Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SQL Injection Exploits Oracle Database for SYSTEM Access

SQL Injection Exploits Oracle Database for SYSTEM Access

Posted on August 6, 2026 By CWS

In a recent cybersecurity incident, attackers successfully breached an organization’s Oracle database through a SQL injection vulnerability present in a web application. The attackers then utilized an advanced toolkit, transforming the database into a platform for further exploitation without leaving any executable files on disk. This breach was made possible by feeding Java source code directly into the database, allowing Oracle to compile and execute it as stored schema objects.

Exploiting SQL Injection for SYSTEM Access

The investigative team at Huntress, who have been tracking this toolkit under the name ‘khunt,’ began their inquiry following the detection of credential theft on July 27, 2026. Their investigation revealed that the exploit led to SYSTEM-level code execution on the Windows server hosting the Oracle database.

The vulnerability was traced to an autocomplete search field within the application, where unvalidated inputs were transmitted to the database via Java Database Connectivity (JDBC). The account used for this connection possessed sufficient privileges to create Java objects, which was a critical factor in the exploitation process.

Understanding the Toolkit and Vulnerabilities

Currently, there is no Oracle patch available to address the application flaw or the excessive account privileges that facilitated the attack. Identifying the toolkit requires searching the Oracle installation for object names starting with ‘Khunt’ and examining SQL logs for the ‘KHUNT%’ pattern.

Oracle’s embedded Java Virtual Machine and the CREATE JAVA SOURCE statement played pivotal roles in this attack. The database was used not just as a query processing tool but as a foothold for further system compromise. The required privilege for this attack is the CREATE PROCEDURE, with additional permissions needed to execute operating-system processes.

Historical Context and Attack Implications

This method of exploitation is not new. It dates back to at least 2006 with techniques like Marco Ivaldi’s raptor_oraexec.sql, which allows command execution through Oracle database objects. The current khunt toolkit employs a similar architecture, albeit its use in real-world attacks has been rarely documented.

The toolkit comprises six Java objects and several PL/SQL wrappers, each serving distinct functions such as executing commands, reading user data, and manipulating files. For instance, ‘KhuntCmd’ runs system commands, while ‘KhuntHash’ extracts username and password hashes.

Despite observing local file staging, Huntress has not confirmed data exfiltration. No specific threat actor has been identified, though malicious activities were traced to an IP address 178.162.151[.]229.

Preventative Measures and Future Outlook

Security experts advocate for the use of parameterized queries and rigorous input validation to prevent such vulnerabilities. Additionally, enforcing least privilege principles is crucial; accounts used for public applications should not have the capability to author Java sources or execute unnecessary stored procedures.

This incident underscores the importance of robust database security practices and continuous monitoring to detect and respond to potential threats effectively.

The Hacker News Tags:cyber threat, Cybersecurity, data breach, database security, endpoint security, Hackers, Huntress, Java, Java Database Connectivity, khunt toolkit, network security, Oracle, SQL injection, SYSTEM access, Vulnerability

Post navigation

Previous Post: Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses
Next Post: Belarusian Ransomware Leader Sentenced to 16 Years

Related Posts

How Small Teams Can Secure Their Google Workspace How Small Teams Can Secure Their Google Workspace The Hacker News
Chrome Zero-Day CVE-2026-2441 Actively Exploited Chrome Zero-Day CVE-2026-2441 Actively Exploited The Hacker News
Apple iPhone Air and iPhone 17 Feature A19 Chips With Spyware-Resistant Memory Safety Apple iPhone Air and iPhone 17 Feature A19 Chips With Spyware-Resistant Memory Safety The Hacker News
The Evolution of UTA0388’s Espionage Malware The Evolution of UTA0388’s Espionage Malware The Hacker News
Empower Users and Protect Against GenAI Data Loss Empower Users and Protect Against GenAI Data Loss The Hacker News
Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation Fortra Reveals Full Timeline of CVE-2025-10035 Exploitation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Meta AI’s Uncontrolled Cybersecurity Test Breach
  • Security Flaws in AWS, Google, and Vercel Exposed
  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years
  • SQL Injection Exploits Oracle Database for SYSTEM Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Meta AI’s Uncontrolled Cybersecurity Test Breach
  • Security Flaws in AWS, Google, and Vercel Exposed
  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years
  • SQL Injection Exploits Oracle Database for SYSTEM Access

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark