Laptop maker Framework discloses data breach after zero-day hits analytics vendor Metabase

Framework has emailed customers to disclose a data breach that exposed personal information after Metabase, its business intelligence vendor, suffered a zero-day attack. The email was shared by Reddit user MeLikaDoTheChaCha. Framework sent the notification on the evening of Thursday, August 6, and it said that customer names, login IP addresses, physical addresses, phone numbers, and email addresses were accessed.
Metabase disclosed the attack on August 6, warning that its Metabase Cloud platform had been compromised through a previously unknown vulnerability affecting versions 1.58 and above. It added that self-hosted installations were also at risk. The attacker reportedly used the flaw to inject arbitrary SQL into the application database, potentially gaining administrator access and exposing stored database credentials.
Framework says it rotated its credentials once it was notified and confirmed that there were no changes to administrative access or systems outside Metabase. Spokesperson Eric Schumacher told TechCrunch the breach affected "all customers" but declined to give a specific number. Framework is still investigating whether business-tier customers were also affected. Metabase's zero-day is also known to have affected at least one other company, Tally.





