KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
ID: 65dd0ca0-bf9b-5c6a-8c3e-b6877b2b2fae
STIX ID: report--65dd0ca0-bf9b-5c6a-8c3e-b6877b2b2fae
Feed Name: The Hacker News
A high-severity zero-day (CVE-2026-5426, CVSS 7.5) in the KnowledgeDeliver LMS—caused by vendor-shipped hard-coded ASP.NET machineKey values—was exploited in the wild to perform ViewState deserialization RCE. Threat actors deployed the Godzilla (BLUEBEAM) web shell, altered JavaScript to push a fake security plugin, and delivered a tailored Cobalt Strike Beacon payload, demonstrating the risk of shared secrets across deployments and the need for unique secrets and enhanced endpoint monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
