KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike
2026-05-26T07:24:09Z•ad7c3b7a6a724d2529fa1747bdbd27aab61cbd137fa91898282f70e749ad8813
active-exploitationcobalt-strikecomposer/packagistcratesiogithub-actionsincident-responseknown-exploited-vulnerabilitylinux-malwaremalwarememory-only-ratnpmprivilege-escalationpypiransomware-infrastructuresql-injectionsupply-chain-attackthreat-actorvulnerabilityweb-shellzero-day
What happened
Multiple actively exploited and high-impact vulnerabilities plus widespread supply-chain and intrusion activity were reported. Notable incidents include a zero-day in Digital Knowledge KnowledgeDeliver (CVE-2026-5426) used to deploy the Godzilla web shell and Cobalt Strike Beacon; Ghost CMS SQL injection (CVE-2026-26980) abused to hijack 700+ sites; a maximum-severity LiteSpeed cPanel plugin flaw (CVE-2026-48172) exploited to run scripts as root; Cisco Secure Workload REST API (CVE-2026-20223) patched for data access abuse; and active exploitation of Drupal Core (CVE-2026-9082) and Microsoft /
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- ad7c3b7a6a724d2529fa1747bdbd27aab61cbd137fa91898282f70e749ad8813
- Enrichment time
- 2026-05-26T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.