PrivacySignal
Breach Critical

Metabase SQLi zero-day exploited in customer data-theft attacks

BleepingComputer · · International · Data Breaches

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.

Related stories

Breach
DataBreaches.net · · International

City of Coweta hit with system-wide ransomware attack, has backup

KTUL in Oklahoma reports: The City of Coweta says they are currently responding to a ransomware attack. According to officials, on Werdnesday, August 5, the City experienced at system-wide attack and immediately contacted their contracted IT provider and additional cycbersecurity professionals to secure their systems to prevent any further intrusion and to begin a recovery... Source

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
BleepingComputer · · International

Unlimited Technology Systems breach impacts 3.8 million people

Healthcare software company Unlimited Technology Systems disclosed a data breach from October 2025 that affected more than 3.8 million people. The company has reported the incident, though details about the type of data exposed have not been specified in available reporting.

Who should care: Cybersecurity · Privacy officers · Administrators

Breach
New York Times — Tech · · International

The White House’s Secret A.I. Rules + The State of Model Alignment With METR’s Chris Painter + The Final Hot Mess Express

The White House has not publicly released its artificial intelligence policy plan, but some details have reportedly leaked to news outlets. The administration has offered little official communication about its AI rules or direction.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance

#breach#regulation Read original →
Breach
BleepingComputer · · International

Real emails, hijacked payments: Two H1 2026 attack chains

Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]

Who should care: Cybersecurity · Privacy officers · Administrators

#breach#security Read original →
Breach
DataBreaches.net · · International

AU: Hackers leak sensitive Victorian court data to dark web

Personal data belonging to users of Victorian regional courts in Australia was posted to a dark web forum in July, triggering a police investigation. The leaked information includes names, email addresses, and job titles of people who participated in online court hearings.

Who should care: Cybersecurity · Privacy officers · Administrators · Lawyers · Compliance · General readers · Policy

#breach#enforcement#privacy Read original →