Metabase SQLi zero-day exploited in customer data-theft attacks

2026-08-08T01:23:21Z0ee102192cbfab8a1701439318021ae4ce814f9f71fca65422f401158e0ae324
ClickFixMetabaseOracleSQL injectionSharePointSnowflakeSpectre v2active exploitationbusiness email compromisecloud securitycritical infrastructurecryptocurrency theftdata breachdata theftextortionfinancial sectorgovernmenthealthcaremacOS infostealerpost-exploitationransomwareside-channel attacksocial engineeringzero-day

What happened

BleepingComputer security feed covering active exploitation of a critical Metabase SQL injection zero-day, major data breaches, social-engineering and business-email-compromise attacks, ransomware and extortion activity, macOS infostealer campaigns, SharePoint compromise, speculative-execution research, and SQL injection-enabled post-exploitation. The most urgent item is exploitation of Metabase instances for customer data theft, alongside ongoing attacks against government, financial, healthcare, and enterprise organizations.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0ee102192cbfab8a1701439318021ae4ce814f9f71fca65422f401158e0ae324
Enrichment time
2026-08-08T01:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metabase SQLi zero-day exploited in customer data-theft attacks · Baitaphish