Framework Customer Data Exposed in Metabase Zero-Day Attack
TL;DR. Modular laptop maker Framework reports a data breach exposing customer personal information due to a zero-day exploit in its analytics provider Metabase. - Metabase discovered the attack on August 3, notifying Framework three days later about the vulnerability. - Exposed data includes names, email addresses, phone numbers, and login IP addresses for all Framework customers. - Framework rotated credentials and is investigating with a third-party forensics firm; no other systems were compromised. - Metabase patched the bug and deployed fixes after the attacker injected arbitrary SQL and gained admin access.
- Framework reported a data breach impacting all its customers.
- The breach resulted from a zero-day vulnerability in Metabase, Framework's analytics provider.
- Exposed data includes names, email addresses, phone numbers, physical addresses, and login IP addresses.
- Metabase has since patched the vulnerability and Framework is conducting an investigation.
Sources
- Framework loses customer data in Metabase zero-day attack — theregister.com