Metabase SQLi zero-day exploited in customer data-theft attacks

2026-08-08T07:23:20Z21b12993432554f8c492033279305e8c03d846e40dc4251a76a93b21cf5262a7
ClickFixMetabaseMicrosoft SharePointOracle DatabaseSQL injectionSpectre v2active exploitationbreachbusiness email compromisecloud securitycredential theftcritical infrastructurecryptocurrency theftdata theftextortionmacOS infostealerpost-exploitationransomwaresocial engineeringspeculative executionsupply chainthreat intelligencezero-day

What happened

A security-news feed covering active exploitation of a critical Metabase SQL injection zero-day, major data breaches, social-engineering and business-email attacks, ransomware and extortion activity, cloud and SharePoint compromises, macOS infostealer campaigns, speculative-execution research, and SQL injection-enabled post-exploitation. The most urgent item is the Metabase vulnerability being exploited in the wild for customer data theft.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
21b12993432554f8c492033279305e8c03d846e40dc4251a76a93b21cf5262a7
Enrichment time
2026-08-08T07:23:20Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.