Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Written by: Takahiro Sugiyama, Peter Revelant, Mathew Potaczek Introduction In late 2025, Mandiant responded to a security incident involving a compromised web server running KnowledgeDeliver.
While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground.
While Russian-speaking threat actors have historically dominated the phishing-as-a-service (PhaaS) landscape, a rival ecosystem is rapidly growing within the Chinese-language underground. Google Threat Intelligence Group (GTIG) analyzed a dozen current PhaaS offerings in the Chinese underground, all of them mature services and many likely tied intricately to the broader criminal ecosystem in that region.
Mandiant responded to a breach of a KnowledgeDeliver Learning Management System, identifying a critical unauthenticated remote code execution vulnerability. The issue stems from identical hardcoded ASP.NET machine keys shared across customer deployments, allowing attackers to craft malicious ViewState payloads.
Mandiant investigated a compromised KnowledgeDeliver server, finding a vulnerability caused by identical hardcoded ASP.NET machine keys across deployments. This allowed an unknown threat actor to perform ViewState deserialization and achieve unauthenticated remote code execution.
Watch out for bogus World Cup websites that mimic official ticket and merchandise flows to.