Techcrunch
Framework Faces Data Breach Due to Metabase Zero-Day Exploit
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Framework, a laptop manufacturer, has reported a data breach affecting all customers due to a cyberattack on Metabase, its business intelligence provider. Hackers exploited a zero-day vulnerability in Metabase, allowing access to customer names, email addresses, phone numbers, and physical addresses, but not payment information. Framework has notified customers and is investigating the incident, while Metabase has released updates to secure its cloud instances. The vulnerability, which has a CVSS score of 10.0, affects all versions of Metabase from 58 to 63. Framework has changed access credentials for its Metabase cloud database and is working with IT forensics to assess the breach's impact. Customers are discussing the leak in forums, and a public statement from Framework is pending.
Key Points: • Framework's data breach affects all customers, with personal data stolen. • The breach was caused by a zero-day vulnerability in Metabase, CVSS 10.0. • Framework is investigating the incident and has changed access credentials.