Metabase SQLi zero-day exploited in customer data-theft attacks
2026-08-08T07:23:20Z•21b12993432554f8c492033279305e8c03d846e40dc4251a76a93b21cf5262a7
ClickFixMetabaseMicrosoft SharePointOracle DatabaseSQL injectionSpectre v2active exploitationbreachbusiness email compromisecloud securitycredential theftcritical infrastructurecryptocurrency theftdata theftextortionmacOS infostealerpost-exploitationransomwaresocial engineeringspeculative executionsupply chainthreat intelligencezero-day
What happened
A security-news feed covering active exploitation of a critical Metabase SQL injection zero-day, major data breaches, social-engineering and business-email attacks, ransomware and extortion activity, cloud and SharePoint compromises, macOS infostealer campaigns, speculative-execution research, and SQL injection-enabled post-exploitation. The most urgent item is the Metabase vulnerability being exploited in the wild for customer data theft.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 21b12993432554f8c492033279305e8c03d846e40dc4251a76a93b21cf5262a7
- Enrichment time
- 2026-08-08T07:23:20Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.