Cybersecurity · 55 views
KnowledgeDeliver flaw exploited as a zero-day to install web shells
Hackers exploited a critical zero-day vulnerability in a server running the KnowledgeDeliver learning management system (LMS) to deploy the Godzilla web shell.
AI Summary
Hackers used a critical zero‑day vulnerability in the KnowledgeDeliver learning management system to install the Godzilla web shell on a server. The flaw, a deserialization issue identified as CVE‑2026‑5426, can be exploited without authentication. It originates from the use of a shared hardcoded machine key in the web portal configuration that is common to all KnowledgeDeliver customer deployments. The attack allows remote code execution and persistence on the affected server.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Cybersecurity
Continue reading recent Cybersecurity coverage
- Hackers exploit Citrix NetScaler zero-day to deploy web shellsContinue reading
- Former US Air Force members sent to prison over BEC attacksContinue reading
- French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven WeeksContinue reading
- DARPA Selects Xint to Use AI in Securing Military Messaging AppsContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow