Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit SQL Server 2025 AI for Data Theft

Hackers Exploit SQL Server 2025 AI for Data Theft

Posted on June 18, 2026 By CWS

Cybersecurity experts are raising alarms as hackers find innovative ways to misuse enterprise technologies. The latest concern revolves around the AI capabilities integrated into Microsoft SQL Server 2025, which are reportedly being exploited for data theft.

Research conducted by SpecterOps reveals that these AI functionalities can be manipulated to extract sensitive information and facilitate command-and-control operations, all managed from within the database framework.

Originally, SQL Server 2025 was equipped with AI to enhance modern applications like Retrieval-Augmented Generation (RAG). However, the same features are now being subverted as effective tools for cybercriminals.

New AI Features Pose Security Risks

The critical vulnerability lies in the newly added stored procedure sp_invoke_external_rest_endpoint, which allows SQL Server to initiate HTTPS communications with outside servers. While intended for legitimate API interactions, this function can be repurposed for unauthorized data transmission.

With support for payloads as large as 100 MB, attackers can efficiently transfer substantial datasets, such as user credentials, across encrypted channels, evading traditional detection methods.

This discovery is underscored by public access to proof-of-concept code on platforms like GitHub, showcasing the real-world applications of these vulnerabilities.

Exploiting AI for Covert Operations

The CREATE EXTERNAL MODEL feature, when combined with AI_GENERATE_EMBEDDINGS, can be hijacked to communicate covertly. These functions, designed for AI integrations, can mask malicious activities as legitimate data exchanges.

By embedding instructions within AI-generated data, attackers can sustain an undetectable command-and-control infrastructure entirely through SQL queries.

Additionally, by using UNC paths in AI configuration settings, attackers can provoke NTLM authentication over SMB, capturing network credentials.

Protective Measures and Future Implications

The exploitation of these features marks a significant challenge for security teams, who must now differentiate between authentic and malicious database traffic. Traditional security measures, such as scrutinizing outbound traffic, are less effective.

To counter these threats, SpecterOps advises strict regulation of database access, especially for sysadmin roles, and vigilant monitoring of external REST endpoints and AI model interactions for potential abuses.

Restricting database server connections and establishing baseline AI traffic patterns are recommended strategies to identify anomalies.

This situation underscores the necessity for advanced security protocols accompanying technological advancements, as attackers continue to adapt and exploit emerging software capabilities.

Stay updated with our latest insights by following us on Google News, LinkedIn, and X.

Cyber Security News Tags:AI exploitation, AI security, command-and-control, cyber threats, Cybersecurity, data exfiltration, data protection, data theft, database security, Microsoft, network security, SpecterOps, SQL injection, SQL Server 2025

Post navigation

Previous Post: Critical NGINX Vulnerabilities Patched by F5
Next Post: INC Ransomware Dominates 2026 with Over 830 Attacks

Related Posts

Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure Cyber Security News
Microsoft Investigates Defender Portal Access Issues Following Traffic Spike Microsoft Investigates Defender Portal Access Issues Following Traffic Spike Cyber Security News
Windows 11 to Hide BSOD Crash Errors on Public Displays Windows 11 to Hide BSOD Crash Errors on Public Displays Cyber Security News
5 Asian Cities Where Cybersecurity Maturity Meets Innovation 5 Asian Cities Where Cybersecurity Maturity Meets Innovation Cyber Security News
OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks Cyber Security News
Cybercriminals Exploit Screen-Sharing to Steal Legal Data Cybercriminals Exploit Screen-Sharing to Steal Legal Data Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution
  • Microsoft Fondue.exe Exploited for Malware Deployment
  • Apple SoCs Vulnerable to New BootROM Exploit
  • Outdated REDCap Servers Pose Cybersecurity Risks
  • INC Ransomware Dominates 2026 with Over 830 Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • F5 Fixes Critical NGINX Vulnerabilities Allowing Code Execution
  • Microsoft Fondue.exe Exploited for Malware Deployment
  • Apple SoCs Vulnerable to New BootROM Exploit
  • Outdated REDCap Servers Pose Cybersecurity Risks
  • INC Ransomware Dominates 2026 with Over 830 Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark