khunt toolkit built inside Oracle after SQL injection leads to SYSTEM access
Source headline: Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Intelligence Summary
Attackers exploited a SQL injection in a public-facing web application to gain access to an organization's Oracle database. They then generated and executed a post-exploitation toolkit (tracked as khunt) from within the database engine. Rather than dropping an executable file, they delivered Java source code for Oracle to compile into stored database objects. Command execution occurred inside the database context, enabling Windows SYSTEM-level access. Organizations should review Oracle exposure, fix SQL injection issues, and hunt for unusual database-side Java compilation and command execution activity.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.