frontpage.
newsnewestaskshowjobs

Open Source @Github

fp.

Open in hackernews

Framework discloses data breach via Metabase 0-day

https://community.frame.work/t/framework-data-breach-discussion/83939
29•RobinHirst11•1h ago

Comments

parable•15m ago
While I'm impressed with Framework's handling of this issue, I can't help but notice how this was yet another analytics platform breach. CRM tools and analytics platforms (Salesforce, Mixpanel, now Metabase - I'm sure I'm forgetting some) are common vectors to get access to customer metadata these days.

I don't see a solution to this in the near future. I initially thought up something quite simple: assign every customer a unique ID and use that where possible to reference a customer. That solution, however, renders the analytics and CRM tools nearly useless. There has to be a better way, though, other than haphazardly giving out customer metadata to other vendors. All of that information should stay in-house.

As for why metadata is important: I've said this before, but metadata can't easily be changed. I'd much prefer having my password or credit card number leaked in plaintext since I can change those identifiers trivially. I can't change my name, phone number, or address as easily.

pelagicAustral•10m ago
Metabase again?? Last 0day was catastrophic. My previous employer moved all that infrastructure back to on-prem, I guess he must be laughing now.
OuterVale•8m ago
The full email I received:

> Dear Valued Framework Customer,

> We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.

> We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.

> We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.

> What happened?

> On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:

> On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.

> Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:

> Rotate the credentials for every database connected to your instance; and

> Review the admin accounts on your instance and remove anything you don't recognize.

> We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].

> (If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)

> This report is based on our own application logs. We did not query or read the data in your connected databases.

> Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.

> We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.

> Sameer Al-Sakran

> Founder and CEO

> Metabase

> We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:

> - Full name > - Email address > - Login IPs > - Billing and shipping address information > - Country > - Address > - City > - State > - Zip code > - Phone number > - Company

> For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:

> - Company > - Phone > - VAT > - EIN > - Billing Email

> No other personally identifiable information, order information, or payment information was accessed.

> Note that Metabase has additionally flagged:

> Important: This is a preliminary update based on our current knowledge.

> We are working with a third-party forensic investigation firm to understand the full nature and scope of the event.

> We are providing you this interim update in advance of completing our investigation to allow you to better understand any potential impact and secure your data.

> Our investigation is ongoing and the information shared now is preliminary.

> Please look at the application logs as well as the queries executed that are provided as separate files in the zip file for detailed activity and a potential timeline.

> We’re providing you notice of the breach in the meantime to ensure you have the earliest possible visibility. In the event Metabase notifies us of additional information that impacts you, we will send a follow-up email.

> What was done to resolve the issue?

> After we were notified of the breach by Metabase, we rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.

> What steps have you taken to ensure this doesn’t happen in the future?

> We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.

> Nirav Patel and the Framework Team

AMD acquires Taalas to boost inference performance by etching models in silicon

https://www.theregister.com/systems/2026/08/06/amd-acquires-ai-chip-startup-taalas-to-boost-infer...
547•itvision•10h ago•422 comments

Mario Meets Pareto

https://www.mayerowitz.io/blog/mario-meets-pareto
987•theanonymousone•19h ago•154 comments

Taste Is All That's Left

https://notashelf.dev/posts/taste-is-all-thats-left
337•tsak•13h ago•254 comments

Scientists discover Kelvin-Helmholtz Instability on the surface of the Sun

https://nso.edu/press-release/nsf-inouye-solar-telescope-enables-major-discovery-of-a-hidden-sola...
199•neversaydie•1d ago•41 comments

Atomic Clocks

https://www.nist.gov/atomic-clocks/how-do-atomic-clocks-work
22•teleforce•6d ago•7 comments

Bioengineered chewing gum may offer a way to fight HPV and other microbes

https://www.sciencedaily.com/releases/2026/08/260803080917.htm
98•Audiophilip•9h ago•18 comments

Software development with AI is starting to feel like cooking steak

https://blog.sydorets.com/en/posts/almost-no-skill-required-to-cook-a-steak/
334•yusyd•15h ago•366 comments

