Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine.

Huntress, which tracks the toolkit as khunt,

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption

GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption GitHub has announced a new cooldown mechanism in Dependabot, allowing the tool to wait at least three days after a

Show HN: Can Europe train a frontier AI model on the compute it owns?

Show HN: Can Europe train a frontier AI model on the compute it owns? Source: Hacker News

LearnVector – Andrew Ng’s AI company building one‑to‑one learning experiences

LearnVector – Andrew Ng’s AI company building one‑to‑one learning experiences Source: Hacker News