Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SQL Injection Exploits Oracle Database for SYSTEM Access

SQL Injection Exploits Oracle Database for SYSTEM Access

Posted on August 6, 2026 By CWS

In a recent cybersecurity incident, attackers successfully breached an organization’s Oracle database through a SQL injection vulnerability present in a web application. The attackers then utilized an advanced toolkit, transforming the database into a platform for further exploitation without leaving any executable files on disk. This breach was made possible by feeding Java source code directly into the database, allowing Oracle to compile and execute it as stored schema objects.

Exploiting SQL Injection for SYSTEM Access

The investigative team at Huntress, who have been tracking this toolkit under the name ‘khunt,’ began their inquiry following the detection of credential theft on July 27, 2026. Their investigation revealed that the exploit led to SYSTEM-level code execution on the Windows server hosting the Oracle database.

The vulnerability was traced to an autocomplete search field within the application, where unvalidated inputs were transmitted to the database via Java Database Connectivity (JDBC). The account used for this connection possessed sufficient privileges to create Java objects, which was a critical factor in the exploitation process.

Understanding the Toolkit and Vulnerabilities

Currently, there is no Oracle patch available to address the application flaw or the excessive account privileges that facilitated the attack. Identifying the toolkit requires searching the Oracle installation for object names starting with ‘Khunt’ and examining SQL logs for the ‘KHUNT%’ pattern.

Oracle’s embedded Java Virtual Machine and the CREATE JAVA SOURCE statement played pivotal roles in this attack. The database was used not just as a query processing tool but as a foothold for further system compromise. The required privilege for this attack is the CREATE PROCEDURE, with additional permissions needed to execute operating-system processes.

Historical Context and Attack Implications

This method of exploitation is not new. It dates back to at least 2006 with techniques like Marco Ivaldi’s raptor_oraexec.sql, which allows command execution through Oracle database objects. The current khunt toolkit employs a similar architecture, albeit its use in real-world attacks has been rarely documented.

The toolkit comprises six Java objects and several PL/SQL wrappers, each serving distinct functions such as executing commands, reading user data, and manipulating files. For instance, ‘KhuntCmd’ runs system commands, while ‘KhuntHash’ extracts username and password hashes.

Despite observing local file staging, Huntress has not confirmed data exfiltration. No specific threat actor has been identified, though malicious activities were traced to an IP address 178.162.151[.]229.

Preventative Measures and Future Outlook

Security experts advocate for the use of parameterized queries and rigorous input validation to prevent such vulnerabilities. Additionally, enforcing least privilege principles is crucial; accounts used for public applications should not have the capability to author Java sources or execute unnecessary stored procedures.

This incident underscores the importance of robust database security practices and continuous monitoring to detect and respond to potential threats effectively.

The Hacker News Tags:cyber threat, Cybersecurity, data breach, database security, endpoint security, Hackers, Huntress, Java, Java Database Connectivity, khunt toolkit, network security, Oracle, SQL injection, SYSTEM access, Vulnerability

Post navigation

Previous Post: Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses
Next Post: Belarusian Ransomware Leader Sentenced to 16 Years

Related Posts

Critical Gitea Docker Flaw CVE-2026-20896 Under Attack Critical Gitea Docker Flaw CVE-2026-20896 Under Attack The Hacker News
Popular Chrome Ad Blocker Raises Security Concerns Popular Chrome Ad Blocker Raises Security Concerns The Hacker News
Redis Security Flaws Lead to Critical Patches Redis Security Flaws Lead to Critical Patches The Hacker News
Cybersecurity Threats: Game Cheat Spyware and More Cybersecurity Threats: Game Cheat Spyware and More The Hacker News
SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids SlopAds Fraud Ring Exploits 224 Android Apps to Drive 2.3 Billion Daily Ad Bids The Hacker News
Keenadu Malware Exploits Android Firmware for Data Theft Keenadu Malware Exploits Android Firmware for Data Theft The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years
  • SQL Injection Exploits Oracle Database for SYSTEM Access
  • Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses
  • Zbtlink Routers Expose Security Flaw with Built-in Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Meta’s AI Breach: Internet Access and System Exploitation
  • Belarusian Ransomware Leader Sentenced to 16 Years
  • SQL Injection Exploits Oracle Database for SYSTEM Access
  • Apple WebKit Flaws Expose iCloud Relay Users’ IP Addresses
  • Zbtlink Routers Expose Security Flaw with Built-in Backdoor

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark