daily cyber × ai intelligence

index

tagged

[framework]

2 editions · 2 items

August 11, 2026

  • Metabase's unauthenticated SQL injection zero-day is spreading downstream, and there's still no CVE. The maximum-severity reset_password flaw grants remote administrator access to the analytics platform, and its blast radius now reaches hosted customers of Metabase itself (Dark Reading). LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after suspicious server activity at a third-party vendor (BleepingComputer), and Framework confirmed customer data loss and rotated credentials (The Register). A loopback-only Docker lab comparing patched vs. vulnerable builds is public (earlier coverage). (discussion) · Vulnerabilities & Exploits

in Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework

August 8, 2026

  • A Metabase SQL injection zero-day was exploited to breach cloud instances, hitting Framework and Tally. Metabase says attackers exploited an unknown flaw in versions 1.58+ that allowed access to customer instances and connected data; Framework says all customers had names, emails, phone numbers, and addresses exposed (order/payment data was not). The bug is patched and cloud instances remediated. BleepingComputer, Framework (discussion) · Data Breaches

in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold