Google Cloud Blog – DevOps & SRE

Google Cloud Blog – DevOps & SRE

Publication
0 followers

DevOps/SRE guidance, tools, and practices from Google Cloud.

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
NewsMay 25, 2026

Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability

Mandiant disclosed a critical ViewState deserialization flaw (CVE‑2026‑5426) in Digital Knowledge’s KnowledgeDeliver LMS, caused by identical ASP.NET machine keys across deployments. The shared keys let an unauthenticated attacker craft malicious ViewState payloads, achieve remote code execution, and install the in‑memory...

By Google Cloud Blog – DevOps & SRE
Welcome to BlackFile: Inside a Vishing Extortion Operation
NewsMay 15, 2026

Welcome to BlackFile: Inside a Vishing Extortion Operation

Google Threat Intelligence Group reports UNC6671, operating under the BlackFile brand, running a vishing‑based extortion campaign that targets Microsoft 365 and Okta environments. The group uses real‑time adversary‑in‑the‑middle attacks to capture MFA credentials, then registers attacker‑controlled devices for persistence. Automated...

By Google Cloud Blog – DevOps & SRE
Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever
NewsApr 16, 2026

Defending Your Enterprise When AI Models Can Find Vulnerabilities Faster Than Ever

General‑purpose AI models are now capable of discovering and even generating functional exploits, compressing the traditional vulnerability‑to‑exploit timeline. Threat actors are already leveraging large language models to automate zero‑day creation, threatening enterprises that rely on human‑speed patching. In response, security...

By Google Cloud Blog – DevOps & SRE
Google Cloud Blog – DevOps & SRE | Pulse