threat-intel Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access Attackers exploited a SQL injection vulnerability in a public-facing web application to gain access to an Oracle database. They then leveraged a post-exploitation toolkit, ‘khunt,’ to execute commands on the underlying Windows server, ultimately achieving SYSTEM-level access. The toolkit, developed using a technique da… The Hacker News · Aug 6, 2026 High sql injectionkhuntpost-exploitation