CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Dire Wolf

actor · actor:dire-wolf

Ransomware and data-extortion group. VenariX reports it exploited the Metabase SQL-injection zero-day CVE-2026-72898 against self-hosted instances in at least two incidents (Statista, Dodo Payments) and suspects fourteen more targets; VenariX has no evidence the group discovered the flaw or is behind the other Metabase incidents.

Coverage
1
first 2026-08-09 → last 2026-08-09
Latest activity
2026-09-29
Metabase Cloud was breached through its own 0-day; self-hosted instances stay vulnerable until manually…
Peak priority
high
1 high
Targets
technology
sectors: technology, public-sector, finance · regions: europe
Sources cited
10
10 hosts

Action items (2)

Do-now tasks recorded on the entries about Dire Wolf, newest first. Check the date before acting on an older one.

  • Upgrade every self-hosted Metabase to at least 0.58.24 / 0.59.21 / 0.60.17 / 0.61.11 / 0.62.9 / 0.63.5, then, for any instance that was reachable and unpatched during the exploitation window, revoke all active sessions by clearing the core_session table, delete unrecognised API keys, and rotate the credentials for every connected database and warehouse, not just the Metabase admin credentials, because the upgrade does not invalidate what was already retrieved.
    2026-08-09CVE-2026-72898
  • Search Metabase application or reverse-proxy ingress logs across the entire pre-upgrade exposure window for a POST to /api/session/reset_password returning HTTP 400 immediately followed by a GET to /api/user/current returning HTTP 200 from the same source; Metabase states that sequence indicates the instance was likely compromised.
    2026-08-09CVE-2026-72898

Defender insights

What each entry about Dire Wolf tells a defender to do, newest first.

2026-08-09HIGHexploitedMetabase Cloud was breached through its own 0-day; self-hosted instances stay vulnerable until manually upgraded

Triage

Story timeline

  1. 2026-08-09Metabase CVE-2026-72898: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances, exploited since at least 3 August, fifteen downstream victims confirmed
    trending-vulnerabilitiesMetabase Cloud was breached through its own 0-day; self-hosted instances stay vulnerable until manually upgraded
ATT&CK techniques (5 across 6 tactics)

5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessValid Accounts · Exploit Public-Facing Application
  • PersistenceValid Accounts
  • Privilege EscalationValid Accounts
  • StealthValid Accounts
  • Credential AccessUnsecured Credentials · Unsecured Credentials: Credentials In Files
  • CollectionData from Information Repositories

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗

T1190Exploit Public-Facing Application×1

Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.

Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗

Credential Access TA0006

T1552Unsecured Credentials×1

Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. Shell History), operating system or application-specific repositories (e.g. Credentials in Registry), or other specialized files/artifacts (e.g. Private Keys).

Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗

T1552.001Unsecured Credentials: Credentials In Files×1

Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to store their own credentials, shared credential stores for a group of individuals, configuration files containing passwords for a system or service, or source code/binary files containing embedded passwords.

Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗

Collection TA0009

T1213Data from Information Repositories×1

Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or information sharing between users, and can store a wide variety of data that may aid adversaries in further objectives, such as Credential Access, Lateral Movement, or Defense Evasion, or direct access to the target information. Adversaries may also abuse external sharing features to share sensitive documents with recipients outside of the organization (i.e., Transfer Data to Cloud Account).

