A Huntress investigation reveals how attackers used SQL injection to achieve RCE and steal credentials.