JPCERT/CC says attackers abused mobile-app APIs and exploited a known Metabase flaw in a leak run Macnica puts at 119 Japanese incidents this year. Some leaks came from BI tools and staff systems their owners never expected outsiders to reach, so the alert asks for access control on every endpoint, public or not.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
A fulfillment partner exposed names, addresses and phone numbers belonging to hardware wallet buyers, according to The Register. The vendor's boundary was the company's boundary.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 55%
- Investor
- Investor 17%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence68
Three exploited flaws, three very different exposure classes. The self-hosted Metabase zero-day is the one with an unpatched population behind it.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
The records cover orders placed between November 2019 and August 2021, years past the 90-day deletion window Trezor advertises. Trezor says it held repeated written confirmation from ShipMonk that the data was gone.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 55%
- Investor
- Investor 15%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+8
- Incentives64
- Confidence66
Metabase published a critical fix on August 6, Mathspace's escalation process never surfaced it, and by the time the update went in on August 29 an intruder had been inside the reporting instance for 19 days and had already exported 1,079,819 records.
Perspective Coverage
4 publishers
- Builder
- Builder 36%
- Operator
- Operator 53%
- Investor
- Investor 11%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+5
- Incentives45
- Confidence74
Brevo says an intruder reached 120 customer accounts and used them to mail phishing from those customers' own domains. Three crypto companies confirmed their newsletter lists were hit. Only one named the provider.
Perspective Coverage
4 publishers
- Builder
- Builder 15%
- Operator
- Operator 69%
- Investor
- Investor 16%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap−20
- Incentives40
- Confidence70
Administrator access on Mathspace's self-hosted reporting tool needed no login, and the week's other exposures sat in an unclaimed Elasticsearch cluster and inside an AI provider's shared package cache.
Reality
- Evidence38
- Adoption55
- Hype gap+12
- Incentives45
- Confidence45