{
  "id": 3313922,
  "title": "You could've applied all 1,449 Oracle patches and still been hit by this attack",
  "url": "https://urgent.news/2026/08/25/you-couldve-applied-all-1-449-oracle-patches-and-still-been-hit-by-3313922",
  "topic": "science",
  "section": "Science",
  "published": "2026-08-25T16:09:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/08/25/you-couldve-applied-all-1449-oracle-patches-and-still-been-hit-by-this-attack/5292335"
  },
  "original_language": "en",
  "account": "In late July, Oracle released a massive security patch update containing 1,449 patches in what may have been an unprecedented day for database administrators. However, according to Craig Savage, cybersecurity lead at Spinnaker Support, none of these patches would have prevented a credential theft incident on an Oracle database server. Huntress, a security platform, reported detecting credential theft activity in July, which involved a simple SQL injection exploiting a public-facing web application. After gaining access, the attackers dropped a post-exploitation toolkit, known as khunt, into the Oracle database using a Java source. This technique, while not entirely novel, had not been widely documented in the wild. Oracle's database includes an embedded Java Virtual Machine (JVM), and users can store Java source code as a database object. The attackers achieved this by using Java source code from Tomcat through the database connection, which was then compiled as a stored schema object within the database. Savage emphasized that Oracle's own JDK allows for the execution of Java programs within the database, a feature that should be limited to the DBA user and disabled in production environments. He warned that cybercriminals are increasingly exploiting legitimate functionality, rather than just seeking vulnerabilities. Despite Oracle releasing a significant number of patches, Savage stressed that organizations must not neglect basic security measures.",
  "summary": "Attackers now ready to exploit how things work, rather than just break them, says Oracle support expert",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "You could've applied all 1,449 Oracle patches and still been hit by this attack",
        "url": "https://urgent.news/2026/08/25/you-couldve-applied-all-1-449-oracle-patches-and-still-been-hit-by",
        "published": "2026-08-25T16:09:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}