Metabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive Data
VulnAttackers exploited a CVSS 10 Metabase zero-day to gain admin access and steal sensitive data. Framework confirmed it was among the victims. Metabase just confirmed something no analytics vendor wants to write: attackers found and used an unpatched, maximum-severity flaw against Metabase Cloud before anyone on the defense side knew it existed. The company’s own […]
Read full story at Security Affairs →