-
15 votes
-
Google will buy up to half the electricity produced by one of Finland's nuclear power plants as part of a record €13bn investment in the country's AI infrastructure
12 votes -
Automattic CEO Matt Mullenweg put on 'leave of absence'
49 votes -
X corp is taking down Nitter instances and demands takedown of project repository
66 votes -
1Password wades into a right-wing mess after funding a Linux project
69 votes -
Meta agrees to heavy restrictions on teen users in major lawsuit settlement
36 votes -
China’s YouTube, Bilibili, plans global expansion, English-language site
22 votes -
Why your Amazon order confirmation emails have become so unhelpful
48 votes -
AI usage patterns in software teams
21 votes -
McDonald’s built a 515-page dossier on me
47 votes -
Is AI profitable yet?
68 votes -
US tax law is funding the AI infrastructure boom, not creating it
18 votes -
Honey gets terminated as lawsuits proceed
43 votes -
Framework customer info has been breached
Just got this email from Framework: Dear Valued Framework Customer, We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an...
Just got this email from Framework:
Dear Valued Framework Customer,
We are writing to inform you of a data breach at our business intelligence database provider Metabase that resulted in an attacker accessing customer names, email addresses, phone numbers, and addresses. Your information was in the database that was accessed in this breach. This breach did not include order or payment information.
We have full details on the incident below. We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors.
We are also in the process of notifying the regulatory authorities in each region where relevant regulations exist. Note that while regulations in most regions do not require notification for breaches of names, email addresses, phone numbers, and addresses, we are sending this email to you regardless to ensure you have visibility and can take any actions needed.
What happened?
On August 6th, 2026 at 9am Pacific Time, Metabase notified us of a breach of their systems with the following email message:
On Monday, August 3, we discovered that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above. We immediately blocked the endpoints used for the attack, then quickly identified and patched the vulnerability. We notified law enforcement, and we have engaged with a third party forensics firm to conduct an independent investigation.
Your instance of Metabase was vulnerable to this 0-day. Therefore, to protect your company, we recommend you:
Rotate the credentials for every database connected to your instance; and
Review the admin accounts on your instance and remove anything you don't recognize.
We also discovered that the attacker was able to gain access to your instance. We created a report on the actions we believe the attacker took on your instance, which includes log files, and which you can get from the Metabase Store at [removed url].
(If you do not have access to the Metabase Store, are having issues accessing the report, or do not want to click on a link in an unexpected email, you can log into your instance directly and reach us at Help > Get help in the grid menu in the upper right hand corner. We'll confirm this message is from us and email you the report.)
This report is based on our own application logs. We did not query or read the data in your connected databases.
Depending on the jurisdictions in which you operate and kinds of data your instance connects to, you may have notification obligations under applicable laws. If you have concerns in this regard, we recommend you assess potential notification obligations with your company’s legal or compliance experts.
We regret any inconvenience this incident may cause you, and we are here to support you. If you have questions, please reply to this email or email us at [removed email address], and we'll get back to you as quickly as we can.
Sameer Al-Sakran
Founder and CEO
Metabase
We immediately investigated the logs Metabase provided to us and confirmed that our database instance was accessed by the attacker. We confirmed that the following information was accessed:
- Full name
- Email address
- Login IPs
- Billing and shipping address information
- Country
- Address
- City
- State
- Zip code
- Phone number
- Company
For Framework for Business customers, we are investigating whether the following information may additionally have been accessed:
- Company
- Phone
- VAT
- EIN
- Billing Email
- No other personally identifiable information, order information, or payment information was accessed.
Note that Metabase has additionally flagged:
Important: This is a preliminary update based on our current knowledge.
We are working with a third-party forensic investigation firm to understand the full nature and scope of the event.
We are providing you this interim update in advance of completing our investigation to allow you to better understand any potential impact and secure your data.
Our investigation is ongoing and the information shared now is preliminary.
Please look at the application logs as well as the queries executed that are provided as separate files in the zip file for detailed activity and a potential timeline.
We’re providing you notice of the breach in the meantime to ensure you have the earliest possible visibility. In the event Metabase notifies us of additional information that impacts you, we will send a follow-up email.
What was done to resolve the issue?
After we were notified of the breach by Metabase, we rotated credentials on all databases associated with our Metabase instance and confirmed that there were no changes in admin access or access to systems outside of Metabase.
What steps have you taken to ensure this doesn’t happen in the future?
We are evaluating the breadth and depth of data shared with business intelligence platforms, and scoping down their access to only the columns required for analysis.
Nirav Patel and the Framework Team
53 votes -
OpenAI didn’t notice its AI agents using a message board to plan their hacking spree
40 votes -
Four top Google AI researchers form new startup
26 votes -
Let's all meet up in the Y2K
21 votes -
As Reddit stock falls, CEO questions value of Google’s AI Overviews
61 votes -
Microsoft struggling with hundreds of AI-discovered security bugs
11 votes -
Amazon data center in Bahrain struck and destroyed by Iranian cruise missiles, state media claims
25 votes -
China wants to use 115,000 banned Nvidia chips to fulfil its AI ambitions
10 votes -
Big Tech is now targeting Native American land for data centers
26 votes -
The voice of Google
11 votes -
Apple sues OpenAI for stealing trade secrets to build AI hardware
44 votes -
Samsung will delete your health data if you don't let them use it to train AI
23 votes -
Palantir has a nemesis and I accidentally found him
17 votes -
Companies reserving AI-training rights in their terms
17 votes -
Small AI models gain traction around the world
16 votes -
Fines doubled as teens outsmart Australia's world-first social media ban
37 votes -
Mark Zuckerberg's increasingly bizarre war on whistleblowers
55 votes -
Google must pay record €4.1 billion fine, top EU court rules
43 votes -
US releases powerful Anthropic model Mythos to some US companies
25 votes -
OpenAI says the US government will vet users of its latest AI model
13 votes -
Nvidia announces liquid cooling system that promises to reduce electricity consumption and cut water use by up to 100%
31 votes -
The Swedish-based “W” platform is the latest in a series of new social media sites vying to replace US Big Tech companies
17 votes -
The founder of Craigslist has given away half a billion dollars. He fears for an America where generosity is trolled.
67 votes -
Our workplace LLM mass delusion
40 votes -
Landmark German ruling declares Google's AI Overviews are Google's own words and makes it liable for false answers
80 votes -
Finland tests new system to help detect threats to subsea cables before incidents happen – scores of breaches in previous years have crippled critical underwater infrastructure
14 votes -
Amazon shuts down internal AI leaderboard after employees cheated
27 votes -
Commemorative US Mint Steve Jobs coin sells out in just eleven minutes
4 votes -
US FBI says Google engineer used internal search data to win $1.2M on Polymarket
39 votes -
Criticizing Eric Schmidt, ex-Google/Alphabet CEO - Casey Muratori
13 votes -
Flock wants to partner with dashcam company Nexar that takes ‘trillions of images’ a month
32 votes -
Samsung chip workers to get $340,000 average bonus in AI boom
26 votes -
Bolt CEO says he let go of his entire HR team for creating problems that didn’t exist: ‘Those problems disappeared when I let them go’
37 votes -
Public backlash after Utah county approves 62 sq miles of development sites for data center
39 votes -
Byron Allen to buy BuzzFeed in $120 million deal, will take over as CEO
14 votes -
Apple has reached a preliminary deal with Intel to make chips in the US
19 votes -
Google DeepMind workers in UK vote to unionize
17 votes