Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIAttackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Attackers exploited a SQL injection vulnerability in a public-facing web application to compromise an Oracle database, then deployed a post-exploitation toolkit called 'khunt' by compiling Java source code directly within the database engine rather than writing executables to disk. This technique allowed them to execute commands from inside Oracle and escalate privileges to Windows SYSTEM level ac
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added CVE-2026-42208, a SQL injection vulnerability in BerriAI LiteLLM, to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation. While remediation is mandatory for Federal Civilian Executive Branch agencies under BOD 22-01, CISA strongly recommends all organizations prioritize patching these vulnerabilities as part of their vulnerability management practices.
