tech π» Hackers baked toolkit right inside Oracle database
Hackers exploited a SQL injection vulnerability to install the khunt post-exploitation toolkit directly within an Oracle database. This breach occurred on a corporate network where Huntress discovered credential theft on July 27, 2026. The attackers used a vulnerable Java application endpoint to issue SQL commands, ultimately granting SYSTEM-level permissions on the Windows server. The toolkit allowed them to steal credentials and enumerate running services by abusing Oracle's Java functionality. Organizations must sanitize input and limit database account privileges to prevent such attacks. π‘οΈ