logo

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

ID: 65dd0ca0-bf9b-5c6a-8c3e-b6877b2b2fae

STIX ID: report--65dd0ca0-bf9b-5c6a-8c3e-b6877b2b2fae

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: [email protected] (The Hacker News)

...
...

A high-severity zero-day (CVE-2026-5426, CVSS 7.5) in the KnowledgeDeliver LMS—caused by vendor-shipped hard-coded ASP.NET machineKey values—was exploited in the wild to perform ViewState deserialization RCE. Threat actors deployed the Godzilla (BLUEBEAM) web shell, altered JavaScript to push a fake security plugin, and delivered a tailored Cobalt Strike Beacon payload, demonstrating the risk of shared secrets across deployments and the need for unique secrets and enhanced endpoint monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.