KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

A nowpatched highseverity security flaw affecting Digital Knowledge KnowledgeDeliver a Learning Management System LMS popular in Japan was exploited as a zeroday to deliver the Godzilla web shell and ultimately facilitate the deployment of Cobalt Strike Beacon The vulnerability tracked as CVE20265426 CVSS score 75 stems from the use of hardcoded ASPNET machine keys leading to