ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Cybersecurity

khunt toolkit built inside Oracle after SQL injection leads to SYSTEM access

Source headline: Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Threat level Critical
Signal strength 85/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

Attackers exploited a SQL injection in a public-facing web application to gain access to an organization's Oracle database. They then generated and executed a post-exploitation toolkit (tracked as khunt) from within the database engine. Rather than dropping an executable file, they delivered Java source code for Oracle to compile into stored database objects. Command execution occurred inside the database context, enabling Windows SYSTEM-level access. Organizations should review Oracle exposure, fix SQL injection issues, and hunt for unusual database-side Java compilation and command execution activity.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#oracle #windows #sql-injection #post-exploitation #khunt #stored-objects
Original reporting The Hacker News Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Open original source