You could've applied all 1,449 Oracle patches and still been hit by this attack
ID: 8ed19bdd-a655-523a-b194-835924d08e1e
STIX ID: report--8ed19bdd-a655-523a-b194-835924d08e1e
Feed Name: The Register (Security)
Huntress reported an attack in which adversaries exploited a SQL injection in a public web app to load a Java-based post-exploitation toolkit (khunt) into an Oracle database. By using Oracle's embedded JVM and CREATE JAVA SOURCE commands, the attackers compiled and executed malicious Java code directly inside the database, enabling credential theft; the incident highlights abuse of legitimate functionality and poor production hardening rather than a patched software vulnerability.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
