Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageVulnerabilities Desk
Vulnerabilities

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Japanese Learning Management Systems face active exploitation through deserialization flaws, highlighting risks for European subsidiaries and partnerships using similar educational technology platforms.

Summary written by editorial AI · Source link below

Filed by Google Threat Intel1 min readRead at source ↗

Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver . KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (RCE). An unknown threat actor leveraged this access to inject malicious code into the LMS platform,

Continue at the source
Read the full report at Google Threat Intel

External link — opens at Google Threat Intel in a new tab.

§
Continue with

More from the Vulnerabilities Desk