Summary
Security researchers at Huntress discovered a classic SQL injection flaw combined with a database trick that allowed hackers to take over Windows servers. The attackers used an Oracle SQLi vulnerability to deploy a rare post-exploitation toolkit called khunt, enabling them to run OS commands, steal credentials, and exfiltrate registry hives.