Skip to content
Brief Security & Trust ·

Japan's CERT warns of data leak wave; app API abuse and Metabase among methods

JPCERT/CC says attackers used app APIs and known flaws, but most causes are still unknown.

In brief
  • JPCERT/CC warned of data leaks involving app API abuse and a Metabase flaw. Macnica counted 119 similar public incidents this year.
  • For most cases, the entry point is unknown. Neither source says which leak used which method.

JPCERT/CC, Japan's incident-report center, said on October 8 that attackers behind a run of personal data leaks abused mobile app APIs and known software flaws, The Hacker News reported. Security firm Macnica counted 119 similar public incidents in Japan this year through October 6. Park24 said a third party took data on about 6.6 million Times Car accounts.

JPCERT/CC called its picture limited and fragmentary, and named no attacker or victim. Macnica said 65 of 81 cases made public since July gave too little detail to show the entry point. In some cases, Macnica said, attackers took API keys from a phone app and made calls that looked normal. JPCERT/CC also named CVE-2026-72898, a flaw in Metabase, a tool companies connect to their databases. An attacker needs no account, and the flaw can give admin access, from which stored database logins could be stolen. AhaSlides said a third party had access to its Metabase from August 12 to September 7, after the August 6 fix was released. Neither source says which leak used which method.

Macnica said scrambling an app's code does not hide keys built into it. A Metabase flaw could expose the databases it connects to. Do our apps ship secrets? Which internal tools face the internet? How fast do we patch?

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: The Hacker News.