惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

腾讯CDC
The Cloudflare Blog
IT之家
IT之家
V
V2EX
雷峰网
雷峰网
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky
Engineering at Meta
Engineering at Meta
S
SegmentFault 最新的问题
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
博客园 - 司徒正美
云风的 BLOG
云风的 BLOG
小众软件
小众软件
博客园 - 叶小钗
Blog — PlanetScale
Blog — PlanetScale
C
Check Point Blog
A
About on SuperTechFans
B
Blog
月光博客
月光博客
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI

Forbes - Consumer Tech

This Unhackable Quantum Navigation System Is The Size Of A Loaf Of Bread Apple At 50 — A Leadership Shift And An AR Future We Are Under-Investing In Robotics ... 90% Of Humanoid Robots Are Made In China Ditch The Apple White: Beats Expands Colorful Cable Line-Up With New 10-Foot Option Satechi’s New ChargeView 140W Desktop GaN Charger With Real-Time Display The Hasselblad In Your Pocket: Oppo’s Find X9 Ultra Challenges The Galaxy S26 Ultra There's No Such Thing As Brain Honey How AI Agents Could Rebuild Fashion’s Visual Production Layer Sennheiser’s New Closed-Back Headphones Are Made For The Studio QClaw Goes Global. The Agent Built Itself In 5 Days Apple’s Tim Cook Exit Hides A $4 Trillion Agentic AI Power Move EZQuest Reveals A New Line Of Pro Series USB-C Hubs For MacBook Neo Samsung Galaxy Z TriFold 2 Already In The Works, Report Claims Apple Revealed New Siri Release Date For iPhone, Latest Report Claims How Arcani’s HARK Is Designed For Modern Battlefield Acoustics The Newest Trend In Tech Embraces Femininity And Fun Samsung’s 75R95H Ushers In A New World Of LCD TVs New Apple iPhone Fold Design Pushes Smartphone Rivals To Go Wider And Taller iPhone 18 Pro Report: Four New Colors Leak As Apple Cancels Popular Shade Nothing’s Design-Led Strategy: Carl Pei Reveals The Tech Brand’s Philosophy iOS 26.5 Release Date: When To Expect Your iPhone Messaging Upgrade Google Pixel And Highsnobiety Build A Talent Pipeline For Fashion Android Circuit: Samsung Raises Galaxy Prices, Oppo Pad Mini Teased, Microsoft Closing Outlook App Apple Loop: iPhone Fold Launch Dates, iPad Air Upgrade, iPhone 18 Pro Specs Comcast $117.5 Million Breach Settlement — Are You Eligible? Amazfit Cheetah 2 Pro Takes Aim At The Garmin Audience Disney’s Launches ‘Infinity Vision’ Certification For Premium Theaters SoundPeats Reveals New Air6 HS Semi-Open Wireless Earbuds Amazon’s $11.57 Billion Leap Into Space: A Challenge To Starlink Meta Quest 3 Hit With $100 Price Increase
Adobe Attacks Underway—Windows And Mac Users Given 72 Hou...
Davey Winder · 2026-04-11 · via Forbes - Consumer Tech
Adobe Acrobat Reader (PDF) logo on smartphone screen.

Adobe Reader zero-day attacks ongoing.

SOPA Images/LightRocket via Getty Images

Update April 11: Adobe has now confirmed that CVE-2026-34621, a critical vulnerability affecting users of Adobe Acrobat and Reader on both Windows and macOS platforms, is already being exploited by attackers. The exploit can lead to arbitrary code execution and requires no user interaction beyond opening a malicious PDF document. Adobe has advised that the security update should be installed within 72 hours.

The use of Adobe PDF documents in cybersecurity threats is far from uncommon; they represent a primary “malicious document” attack surface for those using social engineering tactics, for example. When it comes to zero-day exploits targeting the Adobe Reader used to view such files, however, that’s a different matter. So, when a security researcher reveals a “highly sophisticated, fingerprinting-style PDF exploit" being used against such a zero-day vulnerability, you need to take it seriously. Perhaps even more so when those attacks have been ongoing since December 2025.

ForbesNew Google Security Warning For Android 14, 15 And 16 Users—Update Now

Sophisticated Adobe PDF Zero-Day Exploit—Attacks Against Adobe Reader Ongoing

A security researcher has confirmed that threat actors have been exploiting a zero-day vulnerability that exists within Adobe Reader, used to view Adobe PDF files, since at least December 2025. The critical vulnerability has now been comfirmed as CVE-2026-34621 by Adobe.

Haifei Li, best known for developing a sandbox-based exploit-detection platform called EXPMON, has warned that attackers are exploiting a “zero-day/unpatched vulnerability in Adobe Reader that allows it to execute privileged Acrobat Application Programming Interfaces, and it is confirmed to work on the latest version of Adobe Reader.”

The use of maliciously crafted Adobe PDF documents is, as mentioned previously, not exactly shocking nor new. Just ask Dropbox, Microsoft or PayPal users, and they will unhappily confirm that. This zero-day attack, however, isn’t reliant on a victim clicking a dodgy link in the PDF attachment, though. It’s much worse than that. The exploit “works on the latest version of Adobe Reader without requiring any user interaction beyond opening a PDF file,” Li warned.

ForbesAngry Hacker Drops Microsoft Zero-Day Exploit, 1 Billion Users WarnedBy Davey Winder

Another security researcher, posting on X as Gi7w0rm, said that it “seems to exploit part of Adobe Reader’s JavaScript engine,” and that the documents that have been seen to be used in attacks so far “contain Russian language lures and refer to issues regarding current events related to the oil and gas industry in Russia.”

I reached out to Adobe for a statement and advice for users, and a spokesperson confirmed that a security bulletin has now been added to address the vulnerability and that an update is now available for Adobe Acrobat and Reader for Windows and macOS.

Adobe security bulletin for CVE-2026-34621.

Adobe

The following products have updates available, and all have been given a priority one status by Adobe:

  • Acrobat DC
  • Acrobat Reader DC
  • Acrobat 2024

Users can update their software manually by choosing the Help|Check for Updates menu option. Adobe said that the software will “update automatically, without requiring user intervention, when updates are detected. “

As far as administrators in managed environments are concerned, Adobe recommended installing the updates “via your preferred methodology, such as AIP-GPO, bootstrapper, SCUP/SCCM for Windows, or on macOS, Apple Remote Desktop and SSH." Sorry to spoil your weekend folks.