Attackers exploited a SQL injection flaw in a self-hosted Metabase instance, accessed the internal reporting system from August 10, and downloaded the Australian database on August 27. Mathspace confi

Attackers exploited a SQL injection flaw in a self-hosted Metabase instance, accessed the internal reporting system from August 10, and downloaded the Australian database on August 27. Mathspace confirmed the breach September 3. Notably, Framework, Tally, and Kilo Code filed the same performance report in August. This quarter's corrective action item: take exposed Metabase instances offline immedi

1 reportother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Attackers exploited a SQL injection flaw in a self-hosted Metabase instance, accessed the internal reporting system from August 10, and downloaded the Australian database on August 27. Mathspace confi

mastodon:infosec-exchangeother19d ago kagi ↗

Attackers exploited a SQL injection flaw in a self-hosted Metabase instance, accessed the internal reporting system from August 10, and downloaded the Australian database on August 27. Mathspace confirmed the breach September 3. Notably, Framework, Tally, and Kilo Code filed the same performance report in August. This quarter's corrective action item: take exposed Metabase instances offline immedi