{
  "id": 216182,
  "title": "Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access",
  "url": "https://urgent.news/2026/08/06/attackers-compile-khunt-inside-oracle-to-turn-sql-injection-into",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-06T09:19:23.000Z",
  "source": {
    "name": "The Hacker News",
    "slug": "the-hacker-news",
    "url": "https://thehackernews.com/2026/08/attackers-compile-khunt-inside-oracle.html"
  },
  "original_language": "en",
  "account": null,
  "summary": "Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the database, let Oracle compile it into stored schema objects, and ran commands from inside the database engine. Huntress, which tracks the toolkit as khunt,",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "Dev.to",
        "title": "khunt: SQL Injection to Resident Threat Inside Oracle Database Stealing Credentials with SYSTEM Privileges",
        "url": "https://urgent.news/2026/08/06/khunt-sql-injection-to-resident-threat-inside-oracle-database",
        "published": "2026-08-06T02:47:27.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}