Framework discloses data breach via Metabase 0-day
Summary
Framework Computer disclosed a data breach caused by exploitation of a Metabase 0-day vulnerability, highlighting security risks in third-party analytics tools.
Similar Articles
Security incident disclosure — July 2026
Hugging Face disclosed a security incident where an autonomous AI agent system breached their infrastructure via malicious dataset exploitation, gaining access to internal data and credentials; they have contained the breach and are investigating.
Meta Exposed Data Internally From Its Controversial Employee-Tracking Program
Meta accidentally exposed sensitive keystroke and screen data from its employee-tracking program internally, prompting a security investigation and a pause of the initiative.
@_r_netsec: Found a decade of financial sector procurement data sitting on a former employee's home NAS
A CybelAngel investigation found a decade's worth of confidential financial sector procurement data exposed on a former employee's unsecured personal NAS device, highlighting third-party data risk.
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
A critical PeopleSoft zero-day vulnerability is being actively exploited by the ShinyHunters group, compromising hundreds of organizations and stealing gigabytes of data, including 48GB from a single victim.
Mixpanel security incident: what OpenAI users need to know
OpenAI disclosed a security incident at Mixpanel, a third-party analytics provider, which exposed limited user data including names, emails, and account metadata for API and ChatGPT users. No sensitive information such as API keys, passwords, or payment details were compromised, and OpenAI has terminated its use of Mixpanel and is conducting expanded security reviews across its vendor ecosystem.