This report analyzes a focused holiday exploitation campaign where a single Japan attributed network-based actor leveraged 10+ CVEs and OAST callbacks to target Adobe ColdFusion servers during peak Christmas downtime. This was part of what appears to be a broader initial access broker campaign.