Forensic incident reports published today detail a major supply chain data breach stemming from the active zero-day exploitation of an enterprise business intelligence platform. Threat actors weaponized an unpatched database query flaw to forge administrator sessions and execute bulk database exports.
The vulnerability, tracked as CVE-2026-72898 with a maximum CVSS score of 10.0, affects the Metabase business intelligence platform. Extortion group ShinyHunters exploited the SQL injection defect inside third-party logistics provider ShipMonk’s analytics environment, creating administrative session tokens to exfiltrate physical addresses, phone numbers, and order histories for over 67,000 hardware wallet customers. While core wallet infrastructure was unaffected, exposed customer shipping records create severe physical security and targeted phishing risks.
Subverting business intelligence platforms exposes sensitive customer data repositories across supply chain partners. When third-party logistics vendors maintain unpatched analytics portals containing unverified historical records, an administrative database compromise enables extortion networks to siphon sensitive customer vaults.
– Force immediate installation of security hotfixes published for Metabase analytics platform instances across corporate environments.
– Enforce strict database query rate limiting and IP-bound service account permissions across business intelligence portals.
– Inspect analytics server application access logs for anomalous database export queries or unverified admin session creations.
– Audit third-party vendor data retention schedules and verify technical data deletion assurances across supply chain partners.
Supply chain data security relies on continuous non-human identity auditing and strict third-party risk verification to ensure business intelligence platforms cannot be subverted into bulk data exfiltration channels. #CodeDefence #Metabase #SQLi #ZeroDay #SupplyChainRisk #DataExfiltration #AppSec #ShinyHunters
/
