khunt: SQL Injection to Resident Threat Inside Oracle Database Stealing Credentials with SYSTEM Privileges
1. Basic Information
Article Title: Inside an Oracle Database SQL Injection Attack
Publisher: Huntress
Publication Date: August 5, 2026
khunt: SQL Injection to Resident Threat Inside Oracle Database Stealing Credentials with...
khunt: SQL Injection to Resident Threat Inside Oracle Database Stealing Credentials with SYSTEM Privileges
1. Basic Information
Article Title: Inside an Oracle Database SQL Injection Attack
Publisher: Huntress
Publication Date: August 5, 2026

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Hackers run khunt post-exploitation toolkit from Oracle database

Metabase SQLi zero-day exploited in customer data-theft attacks

Metabase Patches Vulnerability Exploited as Zero-Day

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Attackers compile khunt inside Oracle after a web SQL injection, reach Windows SYSTEM, and stage credential data and registry…

Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that…

Metabase Unauthenticated SQL Injection: From Admin Privilege Heist to Connected DB Data...

A major bug in Oracle's ERP software disproportionately affected American universities, and hackers have capitalized by stealing…

Oracle PeopleSoft zero-day CVE-2026-35273 was exploited before Oracle's June 10 advisory, exposing data and triggering extortion…

Vulnerability in the Oracle-owned PeopleSoft software is about as critical as they come.