
@NathanMcNulty BuT We WaNt tO StAnDaRdIsE oUr DePLoYmEnTs AnD PaTcHiNg fOr SiMpLiCiTy
English
Devang
3.8K posts

@devangchheda_
Part-time IT guy @ Contoso & Fabrikam. I always break prod on Fridays.


Fun fact about the Adobe Reader 0day: actually, it's the "AdobeCollabSync.exe" ("C:\Program Files\Adobe\Acrobat DC\Acrobat\AdobeCollabSync.exe") process who communicates to the attacker-controller server, not the "Acrobat.exe". Therefore, if you're hunting the threat with your e.g EDR telemetry, you may want to look at that "AdobeCollabSync.exe" process too. #threatintel















![Adam Gross [MVP] - ASquareDozen.com](https://pbs.twimg.com/profile_images/1454200017594486790/e_vrmMTf.jpg)