JPCERT/CC warned that attackers are leaking personal data from Japanese organizations by abusing mobile app APIs, exploiting weak access controls, and taking advantage of known flaws such as CVE-2026-72898 in Metabase. The incidents have affected a wide range of public-facing and internal systems, including Park24, Monogatari Corporation, and other organizations that exposed sensitive data through web services. #JPCERTCC #Metabase #CVE202672898 #Park24 #MonogatariCorporation #YakinikuKing
Keypoints
- Attackers are abusing APIs in mobile apps and web systems to steal personal data.
- Known flaws and weak access controls are being exploited across public and internal services.
- Metabase CVE-2026-72898 is being used for unauthorized access and database theft.
- Major incidents include leaks at Park24 and Monogatari Corporation.
- JPCERT/CC recommends strict API access control, rate limiting, and rapid token revocation.
Read More: https://thehackernews.com/2026/10/japan-sees-sharp-rise-in-web-data-leaks.html