
How widespread is the recent Metabase SQL injection attack?
I recently led an incident response investigation for a FinTech client involving the exploitation of Metabase, and the impact was significant.
With the recent reports of active exploitation, I'm curious to understand how widespread this is across the security community.
For those working with Metabase:
Has your organization been affected or received a security notification?
Was your Metabase instance internet-facing?
Have you identified exploitation attempts or unauthorized access?
Were you able to patch before exploitation?
Have you observed any data exposure or compromise?
I’m particularly interested in hearing from security teams and Metabase administrators about how many organizations have been affected or potentially exposed.
https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild
If you've investigated a related incident, what did you observe?