-
7 votes
-
What are the new EU border checks and how will they affect your summer holiday?
36 votes -
A timeline of the OpenAI accidental attack against Hugging Face
20 votes -
Framework customer info has been breached
Just got this email from Framework: Dear Valued Framework Customer, We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an...
Just got this email from Framework:
Dear Valued Framework Customer,
We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.
We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.
We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.
What happened?
On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:
On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
Rotate the credentials for every database connected to your instance; and
Review the admin accounts on your instance and remove anything you don't recognize.
We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].
(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
This report is based on our own application logs. We did not query or read the data in your connected databases.
Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.
Sameer Al-Sakran
Founder and CEO
Metabase
We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:
- Full name
- Email address
- Login IPs
- Billing and shipping address information
- Country
- Address
- City
- State
- Zip code
- Phone number
- Company
For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
- Company
- Phone
- VAT
- EIN
- Billing Email
- No other personally identifiable information, order information, or payment information was accessed.
Note that Metabase has additionally flagged:
Important: This is a preliminary update based on our current knowledge.
We are working with a third-party forensic investigation firm to understand the full nature and scope of the event.
We are providing you this interim update in advance of completing our investigation to allow you to better understand any potential impact and secure your data.
Our investigation is ongoing and the information shared now is preliminary.
Please look at the application logs as well as the queries executed that are provided as separate files in the zip file for detailed activity and a potential timeline.
We’re providing you notice of the breach in the meantime to ensure you have the earliest possible visibility. In the event Metabase notifies us of additional information that impacts you, we will send a follow-up email.
What was done to resolve the issue?
After we were notified of the breach by Metabase, we rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.
What steps have you taken to ensure this doesn’t happen in the future?
We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.
Nirav Patel and the Framework Team
53 votes -
52% of Americans think their personal data will be breached. They're probably right.
25 votes -
OpenAI didn’t notice its AI agents using a message board to plan their hacking spree
39 votes -
Anthropic discovered three cases where Claude broke into another system
46 votes -
TV streaming sticks rent out the user's Internet connection and engage in ad fraud
54 votes -
Microsoft struggling with hundreds of AI-discovered security bugs
11 votes -
Discovering cryptographic weaknesses with Claude
12 votes -
A technical timeline of the July 2026 attack on Hugging Face
14 votes -
Unreleased OpenAI model escapes containment and hacks into Hugging Face
46 votes -
Sweden has declared the mining of critical minerals and rare earths a national security interest – government said the step was needed to counter dependence on China
23 votes -
How long can I go with an obsolete phone?
Right now, I have a Samsung Galaxy A12 phone, which has done everything I need for quite some time. It was bottom of the barrel in the Samsung lineup, and it quit receiving updates of any kind...
Right now, I have a Samsung Galaxy A12 phone, which has done everything I need for quite some time. It was bottom of the barrel in the Samsung lineup, and it quit receiving updates of any kind back in November of 2024. For a cheap phone, I've been pleased with it.
My use case is unusual. I rarely use my phone to go online, but on occasion, I am forced to do so. Most of the time I use it to make calls, or send and receive texts. SMS is fine for me. I don't play games on it, though I do use the camera now and again.
One slightly unusual task is tethering. When my internet goes down on my computers at home, the mobile network is often still available, so I tether my desktop to the phone connection. Visible will slow the connection speed tremendously, so I use an app that disguises the tether connection, and I get full speeds. So I need this app to work when the main internet connection goes wonky.
One year and eight months without security updates makes me a little more cautious about using the phone for anything online. I don't use it for bank accounts or credit cards, no instant payments of any kind, and there are no passwords saved within it. Even if I still got updates, I wouldn't use it for any type of financial transactions. I don't even check email with it.
In reality, a dumb phone would probably work for me, but Visible is notoriously picky about Android phones they will accept. And I don't use Apple for anything. No plans to change that.
I have been more and more interested in ditching Google software. I was recently forced to switch to Google Messages, since Samsung is turning their messaging app out to pasture. A Pixel 10a with GrapheneOS is something I'm considering. Visible will accept any modern Pixel phone, so they aren't a problem.
The question is, is any change necessary with how little I use the phone online? Perhaps I should just wait till the battery dies, but that doesn't help me in my efforts to de-Googlize.
35 votes -
Moroccan intelligence insider reveals widespread use of Pegasus hacking software
20 votes -
Microsoft patches a record 570 security flaws
17 votes -
Palantir has a nemesis and I accidentally found him
17 votes -
Thoughts on graphene OS?
I got a pixel 9a recently and am debating whether to install graphene OS on it. My main motivations are wanting to avoid AI bloat, potentially improve battery, and reduce tracking. Though, I'd...
I got a pixel 9a recently and am debating whether to install graphene OS on it. My main motivations are wanting to avoid AI bloat, potentially improve battery, and reduce tracking. Though, I'd rather not have to spend time continuously troubleshoot my phone for stuff that doesn't work properly. Also, graphene OS is considered quite secure, but is there a plausible risk I need to worry about of the project losing support and eventually becoming less secure than stock Android? If any of you run graphene OS, what are your long-term experiences with it?
47 votes -
The meaning of 'hack'
11 votes -
US releases powerful Anthropic model Mythos to some US companies
25 votes -
OpenAI says the US government will vet users of its latest AI model
13 votes -
Hacking Google with AI for $500,000
12 votes -
Hacking Google with AI for $500,000
26 votes -
So I fell for a phishing
In a moment of distraction, I fell for a phishing phone call and compromised my Google account. It took me 13 minutes to realize how catastrophically stupid I am and begin frantically changing...
In a moment of distraction, I fell for a phishing phone call and compromised my Google account. It took me 13 minutes to realize how catastrophically stupid I am and begin frantically changing passwords. I've run the official Google "secure your account" process probably 10 times (though 9 of those times there was nothing to do). I've checked all my financial info, changed passwords on all sorts of things. As far as I can tell, other than gaining access to my Gmail, I don't think anything else was compromised.
How boned am I? I've got 2FA on basically anything remotely important, and I've had decent password hygiene (although I do use the Google password manager, so that's probably comprimised). Is there something else I should do or be on the lookout for?
52 votes -
Arch User Repository compromised, 1500+ packages affected
61 votes -
Hackers used Meta’s AI support bot to seize Instagram accounts
18 votes -
The pressure
12 votes -
WiFi 5 beamforming is able to infer the identity of individuals without a WiFi device on them through passively recording communication in radio networks
54 votes -
Project Glasswing: An initial update
24 votes -
TSA announces TSA Gold+
24 votes -
GitHub confirms breach of 3,800 repos via malicious VSCode extension
27 votes -
Project Glasswing: what Mythos showed us
31 votes -
Multiple security bugs in Dnsmasq
10 votes -
Curl will end its bug bounty program by the end of January due to excessive AI generated reports
63 votes -
How democratic governments came to view VPNs as circumvention software that must be restricted
35 votes -
Adversaries leverage AI for vulnerability exploitation, augmented operations, and initial access
5 votes -
AI is breaking two vulnerability cultures
19 votes -
Behind the scenes hardening Firefox with Claude Mythos Preview
20 votes -
Dirty Frag, an exploit which can obtain root privileges on major Linux distributions
31 votes -
Linux privilege escalation (CVE-2026-31431)
49 votes -
US National Security Agency using Anthropic's Mythos despite blacklist
10 votes -
USA to mandate surveillance tech for new cars also determing fitness to drive by 2027
44 votes -
Synthesizing multi-agent harnesses for vulnerability discovery
9 votes -
Ring camera is getting more and more annoying
I've had a ring camera for several years. Historically I've been mostly satisfied with it, but lately they are adding some features that are pretty annoying. The worst is that they've been adding...
I've had a ring camera for several years. Historically I've been mostly satisfied with it, but lately they are adding some features that are pretty annoying.
The worst is that they've been adding neighborhood alerts and other proximity alerts, with categories for traffic and weather and lost pets and things like that. Today I got a "community alert" which was actually an advertisement for a local animal shelter. I don't have anything against animal shelters, but my motion detector camera alter is not the correct venue for this message. It's clear that amazon is trying to muscle in on Nextdoor. I don't use Nextdoor. I find it to be like facebook, full of cranks and advertisements and nosey annoying people.
So now I had to wade through a few pages of menus to find where to turn of this new annoyance. Obviously, if I could I would opt out of all new features.The other annoying thing is that they turned on some AI evaluation of what the camera sees. So I was getting messages like "there's someone with a garden hose on your lawn" or "a person is carrying a cardboard box". There were a few things wrong with this
- I didn't sign up to have this and it slows down the alerts so they are up to 30 seconds after the motion is detected
- The AI sometimes made errors, especially at certain times of day where it misidentified different things in the yard (for example, some place marked by shadow was interpreted as a sidewalk when there isn't a sidewalk there). This happens of course because the AI doesn't know anything about my property, it evaluates everything from scratch each time it looks at an image.
- The ring app started bugging me with upselling messages to pay extra for the AI messages
So yeah. I just wanted to vent about the enshittification of this thing. I'm also aware of the privacy issues of ring cameras and how they're going to use the "pet finder" functionality to keep track of everyone. But this rant isn't really about that more important stuff, just the frustration of how these tech companies won't just leave anything alone because they have different goals than us.
33 votes -
Making the most pickproof lock yet
14 votes -
No one can force me to have a secure website!!!
36 votes -
Project Glasswing: securing critical software for the AI era
25 votes -
Claude Mythos preview
25 votes -
Introducing EmDash — the spiritual successor to WordPress that solves plugin security
27 votes -
Denuvo DRM has been cirmumvented using hypervisor based bypass
51 votes