View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Metabase SQL Injection Zero-Day Exploited in Customer Data-Theft

๐Ÿšจ ACTIVE EXPLOITATION

  • UPDATE: Metabase SQL Injection Zero-Day Exploited in Customer Data-Theft Attacks Attackers exploited a Metabase SQL injection zero-day to steal customer data.

    • Metabase Cloud and self-hosted deployments were affected, including instances used by Framework and Tally.
    • Versions 1.58 and later across branches 0.58โ€“0.63 were vulnerable; fixes include 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9, and 0.63.5.
    • An unauthenticated SQL injection in POST /api/session/reset_password enabled remote administrator access.
    • Attackers could steal connected-database credentials, read accessible data, and export records.
    • A suspected attack shows POST /api/session/reset_password returning 400, followed by GET /api/user/current returning 200. ๐Ÿ“Ž Coverage: securityweek.com ยท ๐Ÿ‘ via SecurityWeek
  • UPDATE: Attackers Exploit Critical Progress Kemp LoadMaster Command-Injection Flaw CVE-2026-8037 Attackers are exploiting a critical command-injection flaw in Progress Kemp LoadMaster.

    • Progress Kemp LoadMaster ADCs and load balancers are affected, along with pre-GA 7.2.63.2 MOVEit WAF versions.
    • LoadMaster GA 7.2.63.1 and earlier, and LTSF 7.2.54.17 and earlier, are vulnerable to CVE-2026-8037.
    • Unauthenticated attackers send unsanitized input to API command endpoints to execute arbitrary commands remotely.
    • KEVIntel recorded 792 exploitation attempts from 65 IP addresses across 18 countries over 41 days.
    • Observed source IPs include 192.42.116[.]58, 192.42.116[.]105, and 146.70.139[.]154. ๐Ÿ“„ Source: cisa.gov ยท ๐Ÿ“Ž Coverage: bleepingcomputer.com ยท ๐Ÿ‘ via SecurityWeek, BleepingComputer
  • Private APN Pivot Enabled Attack on Second Polish Energy Facility Hackers used a private APN to sabotage a Polish CHP plant.

    • The target was a Polish combined heat and power plant supplying heat to 50,000 residents.
    • The attack shut down a steam turbine and water treatment system without interrupting heat or electricity supplies.
    • Attackers breached an internet-facing Fortinet device, then accessed a Teltonika router and tunneled into a distribution operator's private APN.
    • They scanned the APN, reached a Wago PLC through SSH, and accessed Siemens PLCs in the plant's OT network.
    • The attackers stopped Siemens PLCs, locked their control state, disrupted Moxa devices, and damaged some ICS equipment. ๐Ÿ“Ž [Coverage: securityweek.com](https

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check