A vulnerability exists in the default KDE extraction utility called ARK that allows attackers to overwrite files or execute code on victim’s computers simply by tricking them into downloading an archive and extracting it. Once a user opens the archive, the attacker can create autostarts that automatically launch programs that could encrypt a user’s files with ransomware, install miners, or install backdoors that give remote attackers shell access to a victim’s account. The bug was quickly fixed in Ark 20.08.0, which was released today.”]

