Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SQL Injection Exploits Oracle Database for SYSTEM Access

SQL Injection Exploits Oracle Database for SYSTEM Access

Posted on August 6, 2026 By CWS

In a recent cybersecurity incident, attackers successfully breached an organization’s Oracle database through a SQL injection vulnerability present in a web application. The attackers then utilized an advanced toolkit, transforming the database into a platform for further exploitation without leaving any executable files on disk. This breach was made possible by feeding Java source code directly into the database, allowing Oracle to compile and execute it as stored schema objects.

Exploiting SQL Injection for SYSTEM Access

The investigative team at Huntress, who have been tracking this toolkit under the name ‘khunt,’ began their inquiry following the detection of credential theft on July 27, 2026. Their investigation revealed that the exploit led to SYSTEM-level code execution on the Windows server hosting the Oracle database.

The vulnerability was traced to an autocomplete search field within the application, where unvalidated inputs were transmitted to the database via Java Database Connectivity (JDBC). The account used for this connection possessed sufficient privileges to create Java objects, which was a critical factor in the exploitation process.

Understanding the Toolkit and Vulnerabilities

Currently, there is no Oracle patch available to address the application flaw or the excessive account privileges that facilitated the attack. Identifying the toolkit requires searching the Oracle installation for object names starting with ‘Khunt’ and examining SQL logs for the ‘KHUNT%’ pattern.

Oracle’s embedded Java Virtual Machine and the CREATE JAVA SOURCE statement played pivotal roles in this attack. The database was used not just as a query processing tool but as a foothold for further system compromise. The required privilege for this attack is the CREATE PROCEDURE, with additional permissions needed to execute operating-system processes.

Historical Context and Attack Implications

This method of exploitation is not new. It dates back to at least 2006 with techniques like Marco Ivaldi’s raptor_oraexec.sql, which allows command execution through Oracle database objects. The current khunt toolkit employs a similar architecture, albeit its use in real-world attacks has been rarely documented.

The toolkit comprises six Java objects and several PL/SQL wrappers, each serving distinct functions such as executing commands, reading user data, and manipulating files. For instance, ‘KhuntCmd’ runs system commands, while ‘KhuntHash’ extracts username and password hashes.

Despite observing local file staging, Huntress has not confirmed data exfiltration. No specific threat actor has been identified, though malicious activities were traced to an IP address 178.162.151[.]229.

Preventative Measures and Future Outlook

Security experts advocate for the use of parameterized queries and rigorous input validation to prevent such vulnerabilities. Additionally, enforcing least privilege principles is crucial; accounts used for public applications should not have the capability to author Java sources or execute unnecessary stored procedures.

This incident underscores the importance of robust database security practices and continuous monitoring to detect and respond to potential threats effectively.

The Hacker News Tags:cyber threat, Cybersecurity, data breach, database security, endpoint security, Hackers, Huntress, Java, Java Database Connectivity, khunt toolkit, network security, Oracle, SQL injection, SYSTEM access, Vulnerability

Post navigation

Previous Post: Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses
Next Post: Belarusian Ransomware Leader Sentenced to 16 Years

Related Posts

Checkmarx Jenkins Plugin Compromised by TeamPCP Checkmarx Jenkins Plugin Compromised by TeamPCP The Hacker News
Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency Moldovan Police Arrest Suspect in €4.5M Ransomware Attack on Dutch Research Agency The Hacker News
Key Insights from the 2025 State of Pentesting Report Key Insights from the 2025 State of Pentesting Report The Hacker News
Chrome Extensions Turn Malicious, Sparking Security Concerns Chrome Extensions Turn Malicious, Sparking Security Concerns The Hacker News
Google Patches Critical V8 Zero-Day in Chrome Update Google Patches Critical V8 Zero-Day in Chrome Update The Hacker News
OpenAI Blocks Russian Accounts for Influence Operations OpenAI Blocks Russian Accounts for Influence Operations The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Integration: A Must for Business Success
  • Guarding AI Models Against Sophisticated Ransomware Attacks
  • AI Security Breach: Hugging Face Incident Analysis
  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Integration: A Must for Business Success
  • Guarding AI Models Against Sophisticated Ransomware Attacks
  • AI Security Breach: Hugging Face Incident Analysis
  • CISA Alerts on Linux Kernel Flaws Under Active Attack
  • TigerByte Cyber Launches with $3M Funding to Enhance Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark