DAPSSADAPSSA

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

By DAPSSA AI Desk | 2026-05-26T06:31:07.786Z
KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

Overview

A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as a zero-day to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon. The vulnerability, tracked as CVE-2026-5426 (CVSS score: 7.5), stems from the use of hard-coded ASP.NET machine keys, leading to

Key Developments

This reflects an evolving cybersecurity situation.

Technical Details

Attackers may use automation and vulnerabilities.

Impact & Risks

Potential disruption and data exposure.

Conclusion

Organizations must stay vigilant.

Read more: https://thehackernews.com/2026/05/knowledgedeliver-lms-flaw-exploited-to.html

Join the Discussion