[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fn4K4Ojd2KB3jaWmulM8Zx7v2CWUPE2VbLoY-JNZ4h4U":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"1d910ebb-3609-48b5-8568-cdafff1a887e","hard-coded-cryptographic-keys-enable-zero-day-exploitation-of-lms-platform","93955099-09f8-48a8-9e43-3c74790f32cb","Hard-coded Cryptographic Keys Enable Zero-Day Exploitation of LMS Platform","Digital Knowledge's KnowledgeDeliver LMS contained hard-coded ASP.NET machine keys in the default web.config file, creating a critical vulnerability that enabled unauthenticated remote code execution. Attackers exploited this configuration flaw through ViewState deserialization attacks to deploy web shells and post-exploitation frameworks. The compromised systems were then used to distribute malicious JavaScript that tricked users into installing fake security plugins containing additional malware. This incident demonstrates how poor secure coding practices and inadequate configuration management can create widespread security exposures that bypass traditional authentication controls.","**Immediate actions:**\n- Audit all web applications for hard-coded cryptographic keys and regenerate with unique values\n- Scan internet-facing LMS and web applications for signs of compromise or unauthorized web shells\n- Block known Cobalt Strike and Godzilla indicators at network and endpoint levels\n\n**Configuration improvements:**\n- Implement secure configuration baselines that require unique cryptographic keys for each deployment\n- Enable ViewState encryption and MAC validation with environment-specific keys\n- Establish mandatory security code reviews focusing on cryptographic implementations\n\n**Detection measures:**\n- Deploy web application firewalls to monitor for deserialization attack patterns\n- Enable logging for ViewState validation failures and suspicious POST requests",[12,13,14,15,16],"CIS Control 16.1","CIS Control 18.3","NIST SC-12","NIST SI-2","OWASP ASVS V6.2","published","2026-05-27T04:56:59.750312+00:00","2026-05-27T04:56:59.675+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F05\u002Fknowledgedeliver-lms-flaw-exploited-to.html","knowledgedeliver-lms-flaw-exploited-to-deploy-godzilla-and-cobalt-strike-8c19f5","KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",[]]