Mathspace Data Breach Exposes Over 1 Million People

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

Mathspace, an online mathematics program for students, has disclosed a data breach that impacts over 1 million individuals.

The incident, it says, was discovered last week, roughly three weeks after hackers compromised its self-hosted Metabase instance using a known vulnerability.

The security defect, tracked as CVE-2026-72898 (CVSS score of 10/10) and described as an SQL injection issue, was patched on August 6, after it had been exploited in the wild as a zero-day.

Shortly after the patches were released, the notorious extortion group ShinyHunters claimed responsibility for hacking Metabase.

Mathspace failed to escalate Metabase’s critical advisory to prioritize patching and upgraded its instance on August 29, more than two weeks after hackers hit it.

“Our investigation identified unauthorised access dating back to 10 August 2026, Australian Eastern Standard Time. We confirmed that information was downloaded from our Australian reporting database on 27 August,” Mathspace says in an incident notice...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more