Vulnerabilità · 168 giorni fa
Un nuovo exploit zero-day in Adobe Acrobat Reader rompe l'assunto che i PDF dannosi agiscano come attacchi one-shot. Invece, questi PDF eseguono prima il fingerprinting dell'ambiente host ed esfiltrano silenziosamente dati di sistema prima di consegnare payloads personalizzati di remote code execution o escape dalla sandbox. Questo approccio a fasi significa che i metodi di rilevamento standard, focalizzati su malware visibile o crash, non rilevano il compromesso iniziale e la perdita di dati.
8 fonti che coprono questa storia
Adobe fixes PDF zero-day security bug that hackers have exploited for months | TechCrunch
It's not clear how many people were compromised by this hacking campaign, but a security researcher said the hackers were targeting victims since at least November 2025.
Adobe Patches Actively Exploited Zero-Day That Lingered for Months
An attacker has been using maliciously crafted PDF files to exploit a zero-day in Adobe Acrobat and Reader for at least four months.
Adobe Patches Reader Zero-Day Exploited for Months
The vulnerability is tracked as CVE-2026-34621 and Adobe has confirmed that it can be exploited for arbitrary code execution.
Adobe Reader Zero-Day Exploited via Malicious PDFs Since December 2025
Adobe Reader zero-day exploited since Dec 2025 via malicious PDFs, enabling data theft and potential RCE, prompting urgent security vigilance.
Old Adobe Reader zero-day uses PDFs to size up targets
: Malicious PDFs abuse legit features to harvest system data and decide which victims get a 2nd-stage payload
Acrobat Reader zero-day exploited in the wild for many months - Help Net Security
Unknown attackers have exploited a zero-day Adobe Acrobat Reader vulnerability since November 2025 and possibly even earlier.
Adobe Reader Zero-Day Exploited for Months: Researcher
Reputable researcher Haifei Li has come across what appears to be a PDF designed to exploit an unpatched vulnerability.
Hackers exploiting Acrobat Reader zero-day flaw since December
Attackers have been exploiting a zero-day vulnerability in Adobe Reader using maliciously crafted PDF documents since at least December.
Adobe Reader zero-day vulnerability in active exploitation
A zero-day vulnerability in Adobe Reader has been exploited since at least December 2025
Part of the PlainSec briefing for 2026-04-14