threat-intel
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
Critical
Summary
A zero-day vulnerability in Digital Knowledge KnowledgeDeliver LMS was exploited to deploy the Godzilla web shell and establish Cobalt Strike Beacon access. The flaw, stemming from hard-coded ASP.NET machine keys, allowed an attacker to execute remote code and compromise KnowledgeDeliver instances globally. This incident underscores the dangers of insecure deployment practices and highlights the potential for widespread impact.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
