Metabase SQLi zero-day exploited in customer data-theft attacks

2026-08-08T13:23:21Zd59c2316d44884e2e5f2fd4ea747c512cfddb426a068997d98a9e04a2b3ebf4f
active-exploitationai-securitybusiness-email-compromiseclickfixcloud-securitycritical-infrastructurecryptocurrency-theftdata-breachdata-theftextortionfinancial-sectorhealthcareinfostealerlinuxmacosmetabaseransomwaresharepointside-channelsnowflakesocial-engineeringspectre-v2sql-injectionsupply-chainzero-day

What happened

A BleepingComputer security-news feed covering active exploitation, data breaches, ransomware, infostealers, supply-chain and cloud compromises, social engineering, cyberattacks against critical infrastructure, and emerging hardware and AI security issues. The most urgent item reports a critical Metabase SQL injection zero-day exploited in attacks against customer instances for data theft. Other notable reports include a macOS ClickFix infostealer, SharePoint compromise affecting a government environment, a Spectre v2 bypass leaking Linux password hashes, and attacks against financial and port

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
d59c2316d44884e2e5f2fd4ea747c512cfddb426a068997d98a9e04a2b3ebf4f
Enrichment time
2026-08-08T13:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Metabase SQLi zero-day exploited in customer data-theft attacks · Baitaphish