SQL Injection Attack Enables Malware Deployment in Oracle Database
ID: 082bc25c-fa21-5051-a70b-0fadea900916
STIX ID: report--082bc25c-fa21-5051-a70b-0fadea900916
Feed Name: ThreatCluster
On July 27, 2026 Huntress observed an SQL injection against a public-facing Java application that allowed attackers to upload a post-exploitation toolkit called 'khunt' into an Oracle database; the toolkit used Oracle's embedded Java to achieve SYSTEM-level command execution on the Windows host and to dump registry hives for possible credential theft. The incident highlights a shift where databases are used as attack platforms and underscores the need for input validation and strict database privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
