Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Mathspace Data Breach Affects Over One Million Users

Mathspace Data Breach Affects Over One Million Users

Posted on September 8, 2026 By CWS

Mathspace, a prominent online mathematics platform, has revealed a significant data breach affecting more than one million individuals. The breach was identified last week, occurring approximately three weeks after the security of Mathspace’s self-hosted Metabase instance was compromised by attackers exploiting a known vulnerability.

Details of the Breach

The vulnerability, identified as CVE-2026-72898 with a maximum CVSS score of 10/10, pertains to an SQL injection flaw. This issue was patched on August 6, but not before it was exploited as a zero-day vulnerability. The hacking group ShinyHunters has claimed responsibility for the breach, targeting Metabase shortly after the patches were made available.

Despite the urgency of the situation, Mathspace delayed the critical advisory from Metabase. The platform only updated its system on August 29, more than two weeks post-attack. Unauthorized access was traced back to August 10, with data from the Australian database confirmed to be downloaded on August 27, according to Mathspace’s incident notice.

Security Measures and Response

Mathspace admitted shortcomings in escalating the advisory and conducting necessary compromise checks suggested by Metabase. The company is now revising its response procedures to prevent future incidents. In response to the breach, Mathspace has taken their Metabase instance offline, revoked API keys, disabled database access, changed passwords, and exported logs for further investigation.

The breach has impacted 1,079,819 students, teachers, staff, and guardians across Australia and New Zealand. The stolen data includes names, user IDs, usernames, email addresses, verification status, time zones, countries, join dates, and login activity. Importantly, no academic records or sensitive authentication data were compromised.

Impact and Precautions

Mathspace warns that the stolen information could be used in phishing attacks, advising those affected to be cautious of unsolicited communications referencing the breach. The incident has been reported to authorities in Australia, and notifications to potentially impacted individuals commenced over the weekend.

The data breach underscores the critical importance of timely security measures and proactive vulnerability management in safeguarding user information. As Mathspace works to enhance its security protocols, the incident serves as a stark reminder of the evolving threats in the digital landscape.

Security Week News Tags:Australia, CVE-2026-72898, Cybersecurity, data breach, Mathspace, Metabase, New Zealand, Phishing, ShinyHunters, SQL injection

Post navigation

Previous Post: BengalSEO Campaign Exploits Bing for Malware and Scams
Next Post: U.S. Offers $10M for Iranian Cyber Chief Behind Attacks

Related Posts

OpenAI Addresses TanStack Supply Chain Breach OpenAI Addresses TanStack Supply Chain Breach Security Week News
MainStreet Bank Data Breach Impacts Customer Payment Cards  MainStreet Bank Data Breach Impacts Customer Payment Cards  Security Week News
React Native Vulnerability Actively Exploited in Attacks React Native Vulnerability Actively Exploited in Attacks Security Week News
Promptfoo Raises .4 Million for AI Security Platform Promptfoo Raises $18.4 Million for AI Security Platform Security Week News
CISA Demands Urgent Fix for Exploited LiteSpeed Flaw CISA Demands Urgent Fix for Exploited LiteSpeed Flaw Security Week News
Cybersecurity Updates: Rapid7 Layoffs and Boeing 737 Hack Cybersecurity Updates: Rapid7 Layoffs and Boeing 737 Hack Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • U.S. Offers $10M for Iranian Cyber Chief Behind Attacks
  • Mathspace Data Breach Affects Over One Million Users
  • BengalSEO Campaign Exploits Bing for Malware and Scams
  • Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam
  • Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • U.S. Offers $10M for Iranian Cyber Chief Behind Attacks
  • Mathspace Data Breach Affects Over One Million Users
  • BengalSEO Campaign Exploits Bing for Malware and Scams
  • Dutch Telecom Giant Hit by Massive Data Breach via Phone Scam
  • Adobe Fixes Critical Magento Flaw Used for Backdoor Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark