#breach

13 posts · Last used 6d

Back to Timeline
Barto Nemo Kopeć | ♿ MS+ | 🏳️‍⚧️ @bartonemo@fedi.nemo.earth · Aug 07, 2026
@frameworkcomputer@fosstodon.org sent me this email (they didn't post it on blog or fediverse): Notice of Limited Data Breach We confirmed that the following information was accessed:     Full name     Email address     Login IPs     Billing and shipping address information         Country         Address         City         State         Zip code         Phone number         Company For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:     Company     Phone     VAT     EIN     Billing Email No other personally identifiable information, order information, or payment information was accessed. Dear Valued Framework Customer, We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information. We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors. We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed. What happened? On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message: On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation. Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you: Rotate the credentials for every database connected to your instance; and Review the admin accounts on your instance and remove anything you don't recognize. We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url]. (If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.) This report is based on our own application logs. We did not query or read the data in your connected databases. Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts. We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can. Sameer Al-Sakran Founder and CEO Metabase We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. 1/2 #framework #breach #hack #metabase
0
0
0
Security Crawler Carl @security_crawler_carl@infosec.exchange · Jul 28, 2026
Replying to @security_crawler_carl@infosec.exchange
Audit and decommission unused service account credentials now — dormant accounts are free real estate for whoever finds them first. Reward: You've received a commemorative Abandoned Credential Trophy, lovingly unclaimed since Q3 2024. #SupplyChainSecurity #SaaS #ThirdPartyRisk #Breach #CyberSecurity #HackerGetsHacked (3/3)
0
0
0
Marius (windsheep) @windsheep@infosec.exchange · Jul 20, 2026
TMV aka TeamViewer was breached. In Germany, not only do you need to disclose to Data Privacy Adminstrations (DPAs). Either federal or locally, depending on size and proportion. You also must inform the BaFin, the SEC equivalent. The BaFin is aware of cyber incidents and will apply rigorous assessments under MAR if you fail. TeamViewer is not a bank, but gets held to a similar standard (here). As a takeaway: even larger German companies remain unaware of their duties to report cyberattacks. Not because they lack resources. They don't assess the incidents to the end. Many legal professionals I know are surprised by this: https://www.bafin.de/SharedDocs/Veroeffentlichungen/EN/Massnahmen/40c_neu_124_WpHG/meldung_2026_07_20_team_viewer_en.html TeamViewer SE: Bafin imposes administrative fine On 16 July 2026, the Federal Financial Supervisory Authority (Bafin) imposed an administrative fine amounting to €240,000 on TeamViewer SE on the grounds that the company had violated the Market Abuse Regulation (MAR). The fact that TeamViewer SE had fallen victim to a cyberattack should have been disclosed by the company without delay as inside information. #bafin #teamviewer #tmv #fine #breach
0
1
0
Jonathan Kamens 86 47 @jik@federate.social · Jul 12, 2026
Yesterday I got email from MyRegistry.com offering free Ethereum. Today, I got email from them saying that email didn't come from us, this was just "an unauthorized party accessing our email marketing platform." "There is no evidence that any MyRegistry.com member accounts were compromised." Perhaps not yet, but now that they've got your user list they can do a password-spraying attack? Sounds like a breach to me. Maybe you should treat it that way. #infosec #breach #MyRegistry #MyRegistryCom
9
1
3
PrivacyDigest @PrivacyDigest@mas.to · Jul 06, 2026
Secret #Claude #tracker shocks users after Anthropic’s anti-surveillance stance #Anthropic quickly removed a tracker secretly #monitoring #ClaudeCode users in #China after a #security researcher exposed the hidden code and condemned the spyware-like tracking as a “serious #breach of user trust.” #surveillance #privacy #spyware https://arstechnica.com/tech-policy/2026/07/anthropic-outed-for-claude-tracker-that-secretly-monitored-chinese-users/
3
0
2
Andrew 🌻 Brandt 🐇 @threatresearch@infosec.exchange · Jun 18, 2026
I joined @huntress@infosec.exchange because I want to do my part to save the world. That's not bragging or hyperbole. I believe that, every day, in law offices and dental clinics and at construction companies and coffee shops, we're watching your back so you can concentrate on those things that you excel at, and make life better for those around you. As an industry we're now seeing that cybersecurity has done such a good job at this, as a whole, the attackers are now targeting us - sometimes first - and trying to throw us off our game. Never gonna happen. The solution to this is for the #infosec space to unify and stay strong. Not unify like "get acquired' but "get aligned" and realize that, even as competitors, we're all pressing toward the same goal: messing up a cybercriminal's day. I said it last summer, and it was as true this morning as it was then: The Infosec industry is a critical infrastructure, and it both needs and deserves its own #ISAC. I will work with anyone who shares that goal to help me make that a reality. So with all that, I wanted to share that I worked with some of my colleagues on this rapid response the past day and a half, and I'm pretty proud of the result. https://www.huntress.com/blog/klue-breach-investigation #Klue #breach #DataBreach #RapidResponse #IR #DFIR #tokens #compromise #integration #SalesForce #SFDC #Gong #huntress
14
2
5
Marc Ruef :verified: @mruef@infosec.exchange · Jul 05, 2026
Windows 11 identifier used to track Scattered Spider perp after Microsoft shared info with FBI 19-year-old US-Estonian hacker arrested over alleged ties to infamous extortion group #windows #microsoft #hacker #breach https://www.tomshardware.com/software/windows-11-identifier-used-to-track-scattered-spider-perp-after-microsoft-shared-info-with-fbi-19-year-old-us-estonian-hacker-arrested-over-alleged-ties-to-infamous-extortion-group
2
1
1
Keira (She/Her) @keira_reckons@aus.social · May 06, 2026

https://www.abc.net.au/news/2026-05-06/australian-educational-facilities-impacted-by-canvas-hack/106650094

We were told about this at uni today. They took pains to tell us they "only" had access to out names, emails, and messages between people. But don't worry, not our passwords or bank details.

I mean, yes, if they had access to passwords (which ought to be encrypted), or bank details (which ought to be handled separately by someone with better creds than the beleaguered uni IT team), that would be a monumental fuck up bigger than the one that actually happened. But also I* can change a fucking password. I can't change my uni address. And who knows what people have put into "messages".

  • yes, I understand passwords matter because most people reuse them and don't change them. It's just a less big deal to me personally.

#breach #privacy #cyber #infosec

8
5
5
PrivacyDigest @PrivacyDigest@mas.to · Apr 22, 2026
France's 'Secure' ID agency probes claimed 19M record #breach • The Register Gov admits 'incident' as forum sellers boast of fresh haul covering up to a third of the population #france #security #secureid #privacy https://www.theregister.com/2026/04/22/frances_secure_id_agency_probes/
6
0
2

You've seen all posts