Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
Mathspace Breach via Metabase: How Attackers Looted 1M+ Records Through an Exposed BI Platform — Detection and Hardening Guide
Introduction Online mathematics learning platform Mathspace disclosed over the weekend that attackers gained access to its Metabase internal...
CVE-2026-20349 and the April 2026 CISA KEV Additions: Cisco Secure Firewall, Metabase, and Windows Flaws — Detection and Remediation Guide
CISA Just Flagged Three Actively Exploited Vulnerabilities — Your Perimeter Is Likely in Scope The U.S. Cybersecurity and Infrastructure Sec...
CVE-2026-72898: Metabase SQL Injection Under Active Exploitation — Detection and Remediation Guide
Introduction On August 11, 2026, CISA added CVE-2026-72898 to the Known Exploited Vulnerabilities (KEV) catalog, confirming what many SOC te...
Metabase Unauthenticated Admin Access Vulnerability Exploited as Zero-Day — Patching, Detection, and Response Guide
Metabase Unauthenticated Admin Access Vulnerability Exploited as Zero-Day — Patching, Detection, and Response Guide Introduction Metabase — ...
Metabase SQL Unpatched Remote-Admin Vulnerability: Detection, Containment, and Remediation Guide
Metabase SQL Unpatched Remote-Admin Vulnerability: Detection, Containment, and Remediation Guide Dark Reading reports a maximum-severity Met...
Metabase Zero-Day (CVSS 10.0) Exploited in the Wild: Unauthenticated SQL Injection Grants Admin Access — Detection and Response Guide
Introduction Metabase — the open-source business intelligence and data visualization platform deployed in tens of thousands of environments ...
Metabase SQL Injection Exploited in the Wild: Framework and Tally Breaches — Detection and Remediation Guide
A Business Intelligence Tool Just Became an Attacker's Data Exfiltration Pipeline Two technology companies — laptop manufacturer Framework a...