Key takeaways Metabase has confirmed a maximum-severity flaw in its business intelligence platform was exploited as a zero-day, first against its own hosted service. An unauthenticated attacker could reach administrator access, then take the stored credentials for every database the tool connects to. The flaw scores 10.0, the highest possible rating, and has no CVE […]
Read MoreErnst & Young (EY), one of the Big Four accounting and advisory firms, is notifying clients of a data breach after an unauthorised party accessed a third-party IT support platform its staff use and downloaded documents. The breach centres not on EY’s audit systems but on a support-ticket tool, where client tax documents had been […]
Read More