#8
The Hacker News
general
August 06, 2026 at 09:19 UTC
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
By [email protected] (The Hacker News)
AI Summary
Huntress researchers documented a novel post-exploitation technique, tracked as 'khunt,' where attackers who breached a corporate network via SQL injection in a public-facing web application fed Java source code directly into an Oracle database, had the database engine compile it into stored schema objects, and executed OS commands without ever writing a binary to disk. This fileless, database-native execution method evades traditional endpoint detection and illustrates the risk of leaving Oracle database servers reachable from compromised DMZ hosts.
Relevance score: 83.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →