Metabase zero-day exploited to breach Framework, Tally customer databases
A critical SQL injection flaw in Metabase analytics software was used in active attacks before disclosure, compromising customer data at multiple firms.
A previously unknown SQL injection vulnerability in Metabase — open-source business intelligence software used by thousands of organizations — was exploited in targeted attacks against customer-facing deployments. Framework and Tally have confirmed breaches resulting in customer data theft.
The vulnerability allowed attackers to execute arbitrary SQL commands against backend databases without authentication. Both Framework, a laptop manufacturer, and Tally, a financial services provider, disclosed that attackers accessed customer information through their Metabase instances before the vendor issued a patch. The flaw was exploited as a zero-day, meaning attacks occurred before public disclosure or available fixes.
Metabase is widely deployed for data visualization and analytics across sectors including finance, healthcare, and e-commerce. The software connects directly to production databases, making SQL injection flaws particularly dangerous. Organizations using self-hosted Metabase instances were at risk if they had not applied emergency patches released following the attacks.
- 01Organizations running self-hosted Metabase must patch immediately or isolate instances from production data
- 02Framework and Tally customers face potential identity theft and fraud from exposed personal information
- 03Companies using business intelligence tools with direct database access should audit connection privileges
- 04Incident response teams should review Metabase logs for indicators of SQL injection attempts
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.