logo

Hackers Can Leverage SQL Server 2025 AI Features to Exfiltrate Sensitive Data

ID: e48c5b47-f8a3-5595-a6e3-ab0b607d07f2

STIX ID: report--e48c5b47-f8a3-5595-a6e3-ab0b607d07f2

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Abinaya

...
...

SpecterOps demonstrates that SQL Server 2025's built-in AI capabilities (e.g., sp_invoke_external_rest_endpoint, CREATE EXTERNAL MODEL, AI_GENERATE_EMBEDDINGS) can be weaponized to exfiltrate large datasets over HTTPS, create covert C2 channels via model embeddings, coerce NTLM SMB authentication, load malicious .NET assemblies in-memory, and persist via triggers; PoC code is public and defenders are urged to restrict privileges, monitor AI-related features, and limit outbound connectivity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.