September 8, 2026
- Mathspace says 1,079,819 students, staff and parents in Australia and New Zealand had data stolen after attackers exploited a vulnerability in its self-hosted Metabase install to gain administrator access without a login. Access began 10 August, the Australian reporting database was downloaded 27 August, and the theft was confirmed 3 September; no academic records, password hashes, tokens or SSO credentials were exposed (BleepingComputer) — the latest in the run of Metabase SQL injection zero-day intrusions linked to ShinyHunters.
· Breaches
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
August 31, 2026
- A working PoC for a Metabase SQL injection (CVE-2026-72898) is being advertised on a cybercrime forum, with the seller claiming full database extraction, mass scanning and escalation to RCE, plus 600+ compromised databases and 50+ RCE sessions already in hand (DailyDarkWeb). The claims are unverified, but internet-facing Metabase deployments deserve an immediate version check.
· Vulnerabilities & Exploits
in Fully Patched, Still Domain Admin
August 14, 2026
- The Metabase pre-auth SQL injection zero-day now has a CVE and a technical writeup. Horizon3 details CVE-2026-72898, an actively exploited unauthenticated SQLi in Metabase before x.63.5 that yields admin access, config modification, and data theft — the flaw that had circulated without a CVE now formally tracked (earlier coverage). (Horizon3)
· Vulnerabilities & Exploits
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
August 12, 2026
- ShinyHunters is claiming a Metabase hacking spree, with leaked data now surfacing, following the still-uncredentialed unauthenticated SQL-injection zero-day Metabase patched last week (earlier coverage). Metabase urged customers to upgrade immediately (Metabase) (discussion).
· Threat Activity
in When the AI Is the One Finding the Zero-Days
August 11, 2026
- Metabase's unauthenticated SQL injection zero-day is spreading downstream, and there's still no CVE. The maximum-severity
reset_password flaw grants remote administrator access to the analytics platform, and its blast radius now reaches hosted customers of Metabase itself (Dark Reading). LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after suspicious server activity at a third-party vendor (BleepingComputer), and Framework confirmed customer data loss and rotated credentials (The Register). A loopback-only Docker lab comparing patched vs. vulnerable builds is public (earlier coverage). (discussion)
· Vulnerabilities & Exploits
in Metabase Zero-Day Blast Radius Widens to LexisNexis and Framework
August 9, 2026
in AI Agents' Black Hat Reckoning Goes Public
August 8, 2026
- A Metabase SQL injection zero-day was exploited to breach cloud instances, hitting Framework and Tally. Metabase says attackers exploited an unknown flaw in versions 1.58+ that allowed access to customer instances and connected data; Framework says all customers had names, emails, phone numbers, and addresses exposed (order/payment data was not). The bug is patched and cloud instances remediated. BleepingComputer, Framework (discussion)
· Data Breaches
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold