Switch language한국어
Back to the list

PDF Warning—Adobe Reader Zero-Day Attack Ongoing Since 2025

TL;DR AI

Key summary

2 min read
  1. Threat actors have exploited an Adobe Reader zero-day since at least December 2025.

  2. The flaw is still unpatched and works in the latest Adobe Reader release.

  3. Opening a PDF is enough to trigger the exploit; no extra user action is needed.

  4. The bug can invoke privileged Acrobat APIs and may target part of Reader's JavaScript engine.

  5. Attack documents use Russian-language lures about Russia's oil and gas industry, and Adobe security bulletin pages do not mention the attacks yet.

Read the original