CYBER● ELEVATEDAug 6 · Aug 6, 2026, 9:19 AM
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
The Hacker News
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt,
GlobeAlert aggregates and classifies open sources; the story above belongs to its publisher. Summaries are machine-generated from the source text.
More in Cyber
CYBERnow[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AIDark ReadingCYBERnow[Virtual Event] Building a Secure AI Strategy for the EnterpriseDark ReadingCYBER32m agoStudent taken into custody on charges of circulating morphed images of fellow students and teachersThe HinduCYBER1h agoChina-Singapore security team claims breakthrough in hacking Starlink terminalsSouth China Morning Post