logo

Hackers Actively Attacking Adobe Reader Users Using Sophisticated 0-Day Exploit

ID: 9466d51a-0551-59ef-9cad-5dfcf06db0bd

STIX ID: report--9466d51a-0551-59ef-9cad-5dfcf06db0bd

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-08

Date Updated: 2026-04-21

Author: Abinaya

...
...

A zero-day Adobe Reader vulnerability is actively exploited via a crafted PDF that uses embedded/obfuscated JavaScript to bypass sandboxing (util.readFileIntoStream) and exfiltrate local files to attacker infrastructure (noted IP 169.40.2.68:45191), perform advanced system fingerprinting, and dynamically retrieve encrypted secondary payloads capable of RCE and sandbox escape; defenders are advised to block the reported IP, monitor for the "Adobe Synchronizer" User-Agent, and avoid opening untrusted PDFs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.