Hackers Smuggle Post-Exploitation Toolkit Into Oracle Database Via Classic SQL Injection Flaw

A SQL injection vulnerability that many organisations might consider a decades-old, well-understood threat has been used as the entry point for a far more sophisticated attack, after threat actors were caught planting a custom-built, database-resident toolkit inside an Oracle database. Security firm Huntress said it was alerted to suspicious activity on an endpoint hosting an […]

This article has been indexed from IT Security Guru

Read the original article: