Japan Faces Surge in Web Data Leaks via API Abuse and Metabase Flaws
Original source
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
The Hacker News →Japanese organizations are experiencing a sharp rise in web data leaks due to mobile API abuse and attacks on known software vulnerabilities. The JPCERT Coordination Center reported that attackers have exploited APIs in consumer apps, business intelligence tools, and management systems, leading to significant data breaches. The incidents, which began around September 2026, involve unauthorized API requests, stolen API keys, and exploitation of known flaws like CVE-2026-72898 in Metabase, a BI tool. The attacks have affected various sectors, including online shops, member services, and business systems, with some breaches exposing millions of records. Defenders are advised to implement strict API access controls and upgrade to the latest Metabase versions to mitigate risks.
Read the full article
Continue reading at The Hacker News →This is an AI-generated summary. Read the original for the full story.