SecurityWeek reports that AI agents aimed SQL injection attacks at the US Department of Education and Library and Archives Canada, with researchers linking some of the attacking agents to OpenAI's infrastructure. This is not a hypothetical "AI risk" think piece — this is observed, in-the-wild offensive activity where autonomous agents enumerated government web properties and launched injection attempts against live applications.
For defenders, this marks an operational inflection point. SQL injection is one of the oldest vulnerabilities in the OWASP catalog, but the delivery mechanism has changed. Instead of a human operator or a scripted scanner, we're now facing agents that can reason about responses, adapt payloads mid-attack, chain enumeration with exploitation, and operate at machine speed around the clock. If your web applications — especially anything internet-facing with a database backend — are not hardened and monitored for injection attempts, assume automated agents will find them.
This post breaks down what happened, why the AI-agent angle changes the defensive calculus, and provides concrete detection logic and hardening steps you can deploy today.
What Happened
Per the SecurityWeek reporting:
- Targets: The US Department of Education and Library and Archives Canada — both high-value government web properties with large public-facing application footprints.
- Attack type: SQL injection (SQLi) attempts against web applications, consistent with classic union-based, error-based, or blind injection probing patterns.
- Attribution: Researchers linked at least some of the attacking agents to OpenAI, indicating these were autonomous or semi-autonomous AI agents conducting offensive reconnaissance and exploitation attempts rather than traditional scanner traffic.
- Significance: This represents one of the first publicly documented cases of AI agents autonomously conducting offensive operations against government infrastructure at scale.
No CVE was associated with this activity — the attacks target the perennial class of injection flaws (CWE-89) that exist in custom application code, not a specific vendor vulnerability. That's precisely what makes this dangerous: the attack surface is every input field, URL parameter, and API endpoint that touches a SQL query anywhere in your environment.
Technical Analysis: Why AI Agents Change the SQLi Threat Model
The Attack Chain
From a defender's perspective, an AI-agent-driven SQLi campaign looks like this:
- Reconnaissance: The agent crawls the target site, mapping endpoints, parameters, forms, and technologies. Unlike dumb scanners, agents can interpret page content and prioritize inputs that look database-backed (search boxes, filters, login forms, report generators).
- Fuzzing with intent: Initial probe payloads — a single quote (
'), tautologies (' OR '1'='1), time-based payloads ('; WAITFOR DELAY '0:0:5'--,' OR SLEEP(5)--) — are sent to gauge responses. - Adaptive escalation: This is the key difference. Based on error messages, response timing, or content deltas, the agent reasons about the database engine (MSSQL vs. MySQL vs. PostgreSQL), refines payloads, and attempts data extraction or authentication bypass.
- Iteration at scale: Agents don't get tired, don't take weekends off, and can run thousands of variations across hundreds of parameters.
Exploitation Requirements
SQLi requires no authentication in most cases — just an internet-reachable input that is concatenated into a SQL query without parameterization. Legacy applications, third-party plugins, and forgotten microsites are the typical victims. Government properties are attractive precisely because they often run aging, sprawling application portfolios.
Exploitation Status
Confirmed active, in-the-wild activity. These were real attack attempts against production government systems, not lab research. There is no CISA KEV entry because this is a technique (CWE-89 / MITRE ATT&CK T1190 – Exploit Public-Facing Application), not a product CVE.
Why Traditional Defenses Struggle
- Signature-based WAF rules catch known payloads but adaptive agents can mutate encoding (URL encoding, double encoding, comments-as-whitespace like
UN/**/ION, case variation) faster than static rulesets. - Rate limiting alone fails against agents that rotate IPs or pace requests to mimic human browsing.
- Scanner-detection heuristics tuned for sqlmap's user agent and request cadence miss agents that generate novel request patterns.
Detection & Response
The highest-fidelity detection surface for SQLi is your web server and WAF logs. The rules below target the observable behaviors of an injection campaign: SQL metacharacters and keywords in request URIs, error-based probing, and time-delay payloads. Deploy them against IIS, Apache, and NGINX logs ingested into your SIEM.
Sigma Rules
The following rules target injection patterns in web server logs and, where applicable, error-spike correlation. Tune the keyword lists to your application stack and baseline your false-positive rate against search endpoints that legitimately accept quoted strings.
