Framework discloses data breach via Metabase 0-day
- Security
- Privacy
- Infrastructure
- Developer Tools
Framework told customers that names, email addresses, phone numbers, login IPs, and billing or shipping addresses were exposed after an attacker used a zero-day in Metabase Cloud and accessed Framework’s connected instance. Order and payment data were not reported stolen. A pasted notice from Metabase said the attacker authenticated as an admin, ran dozens of queries, created and then deleted an API key, and appeared to pull the first rows from tables while hunting for valuable data. That made the incident feel less like a one-off Framework mistake and more like a familiar pattern. Internal analytics systems now sit on top of production customer data, and once that data is mirrored into cloud BI tools, the attack surface quietly expands to vendors most customers have never heard of.
Assume any CRM or analytics vendor connected to your production data is part of your breach surface, even if it only looks like an internal reporting tool. Audit what fields those tools can see, cut them down aggressively, and revisit how long you retain abandoned checkout and account data.
-
community.frame.work
- Discuss on HN