Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
The history of computing contains a recurring pattern: the infrastructure arrives first, and the language that makes it ...
My Home Assistant finally stopped lagging when I replaced SQLite with PostgreSQL.
SplitVPN has been accused of breaching its no-log policy, allegedly leaking 58 million connection logs. While SplitVPN claims the allegations are fabricated, the incident exposes the limits of no-log ...
The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach ...
MAESTRO analysis of OpenAI and Anthropic incidents reveals how per-layer failures, not just the model, shaped security outcomes.
Modular laptop maker Framework has warned customers that an attacker exploited a zero-day at analytics provider Metabase to access names, email addresses, phone numbers, physical addresses, and login ...
GlobalFoundries have enlisted the support Redpanda on its digital transformation journey – improving visibility, responsiveness and operational efficiency ...
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft ...
Security expert Sami Laiho explains how specialization, stolen identities and AI are making familiar attacks faster, cheaper and more scalable.