Evidence: 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally · ATT&CK page ↗

Entries about Dire Wolf (1)

2026-08-09 · view entry permalink →

HIGHCVE-2026-72898exploitedupdatedNATOA1

Metabase CVE-2026-72898: an unauthenticated SQL-injection zero-day gave attackers administrator access to BI instances, exploited since at least 3 August, fifteen downstream victims confirmed

Metabase, an open-source business-intelligence platform run both self-hosted and as a managed cloud service, disclosed on 2026-08-06 that its own Metabase Cloud environment had been attacked by someone using an unknown vulnerability affecting versions 1.58 and above, and that it blocked the endpoints used in the attack before identifying and patching the flaw (Metabase, 2026-08-06). The mechanism matters more than the platform: an unauthenticated caller injects arbitrary SQL against the Metabase application database, and that yields administrator access to the instance, from which the attacker can change the application configuration, steal the stored credentials Metabase holds for the databases it connects to, read anything reachable through those connections, and export it (Metabase, 2026-08-06). Neither the vendor nor the reporting locates the injection point precisely, but the vendor's stated interim workaround for anyone who cannot upgrade immediately is to block the /api/session/reset_password endpoint outright, and its published attack pattern runs through that same route (Metabase, 2026-08-06). BleepingComputer, quoting the associated security advisory, reports it is rated critical at CVSS 10.0 with active exploitation confirmed, and that no CVE identifier had been assigned (BleepingComputer, 2026-08-07). The advisory later assigned CVE-2026-72898, and CISA added it to its Known Exploited Vulnerabilities catalog on 2026-08-11 (CISA, 2026-08-11).

The exposure split is the part defenders need to act on. Metabase Cloud customers were upgraded and patched by the vendor, while self-hosted instances remain vulnerable until an administrator upgrades them by hand (Metabase, 2026-08-06). The minimum safe point releases are 0.58.24, 0.59.21, 0.60.17, 0.61.11, 0.62.9 and 0.63.5 for their respective branches, and anything on a lower point release of those branches is still vulnerable; installations below version 58 are not affected (Metabase, 2026-08-06).

Two organisations have confirmed data theft from their own instances. Framework, the laptop manufacturer, told customers that the attackers stole full names, email addresses, login IP addresses, billing and shipping address details, phone numbers and company names, with VAT, EIN and billing email address additionally in scope for its business customers, and said Metabase notified it on 6 August that its instance had been vulnerable and was accessed on 3 August (BleepingComputer, 2026-08-07). Tally, an online form builder, notified users that its Metabase analytics environment was compromised on the same date and that the attackers reached email addresses and password hashes, while its forms and the responses submitted to them are stored separately and were not reached (BleepingComputer, 2026-08-07). Those two were the first confirmed victims. The count has since grown to fifteen, set out in the updates below.

Detection is unusually well specified for a flaw that went its first week without a CVE, because the vendor published the request sequence rather than indicators. The attack shows up as a call to POST /api/session/reset_password returning a 400 status code followed by a call to GET /api/user/current returning 200, and Metabase states that finding that pattern in application logs or in Metabase server ingress logs means the instance was likely compromised (Metabase, 2026-08-06). After upgrading, the vendor's own follow-up steps for any instance whose reset endpoint was publicly reachable are to revoke every active session by deleting all rows in the core_session table, review and delete unrecognised API keys, check administrator accounts for unexpected changes, rotate the credentials for every connected database, and review both data-warehouse logs and Metabase's own activity and query history for unauthorised access (Metabase, 2026-08-06).

Triage: a 400 on the password-reset route is ordinary, users mistype addresses and reset flows reject malformed requests all day, and on its own the 400 means nothing. The discriminator is what follows it from the same source: an unauthenticated client that is genuinely failing a password reset has no session and cannot then get a 200 from /api/user/current, so it is the ordering and the success of the second call that separate exploitation from noise (Metabase, 2026-08-06).

We recently identified that Metabase Cloud was attacked by someone utilizing an unknown (“0-day”) security vulnerability in versions 1.58 and above.

After gaining access to your instance, the attacker could inject arbitrary SQL against the Metabase application database, which can give them administrator access to the instance.

If you find that pattern in your application logs or in your Metabase server ingress logs, it is likely that your instance has been compromised.

Metabase 2026-08-06

This is a CRITICAL vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance,

BleepingComputer 2026-08-07

Metabase has confirmed active exploitation of this vulnerability.

