⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More

This week's recap covers a critical Adobe 0-day, AI models being used for autonomous exploit generation, and sophisticated state-sponsored attacks targeting infrastructure and crypto assets.
Monday is back, and the weekend’s backlog of chaos is officially hitting the fan. We are tracking a critical zero-day that has been quietly living in your PDFs for months, plus some aggressive state-sponsored meddling in infrastructure that is finally coming to light. It is one of those mornings where the gap between a quiet shift and a full-blown incident response is basically non-existent.
The variety this week is particularly nasty. We have AI models being turned into autonomous exploit engines, North Korean groups playing the long game with social engineering, and fileless malware hitting enterprise workflows. There is also a major botnet takedown and new research proving that even fiber optic cables can be used to eavesdrop on your private conversations.
⚡ Threat of the Week: Adobe Acrobat Reader 0-Day Under Attack
Adobe released emergency updates to fix a critical security flaw in Acrobat Reader that has come under active exploitation in the wild. The vulnerability, assigned the CVE identifier CVE-2026-34621, carries a CVSS score of 8.6 out of 10.0.
Successful exploitation of the flaw could allow an attacker to run malicious code on affected installations. It has been described as a case of prototype pollution that could result in arbitrary code execution. The development comes days after security researcher Haifei Li disclosed details of zero-day exploitation of the flaw to run malicious JavaScript code when opening specially crafted PDF documents. There is evidence suggesting that the vulnerability may have been under exploitation since December 2025.
Your VPN is Helping Attackers Move as Fast as AI
The Zscaler ThreatLabz 2026 VPN Risk Report reveals a dangerous disconnect: while attackers use AI to move at machine speed, legacy VPNs are leaving defenders blind and exposed. When you can’t see what’s happening, response time collapses and the odds of containment drop with it.
U.S. Warns of Hacking Campaign by Iran-Affiliated Cyber Actors
U.S. agencies warned of a hacking campaign undertaken by Iranian threat actors hitting industrial control systems across the U.S. The attacks targeted programmable logic controllers (PLCs) in the energy sector, water utilities, and government facilities exposed to the public internet. The activity has resulted in operational disruption and financial loss, aimed at sabotaging critical systems.
Anthropic's Mythos Model is a 0-Day and Exploit Generation Engine
A closed consortium is getting early access to Mythos, a frontier model from Anthropic that can autonomously discover software vulnerabilities at scale. In early testing, the model identified thousands of high-severity vulnerabilities across operating systems and browsers. It can also devise exploits for N-day flaws in under a day, significantly compressing the timeline typically required for exploit development. Project Glasswing aims to apply these capabilities in a controlled, defensive setting before adversaries can weaponize similar tech.
Law Enforcement Operation Fells APT28 Router Botnet
APT28 (Forest Blizzard) has been exploiting vulnerabilities in SOHO routers to change DNS settings and redirect victims to credential-theft sites. By modifying the router's DNS resolver, every device connecting through it unknowingly forwards requests to Russian intelligence-controlled infrastructure. For high-priority targets, the group escalated to Adversary-in-the-Middle (AiTM) attacks to intercept sensitive traffic, including Microsoft Outlook Web Access data.
Drift Protocol Links $285M Hack to North Korea
Drift Protocol revealed that a North Korean state-linked group spent six months posing as a quantitative trading firm to steal $285 million in digital assets. The group built trust through in-person meetings and Telegram coordination before executing the exploit and vanishing. This incident marks a growing pattern of highly patient social engineering attacks targeting the cryptocurrency sector.
Source: The Hacker News
















