Upgradable Laptop Maker Framework Suffers Breach Affecting All Customers

Laptop manufacturer Framework suffered a data breach after hackers exploited a zero-day vulnerability in a third-party business intelligence tool called Metabase. The incident exposed customer contact information, though payment and order details remain secure.
<p>A hacker breached upgradable laptop maker Framework Computer and accessed a customer database. The San Francisco PC maker began <a href="https://www.reddit.com/r/framework/comments/1vhic7k/framework_data_breach/" target="_blank" title="(Opens in a new tab)">notifying</a> customers on Thursday, saying the breach exposed "customer names, email addresses, phone numbers, and [shipping] addresses," but not order or payment information. </p><p>The breach occurred through a third-party company called Metabase, which <a href="https://www.metabase.com/product/business-intelligence?use_case=bi" target="_blank" title="(Opens in a new tab)">uses</a> AI to deliver "business intelligence" to its <a href="https://www.metabase.com/case-studies" target="_blank" title="(Opens in a new tab)">100,000+</a> clients, which seem to include McDonalds, T-Mobile and Hugging Face. </p><p>The hacker used a previously unknown "<a href="https://www.pcmag.com/how-to/what-are-zero-day-exploits-and-attacks" target="_self">zero-day</a>" vulnerability in the Metabase Cloud system affecting versions 1.58 and above. "We also discovered that the attacker was able to gain access to your instance," Metabase told Framework on Thursday morning. </p><div class="mb-0 rounded-md bg-gray-100 p-3 md:p-5" id="related-video">
Get the full story
Sign up for Headlinne to unlock AI insights, political bias analysis, and your personalized news feed.
Create free accountAlready have an account? Sign in