Metabase SQLi zero-day exploited in customer data-theft attacks
Attackers exploited a critical SQL injection zero-day in Metabase, a widely used business intelligence tool, to steal data from customer instances before a patch was available. The vulnerability is confirmed to have been used against at least two organizations, Framework and Tally.
Who should care: Cybersecurity · Privacy officers · Administrators