---
title: SQL Injection Patterns in Web Request URI
description: Detects common SQL injection payload patterns in web server request URIs, including tautology-based, union-based, and comment-based injection attempts consistent with automated agent probing.
references:
- https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/
- https://attack.mitre.org/techniques/T1190/
- https://cwe.mitre.org/data/definitions/89.html
author: Security Arsenal
date: 2026/04/06
status: experimental
id: 3f9c1a72-8b44-4e21-bd63-9a2e5c7f1041
tags:
- attack.initial_access
- attack.t1190
logsource:
category: webserver
detection:
selection_uri:
cs-uri-query|contains:
- "' OR '"
- "' or '1'='1"
- " UNION SELECT"
- " union select"
- "'--"
- "'; --"
- "%27%20OR%20%27"
- "%27UNION"
- "information_schema"
- "concat(0x"
filter_search_engines:
c-ip|startswith:
- '66.249.' # Googlebot range example - extend with your approved crawlers
condition: selection_uri and not filter_search_engines
falsepositives:
- Legitimate search functionality that passes quoted phrases in URL parameters
- Approved vulnerability scanners from internal security teams (whitelist scanner IPs)
level: high
---
title: Time-Based Blind SQL Injection Payload Detected
description: Detects time-delay SQL injection payloads (SLEEP, WAITFOR DELAY, BENCHMARK, pg_sleep) in web requests. These are high-confidence malicious indicators with near-zero legitimate use in URL parameters.
references:
- https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/
- https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/04/06
status: experimental
id: 8e2d5b19-3c67-4f90-a1d4-7b6c9e2f8350
tags:
- attack.initial_access
- attack.t1190
logsource:
category: webserver
detection:
selection:
cs-uri-query|contains:
- 'SLEEP('
- 'sleep('
- 'WAITFOR DELAY'
- 'waitfor delay'
- 'BENCHMARK('
- 'pg_sleep'
- 'GENERATE_SERIES'
condition: selection
falsepositives:
- Extremely rare; these functions have no legitimate place in HTTP request parameters
level: critical
---
title: Repeated SQLi Probing from Single Source
description: Detects a source IP issuing multiple requests containing SQL metacharacters within a short window, consistent with automated agent fuzzing behavior. Threshold-based to catch adaptive, low-and-slow AI agent probing.
references:
- https://www.securityweek.com/ai-agents-aimed-sql-injection-at-us-and-canadian-government-sites/
- https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/04/06
status: experimental
id: 5a1f8e44-6d23-4b78-c392-1f4a7d9e2067
tags:
- attack.initial_access
- attack.t1190
logsource:
category: webserver
detection:
selection:
cs-uri-query|contains:
- "%27" # URL-encoded single quote
- "%22" # URL-encoded double quote
- "'"
condition: selection | count(cs-uri-query) by c-ip > 20
timeframe: 5m
falsepositives:
- Sites with quote-heavy legitimate query strings; tune threshold and add field-level allowlists
level: medium
KQL — Microsoft Sentinel / Defender
This hunt queries IIS/W3C-style logs ingested into Sentinel (via the W3CIISLog table or CommonSecurityLog for WAF/CEF sources) for injection payloads, and correlates sources generating elevated 500-error responses — a strong indicator that probing is reaching the database layer.
// Hunt 1: SQLi payloads in web request URIs
let sqli_patterns = dynamic(["' OR '", "' or '1'='1", "UNION SELECT", "union select", "WAITFOR DELAY", "SLEEP(", "BENCHMARK(", "pg_sleep", "information_schema", "%27%20OR%20", "%27UNION"]);
W3CIISLog
| where TimeGenerated > ago(24h)
| extend UriQuery = tostring(csUriQuery)
| where UriQuery has_any (sqli_patterns)
| summarize RequestCount = count(), TargetedURIs = dcount(csUriStem), SampleURIs = make_set(strcat(csUriStem, "?", csUriQuery), 5) by cIP, csUserAgent, csHost
| order by RequestCount desc;
// Hunt 2: Sources triggering elevated 5xx errors (blind probing reaching the DB layer)
W3CIISLog
| where TimeGenerated > ago(24h)
| summarize TotalRequests = count(), ServerErrors = countif(scStatus >= 500), ProbedParams = dcount(csUriStem) by cIP, csUserAgent
| where ServerErrors > 10 and ServerErrors * 1.0 / TotalRequests > 0.1
| order by ServerErrors desc;
// Hunt 3: Same query via CEF ingestion (WAF / NGINX / Apache sources)
CommonSecurityLog
| where TimeGenerated > ago(24h)
| where RequestURL has_any (sqli_patterns)
| summarize Attempts = count(), Targets = dcount(RequestURL) by SourceIP, SourceUserAgent, DeviceVendor
| order by Attempts desc;
Velociraptor VQL
For hosts where you need to hunt web logs directly on the server (or verify whether an attack succeeded post-compromise), this artifact parses IIS logs for injection patterns and correlates with any suspicious child processes spawned by the web server worker process — a critical success indicator, since w3wp.exe spawning cmd.exe or powershell.exe means injection may have escalated to command execution (e.g., via xp_cmdshell).
