Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SQL Injection Exploits Oracle Database for SYSTEM Access

SQL Injection Exploits Oracle Database for SYSTEM Access

Posted on August 6, 2026 By CWS

In a recent cybersecurity incident, attackers successfully breached an organization’s Oracle database through a SQL injection vulnerability present in a web application. The attackers then utilized an advanced toolkit, transforming the database into a platform for further exploitation without leaving any executable files on disk. This breach was made possible by feeding Java source code directly into the database, allowing Oracle to compile and execute it as stored schema objects.

Exploiting SQL Injection for SYSTEM Access

The investigative team at Huntress, who have been tracking this toolkit under the name ‘khunt,’ began their inquiry following the detection of credential theft on July 27, 2026. Their investigation revealed that the exploit led to SYSTEM-level code execution on the Windows server hosting the Oracle database.

The vulnerability was traced to an autocomplete search field within the application, where unvalidated inputs were transmitted to the database via Java Database Connectivity (JDBC). The account used for this connection possessed sufficient privileges to create Java objects, which was a critical factor in the exploitation process.

Understanding the Toolkit and Vulnerabilities

Currently, there is no Oracle patch available to address the application flaw or the excessive account privileges that facilitated the attack. Identifying the toolkit requires searching the Oracle installation for object names starting with ‘Khunt’ and examining SQL logs for the ‘KHUNT%’ pattern.

Oracle’s embedded Java Virtual Machine and the CREATE JAVA SOURCE statement played pivotal roles in this attack. The database was used not just as a query processing tool but as a foothold for further system compromise. The required privilege for this attack is the CREATE PROCEDURE, with additional permissions needed to execute operating-system processes.

Historical Context and Attack Implications

This method of exploitation is not new. It dates back to at least 2006 with techniques like Marco Ivaldi’s raptor_oraexec.sql, which allows command execution through Oracle database objects. The current khunt toolkit employs a similar architecture, albeit its use in real-world attacks has been rarely documented.

The toolkit comprises six Java objects and several PL/SQL wrappers, each serving distinct functions such as executing commands, reading user data, and manipulating files. For instance, ‘KhuntCmd’ runs system commands, while ‘KhuntHash’ extracts username and password hashes.

Despite observing local file staging, Huntress has not confirmed data exfiltration. No specific threat actor has been identified, though malicious activities were traced to an IP address 178.162.151[.]229.

Preventative Measures and Future Outlook

Security experts advocate for the use of parameterized queries and rigorous input validation to prevent such vulnerabilities. Additionally, enforcing least privilege principles is crucial; accounts used for public applications should not have the capability to author Java sources or execute unnecessary stored procedures.

This incident underscores the importance of robust database security practices and continuous monitoring to detect and respond to potential threats effectively.

The Hacker News Tags:cyber threat, Cybersecurity, data breach, database security, endpoint security, Hackers, Huntress, Java, Java Database Connectivity, khunt toolkit, network security, Oracle, SQL injection, SYSTEM access, Vulnerability

Post navigation

Previous Post: Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses
Next Post: Belarusian Ransomware Leader Sentenced to 16 Years

Related Posts

⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More ⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More The Hacker News
27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials 27 Malicious npm Packages Used as Phishing Infrastructure to Steal Login Credentials The Hacker News
Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses The Hacker News
Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries Eurojust Arrests 5 in €100M Cryptocurrency Investment Fraud Spanning 23 Countries The Hacker News
Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds The Hacker News
Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing Campaign Exploits Google Branding with Fake Email
  • Intel and AMD Address Over 80 Security Flaws
  • Microsoft Defender Patch Bypass: New Zero-Day Vulnerability
  • Sandworm Exploits Job Interviews to Deploy Malicious VPNs
  • LiteLLM Supply Chain Attack Affects Over 2,500 Organizations

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark