mandiant2 articles
Google Ditches the Industry Naming Pact and Builds Its Own Threat Actor Taxonomy
Google has launched its own two-word naming taxonomy for cybercrime groups, following its merger of Mandiant into the Google Threat Intelligence Group, assigning category terms such as CASTLE (China), RELIC (Russia), and COMET (non-state actors) as the second word. The move appears to contradict earlier reports that Google and Mandiant were open to joining a Microsoft and CrowdStrike-led industry initiative to standardise threat actor naming, which aimed to reduce the confusion caused by the same groups carrying up to ten different names across vendors. Google claims its system is intentionally simple to allow easy mapping to other taxonomies, though critics may see it as yet another competing schema adding to the existing fragmentation.
KnowledgeDeliver Zero-Day Let Attackers Walk In With Keys They Already Had
Threat actors exploited a zero-day vulnerability (CVE-2026-5426) in KnowledgeDeliver, a widely used LMS, by leveraging hardcoded machineKey values in its ASP.NET configuration to mount ViewState deserialization attacks and deploy Godzilla web shells. The attackers used the web shells to modify system permissions, inject malicious scripts, and ultimately install a targeted Cobalt Strike backdoor, as reported by Mandiant. All KnowledgeDeliver deployments prior to February 24, 2026 are potentially at risk, and organisations are advised to rotate machine keys, restrict LMS access, and monitor for signs of intrusion.