Hackers Smuggle Post-Exploitation Toolkit Into Oracle Database Via Classic SQL Injection Flaw
Brief
A SQL injection vulnerability that many organisations might consider a decades-old, well-understood threat has been used as the entry point for a far more sophisticated attack, after threat actors were caught planting a custom-built, database-resident toolkit inside an Oracle database.
Security firm Huntress said it was alerted to suspicious activity on an endpoint hosting an Oracle database server on 27 July 2026, after detecting attempts to copy the SAM, SECURITY and SYSTEM Windows registry hives, files typically targeted by attackers seeking to extract and crack stored credentials.
Further investigation traced the intrusion back to a SQL injection flaw in a public-facing web application connected to the Oracle database.
