logo

Hackers Could Abuse SQL Server 2025 AI Features to Steal Sensitive Data

ID: 52c60b78-fdcc-5f41-a7d6-c83e7bdbb861

STIX ID: report--52c60b78-fdcc-5f41-a7d6-c83e7bdbb861

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-06-18

Date Updated: 2026-06-18

Author: Divya

...
...

Security research demonstrates that Microsoft SQL Server 2025's new AI features (notably sp_invoke_external_rest_endpoint, CREATE EXTERNAL MODEL, and AI_GENERATE_EMBEDDINGS) can be repurposed by attackers to exfiltrate large volumes of data, coerce NTLM authentication for credential capture, and implement covert command-and-control channels via seemingly legitimate AI traffic; defenders should reassess privilege controls, audit external-model creation and usage, and restrict outbound network access from database servers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.