This is a CRITICAL vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance.

Metabase (GitHub Security Advisory) 2026-08-06

The Metabase vulnerability has already been tied to fifteen publicly confirmed incidents

VenariX has confirmed that Dire Wolf, a ransomware and data extortion threat actor, exploited CVE-2026-72898 in at least two incidents involving self-hosted Metabase deployments

There is currently no evidence that the threat actor discovered the zero-day or is behind the other confirmed Metabase-related incidents.

VenariX 2026-08-17

The affected system is a self-hosted deployment of Metabase, a third-party open-source tool that we use for internal reporting only.

Dodo Payments 2026-08-17

Credential rotation is especially important if exploitation is suspected, because patching the application does not invalidate credentials that may already have been exposed.

Metabase states that this pattern in application or ingress logs indicates that the instance was likely compromised.

VenariX 2026-08-17
Updaterun 2026-08-12T0411Z-intelactionscvesevidenceregionssectorssourcestagstechniquesbody

The entry on Metabase's unauthenticated SQL-injection zero-day closed on the observation that no CVE identifier had been assigned, so a purely CVE-driven patch process would not surface the exposure at all. That gap is now closed in both directions. GitHub Security Advisory GHSA-vwf4-m7j8-wcjf assigns CVE-2026-72898 with a CVSS 3.1 base score of 10.0 (AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H), and Metabase's own advisory text states that "Metabase has confirmed active exploitation of this vulnerability" and that the flaw "allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance" (Metabase, 2026-08-06). CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2026-08-11 with a 14 August due date (CISA, 2026-08-11).

The second half of the delta is the affected-version matrix, which the vendor's original blog post did not carry in this form. The advisory lists the affected ranges per release line as >= x.58.0 < x.58.23, >= x.59.0 < x.59.20, >= x.60.0 < x.60.16, >= x.61.0 < x.61.10, >= x.62.0 < x.62.8 and >= x.63.0 < x.63.3, and names the patched versions separately as x.58.24, x.59.21, x.60.17, x.61.11, x.62.9 and x.63.5; note the two lists do not meet, so a build sitting between an affected upper bound and its patched release is not described either way and should be treated as needing the named patched version (Metabase, 2026-08-06). That turns "upgrade Metabase" into a query an asset inventory can answer, and it is what a scanner needed in order to report anything at all.

Nothing here changes the exposure of an instance that has not been upgraded; the exploitation window has been open since at least 3 August per the earlier coverage, and the interim control is unchanged: block the /api/session/reset_password endpoint if an upgrade cannot happen immediately. What changed is visibility, and that is the operationally useful part. An organisation whose vulnerability management runs off CVE identifiers, SBOM matching or KEV feeds got no signal on this flaw for over a week while it was being exploited; the same tooling will now produce a finding on the next scan cycle. The advisory's post-upgrade guidance also stands and is worth re-reading against what an attacker with administrator access would already have taken: revoke active sessions, audit API keys and administrator accounts, and rotate the stored credentials for every connected data source, because those credentials are what an instance-level compromise reaches.

Updaterun 2026-08-19T0410Z-intelactionscvesevidencesectorssourcestagstechniquesbody

The count of downstream victims is now the story. A tracker maintained by VenariX, first published 2026-08-10 and updated 2026-08-17, states that "This brings the number of publicly confirmed downstream organizations tracked by VenariX to nine" (VenariX, 2026-08-17), n8n, Framework, Tally and Kilo Code from the first wave, with Stocksy United Co-op, ShipMonk, Checkly, Cypress.io and Bits of Gold added on 2026-08-17. The earlier entries covered the flaw itself: an unauthenticated SQL injection reachable at the password-reset endpoint, CVSS 10.0, exploited, catalogued as such on 2026-08-11.

