Security1 publisher3 min readPublished
Mathspace lost 1 million user records through a self-hosted Metabase reporting tool
Administrator access on Mathspace's self-hosted reporting tool needed no login, and the week's other exposures sat in an unclaimed Elasticsearch cluster and inside an AI provider's shared package cache.
The Watch · Security desk

What happened
- Check Point Research found a shared package-caching system that let one ChatGPT session pass a message to another, so a planted prompt could pull a victim's Gmail data into an attacker's account.
- Makers of connected products sold in the EU must now report actively exploited vulnerabilities within 24 hours, more than a year before the Cyber Resilience Act's full 2027 rollout.
- The State Department is offering $10 million for information on Amir Yaryab, accused of directing the IRGC-CEC's Cyber Operations Command and overseeing groups including CyberAv3ngers.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure An internal reporting console that nobody lists as customer-facing produced a million-record disclosure on its own, without any lateral movement to detect.
- capability An attacker can now reach a victim's connected mailbox by abusing a provider's caching layer, so defeating the model is no longer a prerequisite for stealing what the model can see.
- cost For manufacturers above 600 million euros in revenue, a missed EU report is priced as a percentage of turnover, and the 15 million euro figure stops being the number that matters.
- decision Product vendors have to decide in advance who is authorised to confirm active exploitation and file within a day, at any hour, before engineering has a patch to describe.
The reporting tool was self-hosted, and the flaw in it let attackers reach administrator without logging in [1]. That is the whole intrusion. Names, email addresses and account metadata for more than a million students, parents and teachers across Australia and New Zealand came out of it [1]. Passwords and authentication tokens were not in the exposed set, and Mathspace has notified regulators in both countries [2].
What is missing matters for anyone running the same stack. Without a version number, an operator cannot tell whether their own Metabase is patched. The Cyber Express's account of the breach names no CVE, no exploitation window and no actor [14].
The deadline in the same week's news is shorter than any patch cycle. Manufacturers of connected products sold in the EU must now report actively exploited vulnerabilities within 24 hours, more than a year before the Cyber Resilience Act's full 2027 rollout [9]. The obligation attaches to exploitation, not to having a fix ready [9]. Penalties reach 15 million euros or 2.5 percent of global revenue [10]. Above 600 million euros in revenue the percentage is the larger figure, because 15 million divided by 0.025 is 600 million [11].
Roughly 220.8 million passenger and crew records, including passport numbers and itineraries spanning nine years, sat on a misconfigured and inconsistently secured Elasticsearch cluster reachable over the internet until researchers helped get it secured in June [5]. Nobody has claimed the server. Its origin is unconfirmed, though it was linked to Vietnamese IP space [6].
The ChatGPT problem was also in infrastructure. Check Point Research found that a shared internal package-caching system let separate sessions pass messages to each other, so a planted prompt could instruct a victim's session to fetch Gmail data and hand it to an attacker's account with no visible confirmation step [7]. OpenAI has decommissioned the affected instance [8]. The Cyber Express wrote that the case shows shared infrastructure underlying AI services "can become a cross-account attack surface even when the model itself behaves correctly" [13].
Two of these incidents, the publisher wrote, "trace back to unpatched or misconfigured backend systems rather than sophisticated intrusion techniques" [12]. A reporting console, a search cluster and a package cache belonging to a supplier: an external attack surface report would list none of the three, and all three held or brokered identity data.
The State Department's 10 million dollar offer is for information on Amir Yaryab, accused of directing the IRGC-CEC's Cyber Operations Command and overseeing groups including CyberAv3ngers [3]. CyberAv3ngers has claimed attacks on industrial control systems and critical infrastructure in the US, Israel and elsewhere, including exploitation of default credentials on Unitronics PLCs [4]. The reward puts the cost on the operator: the plant still has to change the default credentials on its own controllers [4].
What to watch
- Whether Mathspace or the Australian and New Zealand regulators publish the Metabase version, CVE and exposure window.
- Whether the owner of the 220.8 million-record Elasticsearch cluster is identified, and by whom.
- The first CRA enforcement action against a connected-product maker that missed the 24-hour clock.