惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
小众软件
小众软件
The Cloudflare Blog
S
SegmentFault 最新的问题
美团技术团队
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
阮一峰的网络日志
阮一峰的网络日志
博客园 - 聂微东
V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
雷峰网
雷峰网
WordPress大学
WordPress大学
T
Tailwind CSS Blog
腾讯CDC
人人都是产品经理
人人都是产品经理
月光博客
月光博客
Microsoft Azure Blog
Microsoft Azure Blog
M
MIT News - Artificial intelligence
D
DataBreaches.Net
Apple Machine Learning Research
Apple Machine Learning Research
P
Proofpoint News Feed
J
Java Code Geeks
宝玉的分享
宝玉的分享

Sophos Blogs

Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation 2026 MSP Perspectives Report: How MSPs Are Scaling Cybersecurity Leadership Sophos Next-Gen SIEM Unifies Security Operations and Compliance Messageboards Are All They Need ATT&CK grew a 15th tactic: A practical DFIR field guide to the Stealth / Defense Impairment split Devil’s advocate? Uncensored Luciferus AI service advertised underground “Eye” spy: Cyclops Blink returns with extended capabilities Ransomware in Education 2026: Key Findings Sophos Joins OpenAI’s Call for Collective Cyber Defense Sophos Ranked #1 Overall Across Endpoint, XDR, MDR, and Firewall in G2 Fall 2026 Reports Fake AI, real malware: Attackers impersonating AI brands A heap of overflow in August’s Patch Tuesday haul Accelerating NetNTLMv1 Lookups Without GPUs Abuse of alternative runtime environments Deno-tes defender headaches ClickFix campaign abuses Deno runtime for infostealer delivery Sophos Working with OpenAI on security from AI, with AI, and for AI N-able N-central exploitation results in RMM tool deployment Interlock ransomware gang creates volatile situation When AI doesn’t know the target is real Chaos in Teams vishing Why Sophos Has Become Its Own AI Test Lab July Patch Tuesday only feels endless SonicWall SMA1000 vulnerabilities in active exploitation When AI agents look like attackers: what behavioral telemetry tells us Sophos and the Cybersecurity Poverty Line You do surprise me.exe: An unexpected executable in Hola Browser You do surprise me.exe: An unexpected executable in Hola Browser Pointing a Cursor at evading detection Pointing a Cursor at evading detection Pointing a Cursor at evading detection
Adobe Reader zero-day vulnerability in active exploitation
About the author · 2026-04-09 · via Sophos Blogs

On April 7, 2026, a security researcher described an Adobe Reader zero-day vulnerability that has been exploited since at least December 2025. The vulnerability allows threat actors to execute privileged Acrobat APIs via specially crafted malicious PDF files that execute obfuscated JavaScript when opened. Exploitation allows attackers to steal sensitive user and system data and to potentially launch additional attacks and remotely execute code.

Another security researcher noted that the Russian-language lures relate to the Russian oil and gas sector. These details suggest that the attacks are targeted rather than opportunistic.

Recommended actions

Counter Threat Unit™ (CTU) researchers recommend that organizations monitor for an official Adobe patch and update systems as appropriate when available. In the meantime, organizations can reduce the risk by automatically scanning PDF email attachments, blocking suspicious files, training users to be wary of unsolicited attachments, and advising users to temporarily avoid using Adobe Reader to open PDFs.

Protections and threat indicators

The following Sophos protections relate to this threat:

  • Troj/PDF‑BG
  • Malware/Callhome

The threat indicators in Table 1 can be used to detect activity related to this threat. Note that IP addresses can be reallocated. The domain and IP addresses may contain malicious content, so consider the risks before opening them in a browser.

IndicatorTypeContext
1929da3ef904efb8c940679045452321MD5 hashMalicious PDF sample in Adobe Reader attacks (yummy_adobe_exploit_uwu.pdf)
7f3c6f97612dd0a018797f99fad4df754e5feb35SHA1 hashMalicious PDF sample in Adobe Reader attacks (yummy_adobe_exploit_uwu.pdf)
65dca34b04416f9a113f09718cbe51e11fd58e7287b7863e37f393ed4d25dde7SHA256 hashMalicious PDF sample in Adobe Reader attacks (yummy_adobe_exploit_uwu.pdf)
522cda0c18b410daa033dc66c48eb75aMD5 hashMalicious PDF lure in Adobe Reader attacks (Invoice540.pdf)
dafd571da1df72fb53bcd250e8b901103b51d6e4SHA1 hashMalicious PDF lure in Adobe Reader attacks (Invoice540.pdf)
54077a5b15638e354fa02318623775b7a1cc0e8c21e59bcbab333035369e377fSHA256 hashMalicious PDF lure in Adobe Reader attacks (Invoice540.pdf)
ado-read-parser[.]comDomain nameC2 server in Adobe Reader attacks
169[.]40[.]2[.]68:45191IP address:portC2 server in Adobe Reader attacks
188[.]214[.]34[.]20:34123IP address:portC2 server in Adobe Reader attacks
Adobe SynchronizerUser-AgentAssociated with Adobe Reader attacks

Table 1: Indicators for this threat

References

https://justhaifei1.blogspot.com/2026/04/expmon-detected-sophisticated-zero-day-adobe-reader.html

https://x.com/Gi7w0rm/status/2042003381158379554 

https://thehackernews.com/2026/03/adobe-reader-zero-day-targeted-attacks.html

https://www.theregister.com/2026/04/09/monthsold_adobe_reader_zeroday_uses/

https://www.bleepingcomputer.com/news/security/hackers-exploiting-acrobat-reader-zero-day-flaw-since-december/

https://www.securityweek.com/adobe-reader-zero-day-exploited-for-months-researcher/

https://thecyberexpress.com/zero-day-fingerprinting-attack-on-adobe-reader/