Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen

7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen

Posted on August 5, 2026 By CWS

7-Zip Bypass of SmartScreen Check

Recent findings reveal a security vulnerability in 7-Zip that allows malicious files to bypass Windows SmartScreen, potentially leaving users exposed. This issue arises from how 7-Zip handles metadata related to file downloads, particularly the absence of the Mark-of-the-Web (MotW) tag on extracted files from ZIP archives.

ZIP files are frequently used in phishing attacks, often disguised as legitimate documents to lure unsuspecting users. The problem intensifies when these archives are opened with 7-Zip, as the software fails to retain the MotW tag, a crucial security marker.

Understanding the Mark-of-the-Web

Mark-of-the-Web is a metadata tag that informs Windows that a file originated from the internet, prompting additional security checks. This tag is stored in the Zone.Identifier stream, typically marking files with ZoneId=3 to indicate their online origin. Without this tag, Windows SmartScreen may not perform its reputation checks, allowing potentially harmful files to execute without user warnings.

In tests conducted by Attackd analysts, files extracted with 7-Zip version 24.09 lacked the Zone.Identifier stream, bypassing SmartScreen’s reputation checks upon execution. This behavior mirrors previous vulnerabilities but highlights a gap in the default settings rather than a newly identified exploit.

Implications for Cybersecurity

The absence of the MotW tag poses significant risks, especially as files may evade initial antivirus checks while bypassing SmartScreen. This gap underscores the need for comprehensive security strategies that consider how different tools interact within the system. Proper configuration and awareness can mitigate some of these risks.

Windows 11’s Explorer now propagates the MotW tag for password-protected ZIP files, a feature not enabled by default in 7-Zip. Enabling the “Propagate Zone.Id stream” setting in 7-Zip can ensure the metadata follows extracted files, enhancing security.

Enhancing Protection Strategies

Organizations must conduct thorough reviews of their file-processing tools and configurations. Testing realistic user behavior scenarios, such as browser downloads and file extractions, is crucial to understanding potential vulnerabilities. Consistent monitoring and training can help users recognize threats, even when warnings are absent.

Security teams should also keep their software updated and avoid opening unsolicited compressed files. These measures, combined with a comprehensive understanding of how tools like 7-Zip handle metadata, can significantly bolster defenses against phishing and malware threats.

As the landscape of cybersecurity threats evolves, understanding and addressing software vulnerabilities remain critical. By adapting configurations and staying informed, organizations can better protect themselves from exploitation attempts.

Cyber Security News Tags:7-Zip, 7-Zip flaw, archive security, Cybersecurity, endpoint protection, file metadata, internet security, malicious files, Malware, Mark-of-the-Web, MOTW, Phishing, SmartScreen, Windows security, Zone.Identifier

Post navigation

Previous Post: ChainDrop Attack Infects Over 400 NPM Packages

Related Posts

Betterleaks: The Advanced Open-Source Secrets Scanner Betterleaks: The Advanced Open-Source Secrets Scanner Cyber Security News
Researchers Gain Access to StealC Malware Command-and-Control Systems Researchers Gain Access to StealC Malware Command-and-Control Systems Cyber Security News
Halo Security Achieves SOC 2 Type 1 Compliance Halo Security Achieves SOC 2 Type 1 Compliance Cyber Security News
Indian Bank Alerts on LPG Payment Scams Threatening Accounts Indian Bank Alerts on LPG Payment Scams Threatening Accounts Cyber Security News
Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts Critical 0-Day RCE Vulnerability in Networking Devices Exposes 70,000+ Hosts Cyber Security News
131 Malicious Extensions Targeting WhatsApp Used Found in Chrome Web Store 131 Malicious Extensions Targeting WhatsApp Used Found in Chrome Web Store Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • 7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen
  • ChainDrop Attack Infects Over 400 NPM Packages
  • Cybersecurity Evaluation Unveils AI Vulnerabilities
  • Botnet Targets Router Diagnostic Tools for Exploitation
  • Cyberattacks on Water Systems Impact Multiple US States

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • 7-Zip Flaw Lets Malicious Files Skirt Windows SmartScreen
  • ChainDrop Attack Infects Over 400 NPM Packages
  • Cybersecurity Evaluation Unveils AI Vulnerabilities
  • Botnet Targets Router Diagnostic Tools for Exploitation
  • Cyberattacks on Water Systems Impact Multiple US States

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark