TantoSec's public tool turns a Telerik UI padding oracle into unauthenticated code execution for shops that skipped the July patch.
Mandiant discovered attackers exploiting a shared ASP.NET machine key flaw in KnowledgeDeliver LMS to deploy the BLUEBEAM in-memory web shell.