HackerFeeds

CyberSecurity News

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

The Hacker News
· August 6, 2026

AI summary

Attackers exploited a SQL injection vulnerability in a publicly accessible web application to gain access to an organization's Oracle database. They then used the database to compile and run malicious Java code, installing a post-exploitation toolkit known as khunt without creating any executable files on disk. The attackers leveraged Oracle's ability to compile Java code into stored schema objects, allowing them to execute commands from within the database engine itself. This approach enabled them to ultimately achieve Windows SYSTEM access. The toolkit was tracked by Huntress, a security firm. The attack highlights the potential for SQL injection flaws to be used as a stepping stone for further exploitation.

Read the full article at The Hacker Newsthehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.