Hackers Actively Attacking Adobe Reader Users Using Sophisticated 0-Day Exploit
ID: 9466d51a-0551-59ef-9cad-5dfcf06db0bd
STIX ID: report--9466d51a-0551-59ef-9cad-5dfcf06db0bd
Feed Name: cybersecurityNews.com
A zero-day Adobe Reader vulnerability is actively exploited via a crafted PDF that uses embedded/obfuscated JavaScript to bypass sandboxing (util.readFileIntoStream) and exfiltrate local files to attacker infrastructure (noted IP 169.40.2.68:45191), perform advanced system fingerprinting, and dynamically retrieve encrypted secondary payloads capable of RCE and sandbox escape; defenders are advised to block the reported IP, monitor for the "Adobe Synchronizer" User-Agent, and avoid opening untrusted PDFs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
