Utopia Tech
SecurityAI-assisted1 min read

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers exploited a SQL injection vulnerability in a public-facing web application to compromise an Oracle database, then deployed a post-exploitation toolkit called 'khunt' by compiling Java source code directly within the database engine rather than writing executables to disk. This technique allowed them to execute commands from inside Oracle and escalate privileges to Windows SYSTEM level ac

UT

Utopia Tech

August 6, 2026 · 1 min read

Share

Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt,

Originally published at thehackernews.com

Share
▸ Want a deeper look?

Talk to an architect about applying this to your stack.

60-minute technical evaluation, no obligation. We'll map the ideas in this article to your environment.

Skip to main content