In this briefing, Aaron Cole and Lauren Mitchell examine the discovery of a sophisticated Adobe Reader zero-day vulnerability that has been actively exploited since December 2025. The attack leverages maliciously crafted PDFs to harvest data from the Russian oil and gas sector before potentially escalating to remote code execution. We also pivot to an urgent advisory from the FBI and CISA regarding Iranian-affiliated actors disrupting U.S. critical infrastructure by targeting Rockwell Automation PLCs. Finally, we look at Russia's Forest Blizzard and their recent campaign of DNS hijacking via SOHO routers, which enabled global credential theft without traditional malware. This episode provides essential technical context for network defenders facing these evolving state-sponsored threats.
Topics Covered
- ⚠️ Adobe Reader zero-day PDF exploits and JavaScript obfuscation
- 🌐 Iranian APT targeting of Rockwell Automation industrial controllers
- 🔐 Russia's Forest Blizzard DNS hijacking and SOHO router compromises
- 🛡️ Mitigation strategies for internet-exposed PLCs and vulnerable firmware
Disclaimer: This program is for informational purposes only and does not constitute professional security advice.
Neural Newscast is AI-assisted, human reviewed. View our AI Transparency Policy at NeuralNewscast.com.



