A serious zero-day vulnerability in Metabase, a business intelligence platform, has been leveraged by attackers, allowing unauthorized access to sensitive data via SQL injection. This flaw, with a CVSS score of 10, affected versions 1.58 to 1.63. Metabase confirmed that the attack was detected and mitigated quickly, preventing widespread damage among cloud customers. However, self-hosted users may still be at risk and are urged to update.
Following a confirmed breach at PC maker Framework, the security advisory recommends cleaning up after exposure and carefully auditing for any suspicious activity.