
Daily Cybersecurity News - April 9, 2026
Adobe Patches Critical Reader Flaw
Executive Summary
Security researcher Haifei Li (EXPMON) has discovered a sophisticated zero-day vulnerability in Adobe Reader that is being actively exploited in the wild since at least December 2025 (with samples dating back to November 2025).
Threat actors are using highly advanced, fingerprinting-style malicious PDFs that abuse an unpatched flaw to execute privileged Acrobat APIs, collect and leak sensitive information, and potentially enable remote code execution or sandbox escape. Adobe has been notified.
Vulnerability Details
- Affected Product: Latest versions of Adobe Reader and Acrobat (zero-day - unpatched)
- Identifier: Zero-day (no public CVE assigned yet)
- CVSS Score: Not yet assigned
- Exploitation Status: Actively Exploited
Risk & Impact
- Triage: Critical. Immediate caution is required as this zero-day is being used in targeted attacks with no patch currently available.
- Attack Vector: An attacker could trick a user into opening a specially crafted PDF file, which triggers the vulnerability.
- Ease of Exploit: Public exploit samples exist on VirusTotal; the PDF-based attack is described as highly sophisticated.
Action Plan
- Immediate Action: Exercise extreme caution with any PDF files and await an official Adobe security update (Adobe has been notified of the issue).
- Workaround: Avoid opening PDF files from untrusted or unknown sources.
- Detection: Monitor for suspicious PDF files, particularly those with Russian-language lures related to the oil and gas industry, which were used in the exploit campaign.
Relevant professional terms
- Zero-Day Vulnerability
- A flaw in software or hardware that is unknown to the party responsible for patching it. Attackers can exploit it before the vendor becomes aware and releases a fix.
- Arbitrary Code Execution
- An attacker's ability to execute any commands or code of their choice on a target machine or in a target process. This can lead to full system compromise.
Source: SecurityWeek
Russian APT Hijacks Routers for Espionage
Executive Summary
Russia's APT28 (Forest Blizzard) is conducting a large-scale, malwareless cyber-espionage campaign by compromising vulnerable SOHO routers. The group modifies DNS settings to intercept traffic and steal credentials from government, military, and critical infrastructure targets worldwide.
Key TTPs
- Initial Access: Exploiting known vulnerabilities and weak default passwords on SOHO routers from brands like TP-Link and MikroTik.
- Execution: Altering router DNS settings to redirect traffic to actor-controlled infrastructure for credential harvesting.
- Defense Evasion: Using a "malwareless" approach by living off the land, which makes detection difficult as no malicious files are written to disk.
Campaign Analysis
This campaign marks a significant tactical shift for APT28, moving away from malware to large-scale DNS hijacking for stealthy intelligence gathering. By compromising edge devices, the actor creates a persistent and hard-to-detect pathway into sensitive enterprise and government networks.
Targeting & Infrastructure
- Target Profile: Government, military, IT, telecommunications, and energy sectors across North America, Europe, Asia, and Africa.
- Infrastructure: A global network of over 18,000 compromised SOHO routers used to proxy traffic and conduct adversary-in-the-middle attacks.
Relevant Terms
- DNS Hijacking: The malicious redirection of a device's Domain Name System queries to attacker-controlled servers, allowing them to intercept or manipulate network traffic.
- Adversary-in-the-Middle (AiTM): An attack where threat actors secretly position themselves between two parties to intercept and relay communications, stealing data like credentials and session tokens.
Source: Dark Reading
Meta Insider Steals Private User Photos
Executive Summary
The UK's Metropolitan Police are investigating a former Meta engineer for allegedly downloading 30,000 private Facebook images. The employee reportedly built a custom script to bypass internal security, highlighting a significant insider threat at the tech giant.
The Scheme
- TTP 1: Abused insider privileges as an employee to access sensitive user data.
- TTP 2: Developed a custom script to programmatically access and download photos.
- TTP 3: Engineered the script to circumvent Meta's internal detection systems and security checks.
The Consequence
- Outcome: A man in his 30s was arrested in November 2025 and is currently on police bail pending the criminal investigation.
Strategic Takeaway
This incident underscores that even companies with advanced security postures are vulnerable to sophisticated insider threats who can create custom tools to bypass established protocols.
Relevant Terms
- Insider Threat: A security risk originating from within an organization, typically from an employee or former employee with authorized access.
- Detection Systems: Software and hardware designed to identify malicious activity or policy violations on a network or system.
Source: Malwarebytes