BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Digital Knowledge LMS Zero-Day Deploys Malware

Hard-coded keys in Japanese LMS led to malware deployment via zero-day exploit.

  • A critical vulnerability (CVE-2026-5426) in the Japanese LMS Digital Knowledge KnowledgeDeliver allowed unauthenticated remote code execution.
  • Attackers exploited this flaw as a zero-day to deploy the Godzilla web shell and ultimately install the Cobalt Strike Beacon malware on users’ machines.
  • The root cause was hard-coded ASP.NET machine keys in the vendor’s web.config file, allowing a secret from one deployment to compromise others.
  • Google researchers confirmed the attack, noting the final payload was customized for the targeted organization.

In May 2026, threat actors actively exploited a zero-day vulnerability in the popular Japanese Learning Management System Digital Knowledge KnowledgeDeliver to deliver malware. This high-severity flaw, CVE-2026-5426, enabled attackers to execute remote code on affected servers and deploy a web shell.

- Advertisement -

The vulnerability stemmed from hard-coded ASP.NET machine keys, a risk Microsoft first documented in February 2025. Consequently, any attacker obtaining these keys from one system could compromise other internet-facing installations.

Google Mandiant and the Google Threat Intelligence Group (GTIG) detailed the attack chain in a report. They stated “An unknown threat actor leveraged this access to inject malicious code into the LMS platform, with the goal of infecting users visiting the site.”

Attackers initially used the flaw to deploy the Godzilla web shell. Subsequently, they modified application files to display a fake security alert urging users to install a malicious plugin.

This fraudulent installer then infected machines with Cobalt Strike Beacon. Meanwhile, Google noted “The payload was encrypted using a key that used the name of the compromised organization, which indicated that the threat actor prepared this payload specifically for the targeted organization.”

- Advertisement -

The flaw impacted deployments prior to February 24, 2026, and similar issues have been exploited in other software like Sitecore Experience Manager. This incident highlights the severe risk of using shared secrets in deployment templates across an entire software ecosystem.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

AI Agent Security Requires Systemic Approach

Researchers argue AI agents must be treated as untrusted components, requiring system-wide security design...

Berkshire Sells 16 Stocks in 2026 as New CEO Reshapes Portfolio

Berkshire Hathaway, under new CEO Greg Abel, executed a massive portfolio rebalance in early...

Burry Warns AI Boom Temporary; NVDA Underperforms

Investor Michael Burry argues the current surge in AI demand is temporary and driven...

Kelp DAO Recovers $293M in rsETH After Lazarus Hack

The Kelp DAO protocol has completed a five-week recovery of its restaked Ether (rsETH)...

BitMine to Join Russell 1000, Spurring ETF Buying Wave

BitMine Immersion Technologies is set to join the large-cap Russell 1000 Index on June...

Must Read

Best Crypto Audiobooks of 2026: The Ultimate Listen & Learn Guide

You can't read Bitcoin charts while driving 70 mph on the highway. You can't study Ethereum whitepapers during your morning run. But you can...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading