Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.

Huntress, which tracks the toolkit as khunt,

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up

AI Attacks Move in Minutes. Join This Webinar on Building a Defense That Keeps Up AI has changed how fast attacks move. Work that once took an attacker days now

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More

⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More A streaming box should not need a threat model. Neither should a username field, a

Godot will no longer accept AI-authored code contributions

Godot will no longer accept AI-authored code contributions Source: Hacker News