BERLIN - Security researchers at the Fraunhofer Institute and an incident-response collective calling itself Grayhand disclosed a WinRAR zero-day on Friday that allows code execution the moment a booby-trapped archive is extracted. The teams, working with Germany’s BSI and two EU bank CERTs, say the exploit has already been used in targeted intrusions against financial trading desks and treasury ops. Indicators point to spear-phished archives posing as settlement packets and...