Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
ID: 979f78b6-5d31-5b7d-ba71-a1749728f7e7
STIX ID: report--979f78b6-5d31-5b7d-ba71-a1749728f7e7
Feed Name: SpecterOps Blog
Threat Score
This research post analyzes how SQL Server 2025's new AI features (sp_invoke_external_rest_endpoint, CREATE EXTERNAL MODEL, AI_GENERATE_EMBEDDINGS) can be weaponized for high-volume data exfiltration, NTLM SMB coercion, and a native database-resident command-and-control channel; it includes multiple PoC SQL and .NET CLR implementations and concludes with detection and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