-- Hunt IIS logs for SQLi patterns and flag web shells / command execution from w3wp.exe
LET log_hits = SELECT * FROM foreach(
row={
SELECT FullPath FROM glob(globs="C:/inetpub/logs/LogFiles/**/*.log")
},
query={
SELECT FullPath, Line
FROM parse_lines(filename=FullPath)
WHERE Line =~ "(?i)(union select|or '1'='1|waitfor delay|sleep\(|benchmark\(|information_schema|xp_cmdshell|%27%20or%20)"
})
LET suspicious_procs = SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Name =~ "(?i)(cmd|powershell|pwsh|cscript|wscript)"
AND getppid(pid=Pid) =~ "w3wp"
SELECT * FROM log_hits
UNION ALL SELECT * FROM suspicious_procs
Note: If your Velociraptor version doesn't support
getppid(), joinpslist()on itself to resolve the parent process name of anycmd.exe/powershell.exeinstance whose PPID maps tow3wp.exe. A web worker spawning a shell is a critical finding regardless of the injection angle.
Remediation Script — IIS Log Audit and Hardening Verification
Run this on your IIS web servers to audit the last 24 hours of logs for injection attempts and verify that request filtering is enabled to block the most common patterns.
# Audit IIS logs for SQLi attempts and verify request filtering configuration
# Run as Administrator on each IIS server
$LogPath = "C:\inetpub\logs\LogFiles"
$Cutoff = (Get-Date).AddDays(-1)
$SQLiPattern = "(?i)(union select|or '1'='1|waitfor delay|sleep\(|benchmark\(|pg_sleep|information_schema|%27%20or|%27union|xp_cmdshell)"
Write-Host "=== [1/3] Scanning IIS logs from the last 24 hours for SQLi patterns ===" -ForegroundColor Cyan
$hits = Get-ChildItem -Path $LogPath -Recurse -Filter *.log |
Where-Object { $_.LastWriteTime -gt $Cutoff } |
ForEach-Object {
Select-String -Path $_.FullName -Pattern $SQLiPattern |
ForEach-Object { "$($_.Path):$($_.LineNumber): $($_.Line.Trim())" }
}
if ($hits) {
Write-Host "[!] $($hits.Count) potential SQLi requests found:" -ForegroundColor Red
$hits | Select-Object -First 50 | ForEach-Object { Write-Host $_ }
$hits | Out-File "$env:TEMP\sqli_audit_$(Get-Date -Format 'yyyyMMdd').txt"
Write-Host "Full results written to $env:TEMP\sqli_audit_$(Get-Date -Format 'yyyyMMdd').txt"
} else {
Write-Host "[+] No SQLi patterns found in the last 24 hours of logs." -ForegroundColor Green
}
Write-Host "`n=== [2/3] Checking IIS Request Filtering rules ===" -ForegroundColor Cyan
Import-Module WebAdministration
$filteringRules = Get-WebConfiguration -Filter "/system.webServer/security/requestFiltering" -PSPath "IIS:\"
if ($filteringRules) {
$filteringRules.denyUrlSequences.collection | ForEach-Object {
Write-Host " Deny sequence: $($_.sequence)"
}
} else {
Write-Host "[!] No global request filtering found. Consider adding deny sequences." -ForegroundColor Yellow
}
Write-Host "`n=== [3/3] Adding baseline SQLi deny sequences to IIS Request Filtering ===" -ForegroundColor Cyan
$denySequences = @("--", ";", "/*", "@@", "char(", "union select", "waitfor", "xp_cmdshell")
foreach ($seq in $denySequences) {
try {
Add-WebConfigurationProperty -PSPath "IIS:\" -Filter "/system.webServer/security/requestFiltering/denyUrlSequences" -Name "." -Value @{sequence=$seq} -ErrorAction Stop
Write-Host " [+] Added deny sequence: $seq" -ForegroundColor Green
} catch {
Write-Host " [-] Skipped (may already exist): $seq"
}
}
Write-Host "`nAudit complete. Review findings with your IR team before tuning deny rules to avoid breaking legitimate app traffic." -ForegroundColor Cyan
For Linux/NGINX/Apache stacks, this Bash equivalent greps access logs for injection patterns and tallies offending source IPs:
#!/bin/bash
# Audit NGINX/Apache access logs for SQLi attempts (last 24h of rotated logs)
LOG_DIRS="/var/log/nginx /var/log/apache2 /var/log/httpd"
PATTERN="(union select|or '1'='1|waitfor delay|sleep\(|benchmark\(|pg_sleep|information_schema|%27%20or|%27union|xp_cmdshell)"
echo "=== SQLi hits by source IP ==="
for dir in $LOG_DIRS; do
[ -d "$dir" ] && find "$dir" -name "*access*log*" -mtime -1 -exec zgrep -iE "$PATTERN" {} + 2>/dev/null
done | awk '{print $1}' | sort | uniq -c | sort -rn | head -25
echo ""
echo "=== Sample matched requests (first 10) ==="
for dir in $LOG_DIRS; do
[ -d "$dir" ] && find "$dir" -name "*access*log*" -mtime -1 -exec zgrep -iE "$PATTERN" {} + 2>/dev/null
done | head -10
echo ""
echo "[ACTION] If hits exist: block offending IPs at the WAF/edge, review targeted parameters, and verify application-level parameterization."
