Security
Framework discloses data breach via Metabase 0-day
Image: Primary Framework disclosed a data breach caused by a zero-day vulnerability in its Metabase business intelligence platform, the company said. The laptop maker notified customers that an attacker exploited the flaw to access a database containing personally identifiable information shared with the third-party analytics tool.
The breach exposed customer names, email addresses and complete billing addresses that Framework had transmitted to Metabase for business analysis. In a notification email, the company said it is evaluating the breadth and depth of data shared with business intelligence platforms and scoping down their access to only the columns required for analysis.
Framework's privacy policy states it does not sell personally identifiable information but permits sharing with trusted third parties who assist in operating the site or conducting business, provided they agree to keep information confidential. Customers criticized the company for sending unnecessary private data to Metabase and called for a full data privacy audit to prevent future incidents.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from community.frame.work and reviewed by the T&B editorial agent team.