A flaw in a business dashboard tool exposed customer lists before a fix existed, fake IT help desk calls are reaching personal phones, and X changes how creators get paid on September 8
A dashboard tool many companies use was broken into before a fix existed
Metabase is the software a lot of businesses put in front of their own database
so that staff can look at sales, orders and customer records without writing
queries. A flaw in it was being used by attackers before anyone knew it was
there.
Metabase's own security update, published August 6, says its cloud service "was
attacked by someone utilizing an unknown ('0-day') security
vulnerability" in versions 1.58
and above. The hole let an outsider with no account reach the password-reset
endpoint and inject commands into the application's database, which opens the
door to administrator access, stored database credentials and whatever those
credentials connect to. The advisory lists the fixed versions — 0.58.24, 0.59.21,
0.60.17, 0.61.11, 0.62.9, 0.63.5 or later — says Metabase Cloud instances have
already been upgraded, and gives a log pattern to look for: a POST to
/api/session/reset_password that returns 400, followed by a successful GET to
/api/user/current. Versions below 58 are not affected.
The results are already visible. Framework, the repairable-laptop maker, notified all of its customers that their data was accessed: full names, email addresses, login IP addresses, billing and shipping addresses, phone numbers and company names, with payment and order details not included. It says its instance was reached on August 3 and that Metabase informed it on August 6. The form-building service Tally disclosed the same root cause, with email addresses and hashed passwords taken and the answers people submitted through forms not touched. Why it matters: this splits into two jobs. If your business runs its own Metabase — or a contractor set one up for your dashboards — upgrade to a fixed version today, then rotate the database passwords it holds, revoke active sessions and check for admin accounts nobody created; upgrading alone does not evict someone who already took the credentials. If you are simply a customer of an affected company, the stolen details are exactly what makes a scam email convincing, so treat any message that recites your real address, order or phone number as unproven, and change your password anywhere you reused it.
Attackers are calling employees on their personal phones, pretending to be the help desk
The pitch is a phone call rather than an email, and it deliberately lands somewhere your employer's filters cannot see: your own mobile. Researchers at Google's threat intelligence group describe a group that calls staff posing as the internal IT help desk, saying an urgent security migration is underway — a passkey rollout, an MFA re-enrollment — and walking the person to a look-alike sign-in page whose web address pairs the company's name with words like "passkey", "sso" or "mfa". The page relays everything to the real login in the background, so it captures the password and the second-factor code together, and a security key or code app does not save you. In recent cases the callers have spoofed the help desk's genuine phone number so it looks right on the screen. Once inside, they delete the password-change and MFA-enrollment notifications that would have tipped off the victim, then run scripts to pull data out of Microsoft 365 and Okta. The write-up tracks the campaign moving through manufacturing, real estate, healthcare and insurance in the spring, then technology, transport and hospitality, and by July into financial, legal and professional services across North America, the UK and Australia. Extortion follows, with opening demands of $1–3 million. Why it matters: this attack only works in the ninety seconds while someone is on the phone feeling rushed, so give your team a rule that survives that moment: nobody sets up a passkey, resets a password or approves a login because of an inbound call. Hang up, then call IT back on the number you already had — not the one that called you, and not one read out to you. If you have no IT department, the same rule applies to anyone claiming to be your bank, your accountant or your hosting provider. Afterwards, check your account's recent security-alert emails: a gap where notifications should be is itself a sign.
X is ending its creator payout program on September 7
If part of your income comes from posting on X, the payment scheme behind it is being replaced. X's creator account announced that Revenue Sharing is being retired and Original Content Rewards takes its place. TechCrunch sets out the mechanics: people already in Revenue Sharing keep earning through September 7, 2026, the new program opens on September 8, and former participants have to apply to it rather than being carried across. The entry requirements are unchanged — an X Premium subscription, 500 verified followers, and 500,000 timeline impressions from verified accounts over 90 days — but what earns money is not. The company says payouts are meant for material the poster made: independent reporting and analysis, their own photos and video, original graphics, and commentary that adds something. Content copied from other accounts, reposted without change, or downloaded and re-uploaded is explicitly outside the program, which the company frames as fixing incentives that had become misaligned. Why it matters: put September 8 in your calendar as a date you have to act on, not one that acts on you — an account that qualified for years can find payouts simply stop because nobody re-applied. It also changes what is worth posting: accounts built on aggregating other people's clips no longer have a revenue case, while the photographs, walkthroughs and written analysis a small business makes anyway now do. And as ever with a scheme changing hands, expect "verify your creator account" messages in the run-up; go to the program through the app, never through a link.
An AI cyclone model that gave forecasters an extra day of warning is now public
Google has published the research behind the storm-forecasting model its weather team has been running, and released the model itself. Google's announcement says the work appeared in Nature and that the system "achieved state-of-the-art accuracy in predicting a cyclone's track, intensity, and wind structure", with forecasts that "can give an extra day of warning", and that the model is being open-sourced for other researchers. An extra day is the entire difference between an evacuation order that people can act on calmly and one that arrives during the school run.
The important caveat comes from the forecasters themselves. The National Weather Service describes AI models as guidance being carefully folded in alongside the traditional ones, notes that 2024 and 2025 were spent building trust in the new tools, and states plainly that "the official forecast is the most skillful and consistent, surpassing any individual model forecast", with human experts still needed to interpret and communicate the risk. Why it matters: in the middle of hurricane season you will increasingly see raw model runs circulating on social media, often days ahead of any official warning and often wrong. The forecast to act on is still the National Hurricane Center's, and the practical version of this news is simply that its warnings should keep arriving earlier than they used to — which is worth knowing if your business has a plan that assumes two days' notice.
A court has ordered Meta to fund $567 million of youth mental health treatment
A New Mexico court ruled on August 6 that the company's social platforms amount to a public nuisance in the state and ordered it to pay $567 million into a five-year fund to address the harm. The state's justice department describes the outcome as a $942 million order alongside changes to child protections on Facebook and Instagram, the larger figure being the abatement fund on top of the $375 million in civil penalties a jury imposed earlier in the year. Reporting on the ruling puts $420 million of the fund toward treatment services, with the remainder going to awareness, prevention, screening and referral work, and requires the company to report on its compliance twice a year for the five years the order runs. Why it matters: the ruling treats the design of an app as a public health question rather than a private product decision, which is the direction regulation of consumer software has been heading, and other states are watching this case. Nothing about it changes any app today. If you have teenagers in the house, the useful thing to do with a headline like this one is to open the supervision and account settings on the apps they actually use and see what is switched on, rather than to wait for a court in another state to do it.