The mechanism behind the growing list is a property of business-intelligence tooling rather than of this bug. Metabase stores the connection configuration, including credentials, for every external database and warehouse it queries; an attacker who reaches administrative context in the application can therefore read those stored credentials and query or export whatever they reach (VenariX, 2026-08-17). The blast radius of any given instance is set entirely by what it was wired to; VenariX's own framing is that a deployment connected only to a restricted reporting database is a materially different incident from one connected to a production warehouse, which is the assessment question a defender should be answering first.

The victim disclosures show the range. n8n's investigation found the attacker queried 136 records containing names and email addresses, five of which also carried bcrypt password hashes tied to n8n Cloud accounts, and reported that the queries returned a variable set of rows, which prevented it from determining exactly which individual records were returned. Framework confirmed customer data was stolen including names, email addresses, phone numbers, login IP addresses and billing and shipping addresses, with payment information not included. Tally's exposure covered email addresses and password hashes while form content was stored separately and unaffected, and Kilo Code's included names, email addresses, billing addresses, location data and, for a subset of users, partial or full prompts (VenariX, 2026-08-17). Of the newly added names, Bits of Gold separately disclosed on 2026-08-17 that an attacker gained unauthorized access to a third-party data analytics network and obtained names, national ID numbers and emails for roughly 200,000 customers (DataBreaches.net, 2026-08-17), the company describes the platform class, not the product, and it is VenariX that places the incident in this campaign.

The operational point is the one most likely to be got wrong in a remediation ticket. Metabase's own guidance, as VenariX relays it, is that "Credential rotation is especially important if exploitation is suspected, because patching the application does not invalidate credentials that may already have been exposed" (VenariX, 2026-08-17). An estate that upgraded Metabase and closed the ticket has fixed the injection and left the attacker holding working warehouse credentials. Metabase's fuller recommendation set for potentially exposed instances is to revoke active sessions, review administrator accounts and API keys, rotate credentials for connected databases, and review both Metabase and warehouse logs; where an immediate upgrade is impossible it recommends temporarily blocking access to the reset-password endpoint.

Detection has an unusually crisp anchor for a SQL-injection flaw, because the vendor published one. Metabase identified a recurring two-request pattern associated with exploitation (a POST to /api/session/reset_password returning HTTP 400, immediately followed by a GET to /api/user/current returning HTTP 200) and "Metabase states that this pattern in application or ingress logs indicates that the instance was likely compromised" (VenariX, 2026-08-17). Beyond that, the investigative surface is Metabase's own query history, database and warehouse audit logs, administrator accounts, API keys, and any unexpected use of the stored connection credentials; the last being where a compromise that started in the BI tier becomes visible in the warehouse tier.

Triage: a failed password reset followed by a session check is not by itself unusual in a web application's logs, which is exactly why the ordered pair matters rather than either request alone; a genuine failed reset does not produce an authenticated /api/user/current success on the same session immediately afterwards. Downstream, the discriminator for warehouse activity is whether queries arriving under the Metabase service credential match the dashboards and questions that credential is actually used for: bulk selects against tables no saved question references, or access at hours the reporting schedule does not run, are the signal, while high query volume under that identity is normal by design.

Updaterun 2026-09-27T0404Z-intelsourcesevidencesourcing_noteactionsbody

The downstream count grows again, and through a further intermediary this entry had not yet named. Shipup, a French platform used by more than 700 e-commerce brands to send delivery-tracking notifications and post-purchase communications, ran a Metabase instance that was compromised through the same CVE-2026-72898 unauthenticated SQL injection, with unauthorized access to the Shipup instance confirmed between 31 July and 17 August 2026, a window that starts earlier than the "since at least 3 August" this entry's own earlier coverage had established for the campaign (Cyberattaque.org, 2026-09-26). At least six of Shipup's retail clients have since notified their own customers of exposure: Carrefour notified some customers in early September, and Cyberattaque.org had already separately documented Printemps, Citadium, Aroma-Zone, Micromania and Easypara as affected through the same Shipup compromise (Cyberattaque.org, 2026-09-26; French Breaches, 2026-09-27). The exposed categories match the pattern this campaign has shown throughout: names, email addresses and phone numbers; Carrefour states no banking data or passwords were affected, and neither its own site, customer accounts nor internal systems were compromised, consistent with the exposure being limited to data it had shared with Shipup for delivery notifications. Carrefour has not disclosed the exact number of customers affected or confirmed whether the exposure window matches Shipup's own 31 July-17 August dates.

