Framework loses customer data in Metabase zero-day attack
Repairable hardware is little comfort when personal details escape
Framework, a modular laptop manufacturer, has disclosed that its customers' personal information was accessed due to a zero-day vulnerability in Metabase, an analytics platform used by Framework. The leaked data includes names, email addresses, phone numbers, physical addresses, and login IP addresses for individual customers, and company information for business clients.
Framework assured customers that order and payment details remained secure. The company acknowledged the incident, apologizing for the breach and stating that they are reviewing their data storage methods in external database vendors. Framework has notified relevant regulators and is working with a third-party forensics firm to investigate the incident.
The attacker exploited a vulnerability in Metabase's cloud service, affecting versions 1.58 and later, and was able to inject arbitrary SQL and potentially gain administrator access. Framework advises affected customers to patch their Metabase instances immediately and take additional security measures if their instances were exposed to the internet.
The breach occurred during a challenging period for Framework, as the company faced rising costs for certain laptop components.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- Framework loses customer data in Metabase zero-day attack theregister.com