Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks

Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
JPCERT/CC warned that attackers are leaking personal data from Japanese organizations by abusing mobile app APIs, exploiting weak access controls, and taking advantage of known flaws such as CVE-2026-72898 in Metabase. The incidents have affected a wide range of public-facing and internal systems, including Park24, Monogatari Corporation, and other organizations that exposed sensitive data through web services. #JPCERTCC #Metabase #CVE202672898 #Park24 #MonogatariCorporation #YakinikuKing

Keypoints

  • Attackers are abusing APIs in mobile apps and web systems to steal personal data.
  • Known flaws and weak access controls are being exploited across public and internal services.
  • Metabase CVE-2026-72898 is being used for unauthorized access and database theft.
  • Major incidents include leaks at Park24 and Monogatari Corporation.
  • JPCERT/CC recommends strict API access control, rate limiting, and rapid token revocation.

Read More: https://thehackernews.com/2026/10/japan-sees-sharp-rise-in-web-data-leaks.html