KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

2026-05-26T07:24:09Zad7c3b7a6a724d2529fa1747bdbd27aab61cbd137fa91898282f70e749ad8813
active-exploitationcobalt-strikecomposer/packagistcratesiogithub-actionsincident-responseknown-exploited-vulnerabilitylinux-malwaremalwarememory-only-ratnpmprivilege-escalationpypiransomware-infrastructuresql-injectionsupply-chain-attackthreat-actorvulnerabilityweb-shellzero-day

What happened

Multiple actively exploited and high-impact vulnerabilities plus widespread supply-chain and intrusion activity were reported. Notable incidents include a zero-day in Digital Knowledge KnowledgeDeliver (CVE-2026-5426) used to deploy the Godzilla web shell and Cobalt Strike Beacon; Ghost CMS SQL injection (CVE-2026-26980) abused to hijack 700+ sites; a maximum-severity LiteSpeed cPanel plugin flaw (CVE-2026-48172) exploited to run scripts as root; Cisco Secure Workload REST API (CVE-2026-20223) patched for data access abuse; and active exploitation of Drupal Core (CVE-2026-9082) and Microsoft /

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
ad7c3b7a6a724d2529fa1747bdbd27aab61cbd137fa91898282f70e749ad8813
Enrichment time
2026-05-26T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.