S

EPISODE · May 26, 2026 · 0 MIN

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

from Security Stuff · host Trace3

Hackers exploited a zero-day vulnerability in KnowledgeDeliver, a learning management system widely used in Japan, to deploy web shells and Cobalt Strike backdoors. The flaw, tracked as CVE-2026-5426, stemmed from hardcoded encryption keys in Digital Knowledge deployments that allowed attackers to craft malicious payloads and compromise systems through ViewState deserialization attacks. Google's Mandiant says the threat actors used Godzilla web shells to modify access permissions and deliver fake security alerts before ultimately infecting systems with custom backdoors, and all KnowledgeDeliver deployments before February 24, 2026 are potentially at risk.

Episode metadata supplied by the publisher feed · Published May 26, 2026

Embed this episode

NOW PLAYING

Hackers Exploited KnowledgeDeliver Zero-Day for Web Shell Deployment

0:00 0:47

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security Stuff?

This episode is 0 minutes long.

When was this Security Stuff episode published?

This episode was published on May 26, 2026.

Can I download this Security Stuff episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!