Attackers access Lego Certified Stores SA customers' personal data with zero-day

Jan

Who's the Boss?
Staff member
Joined
May 24, 2010
Messages
14,881
Reaction score
13,564
Location
The Rabbit Hole
Lego Certified Stores South Africa hit by zero-day hack of third-party database provider

Personal information of Lego Certified Stores customers in South Africa was exposed following the breach of a reporting tool used by the company that operates its loyalty and marketing programme.

Lego Certified Stores South Africa sent an email to customers on Friday, 14 August 2026, notifying them of the breach and offering advice on precautionary measures they could take.
 
Most likely this 0day.


Get's a max rating of 10.

The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain administrator access to the instance.

sql injection 🤬
 
We have Lego stores in SA?

Never seen one before, or is this only in larny shopping malls?
 
Top
Sign up to the MyBroadband newsletter
X