Shipup is a new entry in this campaign's chain of intermediary vendors, distinct from the data warehouses and analytics platforms this entry's earlier coverage described (n8n, Kilo Code and the others connected directly to a compromised Metabase instance): here, the retail brands are themselves downstream of a vendor that was downstream of the Metabase flaw, a second hop the credential-rotation and log-review guidance in this entry's original analysis already covers, since it applies to any instance that was reachable and unpatched during the exploitation window regardless of how many contractual layers separate the ultimate data subject from the compromised application.

Correctionrun 2026-09-27T1308Z-auditbody

The Shipup paragraph above stated that the 31 July to 17 August 2026 access window matched the exposure window this entry had already established for the campaign. It does not. This entry's earlier coverage places exploitation "since at least 3 August", so the Shipup window opens three days earlier and widens the campaign's known exposure period rather than corroborating it. For a defender scoping a log review against a Metabase instance or a downstream vendor relationship, the earlier start date is the operative one, and the sentence now says so.

Updaterun 2026-09-29T2134Z-audittitlesummarytagsentitiessourcesevidencesourcing_notebody

VenariX's tracker has grown from nine confirmed downstream incidents to fifteen. The additions since the 2026-08-17 count are Privy, Paradigm Connect Asia, Statista, Dodo Payments, Marsello and LEGO Certified Stores South Africa (VenariX, 2026-08-10, revised since). The Shipup compromise and its retail clients, covered in the update of 2026-09-27, are not on that list, so the real total is higher still.

The larger change is who is using the flaw. VenariX says it has confirmed that Dire Wolf, a ransomware and data-extortion group, exploited CVE-2026-72898 in at least two incidents against self-hosted Metabase deployments, at Statista and Dodo Payments, and suspects the group targeted fourteen more companies the same way. It is explicit that it has no evidence Dire Wolf discovered the zero-day or is behind the other confirmed incidents (VenariX, 2026-08-10, revised since). Dodo Payments, a payments company, confirms the vector without naming an actor: an unauthorised party exploited CVE-2026-72898 in a self-hosted Metabase instance used for internal reporting, viewed and queried the reporting datasets that system could reach, and the company contained it within hours of learning of it on 16 August (Dodo Payments, 2026-08-17). A dark-web listing dated 16 August, reviewed but not verified by MediaNama, claims about 60.8 GB and 39.3 million rows from four ClickHouse analytics databases, including tables it labels API keys, one-time passcodes and identity-provider credentials, where Dodo says API keys and credentials were not in the affected system (MediaNama, 2026-09-01).

For a defender this moves the self-hosted exposure from opportunistic data theft to an extortion operator's target list. The dispute over what left Dodo's warehouses is the point this entry has made since August: the reach of a compromised Metabase instance is whatever its stored connections reach, and the vendor's statement of what the BI tool itself held does not bound it. An instance that was internet-reachable on a vulnerable build between late July and its upgrade should be scoped as a warehouse compromise, not an application one.

vulnerability09 Aug 04:44Zmulti-sourceOpen finding →

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns1

Source distribution

  • bleepingcomputer.com1 (10%)
  • cisa.gov1 (10%)
  • cyberattaque.org1 (10%)
  • databreaches.net1 (10%)
  • dodopayments.com1 (10%)
  • frenchbreaches.com1 (10%)
  • github.com1 (10%)
  • medianama.com1 (10%)
  • other2 (20%)