KnowledgeDeliver LMS zero-day exploited to deploy Bluebeam web shell
The flaw, tracked as CVE-2026-5426, impacts KnowledgeDeliver deployments that used default ASP.NET configuration settings before February 24, 2026.
The flaw, tracked as CVE-2026-5426, impacts KnowledgeDeliver deployments that used default ASP.NET configuration settings before February 24, 2026.
Researchers traced the campaign to compromised versions of the open-source chatbot platform called Tiledesk.
This toolset may be reserved for high-value targets where long-term, stealthy access is the objective.
The attackers used a previously undocumented backdoor called MiniFast, replacing the group’s earlier MiniJunk malware framework.
Officials claim the pair indirectly supplied economic resources to Russian and Belarusian entities under EU sanctions.
Threat actors have been exploiting an SQL injection flaw in Ghost CMS to inject malicious JavaScript that launches ClickFix attack chains.
In brief: Microsoft fixes two zero-days in Defender, authorities dismantle the First VPN service used by cybercriminals, and more.
Criminal groups allegedly used the service to hide their identities and online infrastructure.
The company has also patched a critical remote execution flaw, which has no signs of active exploitation.
The company said that its current investigation indicates the attackers accessed only GitHub’s internal repositories.
Showing elements 51 - 60