnerability in WinRAR, tracked as CVE-2025-8088, to deploy information-stealing malware against Ukrainian organizations. Patches for the flaw have been available for nearly a year, yet targeted attacks continue unabated, according to Trend Micro research. In a separate incident, high-profile Instagram accounts — including those belonging to the Obama White House archive and a senior U.S. Space Force official — were temporarily defaced with pro-Iranian imagery after step-by-step instructions for abusing Meta's AI support chatbot spread through Telegram. Attackers discovered the bot could be manipulated into initiating unauthorized password resets, bypassing standard account recovery safeguards.

Why it matters for your business

The ongoing WinRAR exploitation is a stark reminder that unpatched legacy software remains one of the most reliable entry points for state-sponsored actors — and not only in conflict zones. Organizations anywhere that handle sensitive data and still run unpatched archiving tools are exposed to credential theft and lateral movement. The Meta AI incident raises a distinct but equally urgent concern: as enterprises deploy AI-powered support interfaces for customers and employees, each new chatbot capability becomes a potential social-engineering surface. Security teams should audit any AI assistant that has the authority to trigger account or credential changes, enforce out-of-band verification steps, and treat AI-mediated account actions with the same skepticism applied to a phone-based help desk call.

What to watch next

Meta has not yet detailed what guardrail changes, if any, have been implemented following the Instagram incidents, making further opportunistic abuse likely until a formal fix is confirmed. On the WinRAR front, security researchers will be watching whether exploitation widens beyond Ukrainian targets as threat groups test the vulnerability against Western infrastructure. Both cases are expected to feature prominently in upcoming government cybersecurity advisories, and affected vendors may face regulatory pressure to accelerate mandatory patching timelines and impose stricter controls on AI assistant permissions.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp