Metabase SQLi zero-day exploited in customer data-theft attacks
2026-08-08T01:23:21Z•0ee102192cbfab8a1701439318021ae4ce814f9f71fca65422f401158e0ae324
ClickFixMetabaseOracleSQL injectionSharePointSnowflakeSpectre v2active exploitationbusiness email compromisecloud securitycritical infrastructurecryptocurrency theftdata breachdata theftextortionfinancial sectorgovernmenthealthcaremacOS infostealerpost-exploitationransomwareside-channel attacksocial engineeringzero-day
What happened
BleepingComputer security feed covering active exploitation of a critical Metabase SQL injection zero-day, major data breaches, social-engineering and business-email-compromise attacks, ransomware and extortion activity, macOS infostealer campaigns, SharePoint compromise, speculative-execution research, and SQL injection-enabled post-exploitation. The most urgent item is exploitation of Metabase instances for customer data theft, alongside ongoing attacks against government, financial, healthcare, and enterprise organizations.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0ee102192cbfab8a1701439318021ae4ce814f9f71fca65422f401158e0ae324
- Enrichment time
- 2026-08-08T01:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.