Attackers embed post-exploitation toolkit inside Oracle database
SQL injection used to install khunt framework directly in database memory, enabling lateral movement without detection by endpoint tools.
Attackers breached a corporate network by exploiting a SQL injection flaw to install a post-exploitation toolkit—dubbed khunt—directly inside an Oracle database instance. The technique allows adversaries to conduct reconnaissance, credential harvesting, and lateral movement entirely from database memory, bypassing traditional endpoint detection.
The khunt framework runs as PL/SQL procedures within the database itself, granting attackers a persistent foothold that conventional security tools struggle to observe. Once embedded, the toolkit can enumerate network topology, extract credentials, and pivot to adjacent systems—all while appearing as legitimate database activity. The attack was documented by incident responders who encountered the technique during a corporate breach investigation.
Oracle databases are ubiquitous in enterprise environments, often holding sensitive financial, customer, and operational data. Their privileged network position makes them high-value targets. Running malicious code inside the database layer exploits a blind spot: most organizations monitor endpoints and network traffic but lack deep visibility into database-layer execution.
- 01Enterprises running Oracle databases face a new persistence vector invisible to endpoint tools.
- 02Security teams must extend monitoring and logging to database-layer execution, not just queries.
- 03Incident responders should audit PL/SQL procedures for unauthorized or anomalous code.
- 04Attackers gain a privileged position for credential theft and lateral movement within corporate networks.
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.