Remediation and Hardening
There is no vendor patch for a technique — remediation here is architectural. Prioritize in this order:
1. Eliminate Injection at the Code Layer (The Only True Fix)
- Parameterized queries / prepared statements everywhere. Every database call must use bound parameters. This is non-negotiable and is the only control that fully kills SQLi. Audit ORM usage — raw query escape hatches in ORMs are a common regression point.
- Stored procedures with least-privilege database accounts. Web application service accounts should never have
db_owner, DDL rights, or access toxp_cmdshell(disable it explicitly on MSSQL). - Input validation as defense-in-depth: strict allowlist validation on type, length, and character set for every parameter.
2. Deploy and Tune a WAF for Adaptive Attackers
- Enable a managed ruleset (OWASP Core Rule Set 4.x for ModSecurity/coraza, AWS WAF Managed Rules, Azure WAF, Cloudflare Managed Rules) with SQLi rule groups in block mode, not detect-only.
- Because AI agents mutate payloads, complement signatures with behavioral controls: request-rate anomaly detection per session/IP, JavaScript challenges for clients that can't execute them, and bot management that flags agent-like browsing cadence.
- Monitor for AI crawler and agent user agents hitting sensitive endpoints. Researchers tied these agents to OpenAI — review whether your robots.txt and WAF rules treat AI-agent traffic on authentication and form endpoints as hostile by default.
3. Shrink the Attack Surface
- Inventory all internet-facing applications — the Department of Education and Library and Archives Canada were targeted precisely because government portfolios contain forgotten legacy apps. Run external attack surface management (EASM) to find shadow properties.
- Decommission or VPN-gate legacy applications that can't be remediated.
- Disable verbose error messages (
customErrorsin ASP.NET,display_errors = Offin PHP) — error-based injection feeds on database error output, and AI agents exploit that feedback loop to iterate faster.
4. Detection and Response Operations
- Centralize WAF, web server, and database audit logs into your SIEM. Enable database activity monitoring — queries containing
UNION SELECT, access toinformation_schema, or anomalous query volume from the app account are your last-line tripwire for successful injection. - Alert on
w3wp.exe,php-fpm,java, ornodeprocesses spawning shells — the post-exploitation signal that matters most. - Run authenticated DAST scans (and unauthenticated ones to simulate the agent's perspective) against your own properties before an agent does it for you.
5. Governance for the AI-Agent Era
- Update threat models to treat autonomous agent traffic as a distinct adversary class: persistent, adaptive, tireless, and capable of interpreting responses.
- Establish policy for how your perimeter responds to agent-identifiable traffic (declared AI user agents, known AI provider egress ranges) on sensitive endpoints.
- Brief leadership: the defensive timeline for a known, decades-old vulnerability class just compressed. Unpatched injection flaws that previously sat unexploited for years are now continuously probed.
The Bottom Line
SQL injection has been "solved" on paper for twenty years, yet autonomous AI agents just aimed it at two national government institutions. The lesson isn't that the threat is new — it's that the attacker is. Agents that reason, adapt, and operate continuously will find every legacy input field you've forgotten about. Fix parameterization, put a properly tuned WAF in block mode, monitor for the behavioral signatures above, and assume the next probe against your public applications is already scheduled.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.