Google Cloud's Mandiant Threat Intelligence reported exploitation of the KnowledgeDeliver platform through an ASP.NET ViewState deserialization vulnerability, indicating attackers were able to abuse insecure server-side handling of serialized state data to achieve code execution on exposed systems. The issue affects deployments where ViewState protections were improperly configured or bypassed, turning a common web application mechanism into an entry point for compromise.
The report highlights the risk to organizations running internet-facing KnowledgeDeliver instances, where successful exploitation could allow unauthorized access, remote command execution, and follow-on intrusion activity. Defenders were urged to identify exposed systems, review application and web server logs for suspicious requests tied to ViewState processing, validate hardening of ASP.NET cryptographic settings, and apply vendor guidance or mitigations to prevent further exploitation.

See which actors are running it and whether you're in range.
2 events from the most recent confirmed update back to the earliest known activity.
Google Cloud's Mandiant Threat Intelligence blog published a report on exploitation of a ViewState deserialization vulnerability affecting KnowledgeDeliver. The reference provides no additional incident details, dates, victims, or remediation milestones beyond the publication itself.
KnowledgeDeliver deployments using default ASP.NET settings prior to 2026-02-24 were vulnerable to unauthenticated RCE via forged ViewState payloads because identical hardcoded machine keys were reused across customer instances. Mandiant later linked post-exploitation activity to BLUEBEAM web shell deployment, JavaScript tampering, and Cobalt Strike delivery, and advised defenders to rotate machine keys and hunt for published indicators.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
5 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcethehackernews.com
Open sourcecybersecuritynews.com
Open sourcecloud.google.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.