Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Exploit SQL Server 2025 AI for Data Theft

Hackers Exploit SQL Server 2025 AI for Data Theft

Posted on June 18, 2026 By CWS

Cybersecurity experts are raising alarms as hackers find innovative ways to misuse enterprise technologies. The latest concern revolves around the AI capabilities integrated into Microsoft SQL Server 2025, which are reportedly being exploited for data theft.

Research conducted by SpecterOps reveals that these AI functionalities can be manipulated to extract sensitive information and facilitate command-and-control operations, all managed from within the database framework.

Originally, SQL Server 2025 was equipped with AI to enhance modern applications like Retrieval-Augmented Generation (RAG). However, the same features are now being subverted as effective tools for cybercriminals.

New AI Features Pose Security Risks

The critical vulnerability lies in the newly added stored procedure sp_invoke_external_rest_endpoint, which allows SQL Server to initiate HTTPS communications with outside servers. While intended for legitimate API interactions, this function can be repurposed for unauthorized data transmission.

With support for payloads as large as 100 MB, attackers can efficiently transfer substantial datasets, such as user credentials, across encrypted channels, evading traditional detection methods.

This discovery is underscored by public access to proof-of-concept code on platforms like GitHub, showcasing the real-world applications of these vulnerabilities.

Exploiting AI for Covert Operations

The CREATE EXTERNAL MODEL feature, when combined with AI_GENERATE_EMBEDDINGS, can be hijacked to communicate covertly. These functions, designed for AI integrations, can mask malicious activities as legitimate data exchanges.

By embedding instructions within AI-generated data, attackers can sustain an undetectable command-and-control infrastructure entirely through SQL queries.

Additionally, by using UNC paths in AI configuration settings, attackers can provoke NTLM authentication over SMB, capturing network credentials.

Protective Measures and Future Implications

The exploitation of these features marks a significant challenge for security teams, who must now differentiate between authentic and malicious database traffic. Traditional security measures, such as scrutinizing outbound traffic, are less effective.

To counter these threats, SpecterOps advises strict regulation of database access, especially for sysadmin roles, and vigilant monitoring of external REST endpoints and AI model interactions for potential abuses.

Restricting database server connections and establishing baseline AI traffic patterns are recommended strategies to identify anomalies.

This situation underscores the necessity for advanced security protocols accompanying technological advancements, as attackers continue to adapt and exploit emerging software capabilities.

Stay updated with our latest insights by following us on Google News, LinkedIn, and X.

Cyber Security News Tags:AI exploitation, AI security, command-and-control, cyber threats, Cybersecurity, data exfiltration, data protection, data theft, database security, Microsoft, network security, SpecterOps, SQL injection, SQL Server 2025

Post navigation

Previous Post: Critical NGINX Vulnerabilities Patched by F5
Next Post: INC Ransomware Dominates 2026 with Over 830 Attacks

Related Posts

Payload Ransomware Threatens Global Systems with Advanced Encryption Payload Ransomware Threatens Global Systems with Advanced Encryption Cyber Security News
Malicious Ads Deploy FlutterShell Backdoor on macOS Malicious Ads Deploy FlutterShell Backdoor on macOS Cyber Security News
LapDogs Hackers Leverages 1,000 SOHO Devices Using a Custom Backdoor to Act Covertly LapDogs Hackers Leverages 1,000 SOHO Devices Using a Custom Backdoor to Act Covertly Cyber Security News
Microsoft Pauses Automatic 365 Copilot App Installations Microsoft Pauses Automatic 365 Copilot App Installations Cyber Security News
New GitHub Device Code Phishing Attacks Targeting Developers to Steal Tokens New GitHub Device Code Phishing Attacks Targeting Developers to Steal Tokens Cyber Security News
Hackers Exploit GitHub with Fake AI Repositories Hackers Exploit GitHub with Fake AI Repositories Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Apple SoCs Vulnerable to New BootROM Exploit
  • Outdated REDCap Servers Pose Cybersecurity Risks
  • INC Ransomware Dominates 2026 with Over 830 Attacks
  • Hackers Exploit SQL Server 2025 AI for Data Theft
  • Critical NGINX Vulnerabilities Patched by F5

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Apple SoCs Vulnerable to New BootROM Exploit
  • Outdated REDCap Servers Pose Cybersecurity Risks
  • INC Ransomware Dominates 2026 with Over 830 Attacks
  • Hackers Exploit SQL Server 2025 AI for Data Theft
  • Critical NGINX Vulnerabilities Patched by F5

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark