Hackers Hid a Remote-Control Toolkit Inside Oracle to Take Over a Windows Server
Attackers were able to use a weak spot in a public website form to break deeper into a company’s systems and take control of a Windows server by hiding their tools inside the company’s database. This is a reminder that a small website problem can lead to a much bigger systems takeover if not fixed quickly.
Who is at risk
Organizations that run public-facing websites connected to internal databases or Windows servers are most at risk, especially if their web forms and software are not regularly updated and reviewed.
What to watch for
Watch for unusual website behavior, unexpected changes to server performance, strange database activity, or login and admin actions that no one on your team recognizes.
What to do
Immediately review and lock down public website forms, apply pending software updates, restrict who and what can access your databases and servers, and investigate any unusual activity.
