INTEL_REPORT
Mandiant / Google Threat Intelligence Blog · published 5/25/2026, 2:00:00 PM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver . KnowledgeDeliver is a Learning Management System (LMS) developed by Digital Knowledge commonly used in Japan. Mandiant identified a critical vulnerability that allowed unauthenticated Remote Code Execution (R…
https://cloud.google.com/blog/topics/threat-intelligence/knowledgedeliver-viewstate-deserialization-vulnerability
sha256:6744a25220bf77c0a4e739bac6bb6567521fd189dcceb6eac8b4e364c1bde9bf
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| domain | loadlibrary.dll | Open → |
| domain | additional.fields | Open → |
| domain | principal.process | Open → |
| domain | target.process | Open → |
| sha256 | 7c1f99dca8e5a7897892f9d224a6495023a2cfd2671697d229d355978c415ed2 | Open → |
| cve | CVE-2026-5426 | Open → |