Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mathspace Data Breach Exposes Over 1 Million Users

Mathspace Data Breach Exposes Over 1 Million Users

Posted on September 7, 2026 By CWS

More than one million individuals in Australia and New Zealand have been affected by a significant data breach at Mathspace, an online mathematics learning platform. The breach occurred when attackers exploited a critical flaw in the company’s internal reporting software, compromising sensitive user information.

Details of the Breach

Sydney-based Mathspace disclosed on 3 September 2026 that unauthorized parties accessed its internal reporting system. This breach impacted students, parents, guardians, and school staff, totaling 1,079,819 affected individuals. This event has become one of the largest reported breaches in the education sector within the region this year.

The breach was facilitated through a vulnerability in Mathspace’s self-hosted Metabase installation, a business intelligence tool used for internal reporting. Identified as CVE-2026-72898, this flaw allowed attackers to execute arbitrary SQL commands through an unauthenticated SQL injection, gaining administrator access without valid credentials.

Response and Impact

Although Metabase released a patch for the vulnerability on 6 August 2026, Mathspace did not apply it promptly. The company acknowledged that its process for handling vulnerability notifications failed to escalate the advisory for action. Consequently, unauthorized access began on 10 August, and data exfiltration occurred on 27 August.

The compromised data included user IDs, names, email addresses, and other account-related metadata. However, Mathspace assured that critical credentials, such as passwords, SSO tokens, and academic records, were not exposed. There is no evidence thus far that the stolen data has been misused or made public.

Preventive Measures and Future Steps

In response, Mathspace has taken the affected reporting system offline and is revising its processes to prevent future incidents. The company has communicated the breach to school contacts, urging them to verify suspicious communications through official channels. Furthermore, Mathspace is working with cybersecurity authorities to enhance its security measures.

Affected individuals are advised to remain vigilant, monitor accounts for unusual activity, and avoid reusing passwords across different services. Mathspace’s proactive measures aim to restore trust and prevent similar breaches in the future.

For further details, Mathspace encourages users to stay informed through its data-breach response channels.

Cyber Security News Tags:Australia, CVE-2026-72898, Cybersecurity, data breach, education technology, Mathspace, Metabase, New Zealand, SQL injection, user data security

Post navigation

Previous Post: Zero-Day Vulnerability Hits Adobe Commerce Platforms
Next Post: Executives Targeted in Microsoft 365 Data Extortion Scam

Related Posts

Critical React2Shell Vulnerability Under Attack Critical React2Shell Vulnerability Under Attack Cyber Security News
10 Best VPN Alternatives in 2025 10 Best VPN Alternatives in 2025 Cyber Security News
Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands Cyber Security News
Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code Fake Postmark MCP Server Silently Stole Thousands of Emails With a Single Line of Malicious Code Cyber Security News
OpenClaw Vulnerabilities Lead to Security Risks OpenClaw Vulnerabilities Lead to Security Risks Cyber Security News
New Android Malware ‘Fantasy Hub’ Intercepts SMS Messages, Contacts and Call Logs New Android Malware ‘Fantasy Hub’ Intercepts SMS Messages, Contacts and Call Logs Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Switzerland to Test Open-Source Alternative to Microsoft 365
  • ScreenConnect Exploited in Cyberattack Campaign
  • Executives Targeted in Microsoft 365 Data Extortion Scam
  • Mathspace Data Breach Exposes Over 1 Million Users
  • Zero-Day Vulnerability Hits Adobe Commerce Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Switzerland to Test Open-Source Alternative to Microsoft 365
  • ScreenConnect Exploited in Cyberattack Campaign
  • Executives Targeted in Microsoft 365 Data Extortion Scam
  • Mathspace Data Breach Exposes Over 1 Million Users
  • Zero-Day Vulnerability Hits Adobe Commerce Platforms

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark