frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Metabase: Unauthenticated SQL injection in password reset (CVSS 10.0)

https://github.com/metabase/metabase/security/advisories/GHSA-vwf4-m7j8-wcjf
3•thejosh•53m ago

Comments

thethrowawayacc•42m ago
It seems this has been already used in the wild, I just received the following email from Framework:

Dear Valued Framework Customer,

We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.

We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.

We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.

What happened?

On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:

On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.

Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:

Rotate the credentials for every database connected to your instance; and

Review the admin accounts on your instance and remove anything you don't recognize.

We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].

(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)

This report is based on our own application logs. We did not query or read the data in your connected databases.

Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.

We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.

Sameer Al-Sakran

Founder and CEO

Metabase

We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:

  * Full name
  * Email address
  * Login IPs
  * Billing and shipping address information
      * Country
      * Address
      * City
      * State
      * Zip code
      * Phone number
      * Company

 
For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:

  * Company
  * Phone
  * VAT
  * EIN
  * Billing Email
No other personally identifiable information, order information, or payment information was accessed.

Note that Metabase has additionally flagged:

Important: This is a preliminary update based on our current knowledge.

We are working with a third-party forensic investigation firm to understand the full nature and scope of the event.

We are providing you this interim update in advance of completing our investigation to allow you to better understand any potential impact and secure your data.

Our investigation is ongoing and the information shared now is preliminary.

Please look at the application logs as well as the queries executed that are provided as separate files in the zip file for detailed activity and a potential timeline.

We’re providing you notice of the breach in the meantime to ensure you have the earliest possible visibility. In the event Metabase notifies us of additional information that impacts you, we will send a follow-up email.

What was done to resolve the issue?

After we were notified of the breach by Metabase, we rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.

What steps have you taken to ensure this doesn’t happen in the future?

We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.

Nirav Patel and the Framework Team

Show HN: Greatarrow.ai – Shared Memory for Claude, ChatGPT, Gemini and Cursor

https://www.greatarrow.ai
1•clapptastic•15s ago•0 comments

From Memory to Agency

https://arkalabs.app/from-memory-to-agency
1•Jergrim•2m ago•0 comments

Google repository now has 90 skills

https://github.com/google/skills
1•haebom•2m ago•0 comments

Everyday Technology Is Becoming a Black Box. Is There a Cost?

https://thereader.mitpress.mit.edu/everyday-technology-is-becoming-a-black-box-is-there-a-cost/
1•EA-3167•2m ago•0 comments

Gemma Translator: offline DIY translation device built with Gemma 4

https://www.youtube.com/watch?v=4dNry5zP0Jo
1•twobitshifter•3m ago•0 comments

Slopaganda Countermeasures: Part 1

https://docsgoblin.com/blog/26-03-17-slopaganda-countermeasures.html
1•erikhopf•3m ago•0 comments

Spin audit of SQD/QSCI quantum-chemistry benchmarks on iron–sulfur clusters

https://zenodo.org/records/21359923
1•purestatelabs•5m ago•0 comments

Kevin Warsh to stick with lean Fed messaging despite market backlash

https://www.ft.com/content/debe096f-ec89-424f-a8ca-d3843ef53549
1•petethomas•6m ago•0 comments

"I loved every minute of it, however hard it had been" [video]

https://www.youtube.com/watch?v=GS7CxAtV5Ks
1•jackdoe•14m ago•1 comments

OpenAI's ring-shaped smart speaker will reportedly cost between $300 and $400

https://www.engadget.com/2232108/openai-s-ring-shaped-smart-speaker-will-reportedly-cost-between-...
2•prng2021•15m ago•2 comments

Patient Zero (you can hug faces with cyber arms)

https://lokley.substack.com/p/patient-zero
1•loopscrollgame•16m ago•0 comments

The Schwarzschild Metric: Complete Derivation – General Relativity [video]

https://www.youtube.com/watch?v=6cSYZMM0wU4
1•binyu•20m ago•0 comments

VCS Friendly Scene Diffs in Godot 4.8

https://godotengine.org/article/dev-snapshot-godot-4-8-dev-2/#core-write-object-variants-with-n-b...
1•BinRoo•20m ago•0 comments

Snapline – menu-bar screenshot app that searches shots by their text

https://snap-line.app/
2•ziadeh•21m ago•0 comments

Blasting the Air in Front of Hypersonic Vehicles with Lasers Reduces Drag

https://www.twz.com/33859/blasting-the-air-in-front-of-hypersonic-vehicles-with-lasers-could-unlo...
1•delichon•26m ago•0 comments

How I released a game that has no assets [video]

https://www.youtube.com/watch?v=Qr3VsZYQy4s
1•EspadaV9•29m ago•1 comments

tla-rs: IronFleet and AutoMan in Verus

https://github.com/stonysystems/tla-rs
1•matt_d•30m ago•0 comments

Introducing Dogwood: runtime verification for AI agents

https://aws.amazon.com/blogs/opensource/introducing-dogwood-runtime-verification-for-ai-agents/
1•matt_d•31m ago•0 comments

Data Science Weekly – Issue 663

https://datascienceweekly.substack.com/p/data-science-weekly-issue-663
1•sebg•32m ago•0 comments

PyTorch Tutorial for Deep Learning – The JetBrains Blog

https://blog.jetbrains.com/pycharm/2026/07/pytorch-tutorial-for-deep-learning/
1•rbanffy•33m ago•0 comments

Cloudflare Announces Second Quarter 2026 Financial Results

https://cloudflare.net/news/news-details/2026/Cloudflare-Announces-Second-Quarter-2026-Financial-...
1•TheqO•33m ago•0 comments

OpenAI and four rivals just agreed on one standard for AI agents

https://thenextweb.com/news/openai-agent-plugins-open-standard-skills-mcp
5•FireBeyond•33m ago•1 comments

South Korea province deploys drones to warn elderly farmers amid heatwave

https://www.reuters.com/business/environment/south-korea-province-deploys-drones-warn-elderly-far...
1•petethomas•34m ago•0 comments

Rise of the $100 Hot Dog

https://www.wsj.com/arts-culture/food-cooking/the-rise-of-the-100-hot-dog-2ac6f322
2•bcaulfield•37m ago•1 comments

The Race to Come Up with the Next Big Sleep Drug

https://www.wsj.com/health/pharma/the-race-to-come-up-with-the-next-big-sleep-drug-473a4a5e
1•bookofjoe•37m ago•1 comments

New York Has Sued Kalshi for Running Illegal Gambling Operation

https://ag.ny.gov/press-release/2026/governor-hochul-and-attorney-general-james-announce-new-york...
2•cdrnsf•39m ago•0 comments

The messy politics behind Google's big AI shakeup

https://www.theverge.com/tech/976108/google-ai-leadership-shakeup-jeff-dean-demis-hassabis-deepmind
1•Anon84•40m ago•0 comments

BMS ran AI for drug discovery 3 years- what they found and why they doubled down

https://blogs.nvidia.com/blog/bristol-myers-squibb-building-life-science-industrys-most-advanced-...
1•bcaulfield•40m ago•0 comments

With software alone, one B200 beats the LPU and gets close to Cerebras

https://runinfra.ai/news/b200-beats-the-lpu
3•OsamaJaber•40m ago•0 comments

Why AI is a risk to Communist China

https://www.economist.com/leaders/2026/08/06/why-ai-is-a-risk-to-communist-china
2•petethomas•40m ago•0 comments