Adobe Reader Zero-Day Exploited to Steal Data via Malicious PDFs

2026-04-09T20:51:44Ze4bb89ea1f5635c52f027161fa6f185206336ea474442431a8904531217d4829
AI injectionAdobe ReaderCLAUDE.mdClaude CodeClickFixDNS hijackingForest BlizzardGRUGrafanaGrafanaGhostMedusa ransomwareNode.js malwareOperation MasqueradeSQL injectionStorm-1175Tor-based malware','Monero mining','REF1695','threat intel','AI‑active exploitationcrypto wallet theftmacOS malwaremalicious PDFnotnullOSXprompt injectionrapid exploitationrouter hijackingzero-day

What happened

Multiple high-impact threats reported: an unpatched Adobe Reader zero-day is being actively exploited via malicious PDFs to steal data; GrafanaGhost — a critical AI-component vulnerability — enables data exfiltration via injection; LayerX demonstrated how Claude Code’s CLAUDE.md can be abused to bypass safety controls and perform SQL injection; and Storm-1175 is rapidly weaponizing disclosed flaws to deploy Medusa ransomware within 24 hours against healthcare and education. Additional notable incidents include Russian state-linked router DNS hijacking (Operation Masquerade / Forest Blizzard),

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
e4bb89ea1f5635c52f027161fa6f185206336ea474442431a8904531217d4829
Enrichment time
2026-04-09T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.