Skip to content

Hackers Could Abuse SQL Server 2025 AI Features to Steal Sensitive Data

Gbhackers Divya June 18, 2026

A new security analysis has revealed that Microsoft SQL Server 2025’s native AI capabilities can be repurposed by attackers to stealthily exfiltrate sensitive data and establish command-and-control (C2) channels directly within the database engine, significantly expanding the post-exploitation attack surface. Security researcher Justin Kalnasy of SpecterOps demonstrated that newly introduced AI-focused features, intended to support […]

Extracted Entities

Attack Types (1)