Cybersecurity News
Filters
Filtered by tag: sql injection × Clear
Inside an Oracle Database SQL Injection Attack | Huntress
Attackers exploited a SQL injection vulnerability in an Oracle Database-connected application to achieve full OS-level remote code execution. By abusing Oracle's built-in Java functionality, they compiled and executed malicious Java source code directly within the database, ultimately deploying the Khunt post-exploitation toolkit for further access and lateral movement.
Threat Actors Achieve Persistence After SQL Injection
Attackers exploited SQL injection vulnerabilities to compromise IIS servers, deploying the BadIIS malware to gain persistence. Once inside, they disabled Windows Defender to avoid detection, then silently installed a cryptominer to hijack system resources. The attack highlights how unpatched web application vulnerabilities can serve as entry points for multi-stage intrusions with lasting impact.
