SECURITY Signal 361
Framework loses customer data in Metabase zero-day attack
Framework disclosed a data breach after attackers exploited a zero-day in its Metabase analytics instance, exposing customer personal and business details.
Engineers who integrate third-party analytics tools now face a concrete risk: even a single unpatched dependency can expose sensitive user data. The incident also highlights that compliance thresholds for reporting breaches may not align with customer expectations, leaving teams to manage reputational fallout regardless of legal obligations.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
A previously unknown Metabase vulnerability allowed SQL injection and potential admin access, leading to the exfiltration of customer data.
Framework rotated credentials and engaged forensic investigators, but the exposed data included names, addresses, and business identifiers for all customers.
Metabase patched the zero-day and advised self-hosted users to audit for rogue accounts and session tokens if the vulnerable endpoint was internet-exposed.
THE CLUSTER