1 article with this tag
In August 2026 it emerged that an unauthenticated SQL injection in the BI (business intelligence) and analytics tool Metabase (CVE-2026-72898, CVSS 10.0) had been exploited before a fix was released. Metabase says fewer than 3% of its cloud customers and some internet-reachable self-hosted instances were compromised. Organizations that disclosed impact include Trezor, which sells cryptocurrency hardware wallets (80,689 customers' names, addresses, phone numbers and email addresses, via its logistics partner's analytics environment), laptop maker Framework, automation tool n8n, Anaconda's Kilo Code and wallet-infrastructure provider Privy. This site's take: what leaked matches what the compromised analytics tool could read at the time. Trezor customers should never type or share their wallet backup (recovery seed) and should assume their home address is known, so they should not follow instructions in letters or calls either. Operators of analytics tools should patch, and also limit the data the tool can read to the columns analysis actually needs.