Google's Threat Analysis Group has found instances of hackers exploiting a glitch in how WinRAR handles file-name matching when trying to unzip an archive.
www.theverge.com
WinRAR doesn't have an auto-updater, so anyone who uses it needs to go to their site and get the newest version.

PSA: it’s time to update WinRAR due to a big security vulnerability
WinRAR doesn’t have an auto-update feature, so it’s time to download and install.
WinRAR doesn't have an auto-updater, so anyone who uses it needs to go to their site and get the newest version.