Hackers exploiting Acrobat Reader zero-day flaw since December
ID: dc0b200e-7728-5be8-a20b-04c9002b4cd9
STIX ID: report--dc0b200e-7728-5be8-a20b-04c9002b4cd9
Feed Name: Bleeping Computer
Attackers are exploiting a zero-day Adobe Reader vulnerability via maliciously crafted PDFs that perform fingerprinting-style exploitation to steal local data using privileged Acrobat APIs and may enable subsequent RCE and full system compromise; discoveries were reported by researcher Haifei Li and analyst Gi7w0rm, PDFs include Russian-language lures, Adobe has been notified, and mitigations include avoiding untrusted PDFs and blocking HTTP(S) requests with the "Adobe Synchronizer" User-Agent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
