Morningstar Blueberry Medical Suffers Security Incident via Metabase Vulnerability
Article Content
- •Unauthorized access to Blueberry Medical's Metabase environment occurred on August 10, 2026.
- •Personal information, including health records, may have been exposed during the incident.
- •Blueberry Medical has implemented enhanced security measures following the breach.
On August 10, 2026, Blueberry Medical experienced unauthorized access due to a critical vulnerability in the Metabase platform. The breach, linked to broader exploitation of the Metabase vulnerability, was detected on August 22, prompting an incident-response process. Blueberry terminated unauthorized access within an hour and preserved relevant logs. The incident may have exposed personal information, including names, health plan details, and medical records. Blueberry has since strengthened its security measures, including enhanced authentication and increased security reviews. Law enforcement and a cybersecurity firm were engaged for further investigation. The Metabase platform was confirmed to be running a non-vulnerable version at the time of detection.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Blueberry Medical in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What information may have been exposed?
What steps has Blueberry taken since the breach?
Who should I contact for more information?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…