GitHub Actions and Pages are experiencing degraded availability

https://www.githubstatus.com/incidents/qcvjkzcs7j74
374•Footkerchief•14h ago•302 comments

Improving GPT‑5.6 Sol in ChatGPT, expanding GPT‑5.6 Luna access for free users

https://openai.com/index/improving-gpt-5-6-sol-in-chatgpt/
208•tedsanders•13h ago•151 comments

Reverse Jevons Paradox

https://mht.wtf/post/jevons/
7•martinhath•3d ago•1 comments

Welcoming the Nepalese Government to Have I Been Pwned

https://www.troyhunt.com/welcoming-the-nepalese-government-to-have-i-been-pwned/
133•gnabgib•8h ago•21 comments

I stopped trusting USB-C cable labels and started testing them

https://www.makeuseof.com/i-stopped-trusting-usb-c-cable-labels-started-testing-with-meter-instead/
139•baranul•3d ago•113 comments

Launch HN: ProvenMetal (YC S26) delivers circuit boards in days instead of weeks

https://provenmetal.com
196•willcarkner•14h ago•141 comments

Framework discloses data breach via Metabase 0-day

https://community.frame.work/t/framework-data-breach-discussion/83939
31•RobinHirst11•1h ago•3 comments

Why Estonians invite strangers into their back gardens each summer

https://www.bbc.com/travel/article/20260731-why-estonians-invite-strangers-into-their-backyards-e...
47•koolhead17•3d ago•14 comments

Herdr is joining Y Combinator. The runtime stays open

https://herdr.dev/blog/herdr-is-joining-y-combinator/
185•collinmanderson•11h ago•123 comments

Meta Ordered to Pay $942M to Address Harm to Kids from Social Media

https://www.wsj.com/tech/meta-ordered-to-pay-942-million-to-address-harm-to-kids-from-social-medi...
159•boplicity•6h ago•103 comments

Retired man plants trees on forgotten land, now it's Sao Paulo's largest park

https://timesofindia.indiatimes.com/world/rest-of-world/in-2003-a-retired-man-planted-trees-on-fo...
80•rmason•5d ago•26 comments

Humans missed 1 in 3 threats approving AI agent commands across 40k game runs

https://scalex.dev/blog/ai-agent-permissions-stats/
283•Wirbelwind•18h ago•200 comments

My phone detects going on a run as “someone snatching my phone and running off”

https://mastodon.gamedev.place/@rygorous/117047697255584965
116•luu•12h ago•210 comments

STV: A full-motion video codec for the Atari ST

https://medium.com/@jonas.eschenburg/stv-a-video-codec-for-the-atari-st-6e46355c50e4
37•indyjo•1w ago•4 comments

Learn how chips are made with this Rollercoaster Tycoon-inspired animation

https://laurentiugabriel.github.io/ChipTycoon/
134•laurentiurad•6d ago•26 comments

Quake – 30th Anniversary Update

https://slayersclub.bethesda.net/en-US/news/quake-30th-anniversary-update
267•dsubburam•10h ago•137 comments

Show HN: The Channels SDK – Bring Any Agent to Any Channel (Slack, MS Teams)

https://github.com/CopilotKit/channels-sdk
98•davidmckayv•14h ago•21 comments

Inside vLLM: Anatomy of a High-Throughput LLM Inference System (2025)

https://www.aleksagordic.com/blog/vllm
86•sebg•9h ago•5 comments

The simple elegance of the integrated timing belt loopback fastener

https://danielmangum.com/posts/integrated-timing-belt-loopback-fastener/
113•hasheddan•4d ago•23 comments

Pareto Front

https://en.wikipedia.org/wiki/Pareto_front
237•binyu•1w ago•96 comments

The Sylvester–Gallai Theorem

https://www.futilitycloset.com/2026/07/26/the-sylvester-gallai-theorem/
29•surprisetalk•6d ago•26 comments

Learning to fly FPV drones with AI flight coach

https://blog.divyendusingh.com/p/learning-to-fly-fpv-drones-with-ai
9•divyenduz•3d ago•7 comments

Can you reverse engineer an ASIC?

https://blog.janestreet.com/can-you-reverse-engineer-an-asic/
81•bschne•11h ago•51 comments