Quick Security Hits: Metabase Zero-Day Exploits, npm Supply-Chain Attack, Vishing Wave, and Healthcare Data Leak
A healthcare incident exposed 3.8 million records containing names, Social Security numbers, medical data, and insurance details. Levi Strauss reported a social engineering attack that compromised three employee computers and led to corporate data exfiltration. The Metabase zero-day vulnerabilities continued to be exploited for data theft.
The Metabase flaw enables remote attackers to bypass authentication entirely, granting full database control and credential theft, with Framework and Tally already confirmed as victims. Separately, the npm campaign leverages automated package creation to distribute malware that disables Windows security monitoring and establishes persistent backdoors across all major operating systems.
UNC6671's tactics involve spoofing helpdesk numbers to trick employees into surrendering live session tokens, enabling automated data theft from cloud platforms. Meanwhile, the healthcare breach at Unlimited Technology Systems occurred in October 2025, exposing sensitive medical and insurance details for millions of individuals.
These incidents could affect a broad cross-section of society, from corporate employees targeted by vishing to consumers whose personal and medical data is exposed. The Metabase and npm attacks may compromise enterprise infrastructure, potentially leading to widespread data breaches. Healthcare patients could face identity theft or insurance fraud. Organizations may need to reassess their security postures, particularly around authentication and supply-chain integrity, while individuals might experience increased phishing attempts and data privacy risks.