This happened to a site I managed a while ago. The cause was a comment a user posted that was flagged as a "batch virus". The content of the comment was all text, along the lines of
@echo off
echo "Speeding up your PC!"
delete c:\Windows\system32\
Norton probably blacklisted HN for this comment because it infringes on their intellectual property, not merely because it is potentially destructive code. In other words, it duplicates the functionality of some of their products and they don't appreciate their trade secrets being exposed this way.
I was going through some old patent applications from 2015 and found this exact code snippet in Pat. #482739HG by one of Norton's subsidiary companies.
We got that same issue on joust.hearthsim.net (serving an S3 static site), it's getting blocked in russia because some website used to be on the IP it's currently routed to, back in 2013 or some such.
You're correct - at least one of the subdomains (hacker news) is on CF and I assumed the main site was on it too.
I don't know how Adobe flagging works - it's possible that detecting an issue on a subdomain would cause them to flag the apex. That being said, the same recycled-IP issue could apply to the Amazon load balancer / CDN.
Most every provider has had problematic customers at some point. Especially when you consider countries that might find just about anything to be problematic. Insult our leader? Your IP is banned forever.