news.mlab.sh
Back to the feed
threat-intel

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

Critical
Image: The Hacker News
Summary

A zero-day vulnerability in Digital Knowledge KnowledgeDeliver LMS was exploited to deploy the Godzilla web shell and establish Cobalt Strike Beacon access. The flaw, stemming from hard-coded ASP.NET machine keys, allowed an attacker to execute remote code and compromise KnowledgeDeliver instances globally. This incident underscores the dangers of insecure deployment practices and highlights the potential for widespread impact.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.