Hackers Embed Post-Exploitation Toolkit Inside Oracle Database Using SQL Injection
Huntress discovered attackers exploiting a SQL injection flaw in an Apache Tomcat application to embed a post-exploitation toolkit called khunt directly inside an Oracle database, achieving SYSTEM-level command execution on the underlying Windows server.