Affected Systems
KnowledgeDeliver learning management system (specific versions unknown). Exploitation results in web shell deployment enabling persistent remote access to affected servers.
Exploitation Status
Active exploitation confirmed in the wild. Attackers are deploying Godzilla web shell on vulnerable KnowledgeDeliver LMS servers. No CVE assigned yet, indicating this is an unpatched zero-day vulnerability.
Business Impact
Organizations running KnowledgeDeliver LMS face immediate risk of server compromise and persistent attacker access. Godzilla web shell enables arbitrary command execution, data exfiltration, lateral movement, and deployment of additional malware. Educational institutions and corporate training environments are primary targets. No patch currently available. CVSS score not yet published.
Urgency
🔴 Immediate
Recommended Actions
- Immediately identify all KnowledgeDeliver LMS instances in your environment and isolate them from the network pending vendor patch availability
- Hunt for Godzilla web shell indicators: suspicious JSP/ASPX files in web directories, unusual outbound connections, and POST requests with encrypted payloads
- Review web server access logs for KnowledgeDeliver systems for anomalous requests, file uploads, or authentication bypass attempts in the past 30 days
- Contact KnowledgeDeliver vendor for emergency patch timeline and interim mitigation guidance
- If compromise is suspected, perform full incident response including forensic imaging, credential rotation, and system rebuild from known-good backups
