Ethical Hacking News
A sharp rise in web data leaks in Japan has been attributed to mobile API abuse and Metabase attacks, with numerous organizations falling victim to these malicious activities. The JPCERT/CC has warned about the risks of these attacks, emphasizing the need for organizations to take immediate action to secure their web systems. By implementing access controls, enforcing rate limits, and regularly updating software, organizations can reduce the risk of these types of attacks and protect their sensitive data.
Japan has seen a sharp rise in web data leaks due to mobile API abuse and Metabase attacks. These attacks have resulted in large-scale personal data breaches, leaving many wondering about the motivations behind them. The JPCERT/CC has warned about the risks of mobile API abuse and Metabase attacks, citing vulnerabilities in mobile apps and weak admin-screen passwords. Mobile API abuse is a significant threat, allowing attackers to rewrite information and exploit vulnerabilities. The JPCERT/CC has identified a pattern of attacks using stolen API keys to obtain sensitive data. The Metabase vulnerability (CVE-2026-72898) allows SQL injection, providing attackers with administrator access. Organizations are advised to implement access controls, rate limits, and regularly update software to patch known vulnerabilities. Staying vigilant and monitoring for potential vulnerabilities is crucial to preventing future attacks.
In recent months, Japan has witnessed a sharp rise in web data leaks, with numerous organizations falling victim to mobile API abuse and Metabase attacks. According to the JPCERT Coordination Center (JPCERT/CC), a Tokyo-based center that takes incident reports, the attacks have resulted in large-scale personal data breaches, leaving many to wonder about the motivations behind these malicious activities.
The JPCERT/CC has warned about the risks of mobile API abuse and Metabase attacks, emphasizing that these types of attacks can lead to severe consequences, including unauthorized access to sensitive data. The center has attributed the attacks to a combination of factors, including the exploitation of known vulnerabilities in mobile apps and the use of weak admin-screen passwords.
Mobile API abuse, in particular, has been identified as a significant threat, with attackers utilizing publicly released smartphone apps to find API endpoints and keys. These endpoints can then be used to rewrite information, creating a vulnerability that can be exploited by malicious actors.
Furthermore, the JPCERT/CC has identified a pattern of attacks that involve the use of API keys stolen from compromised systems. In some cases, attackers have taken API keys from smartphone apps and called the API in a way that looks like normal use, thereby obtaining sensitive data.
The Metabase vulnerability, CVE-2026-72898, has also been identified as a key factor in these attacks. This vulnerability allows SQL injection into Metabase's own application database, providing attackers with administrator access and the ability to steal stored credentials for connected databases.
In response to these attacks, the JPCERT/CC has advised organizations to take immediate action to secure their web systems. This includes implementing access controls on every API endpoint, enforcing rate limits on API requests, and regularly updating software to patch known vulnerabilities.
Additionally, the JPCERT/CC has published a list of source IP addresses and User-Agent examples that were abused in the period in question. These indicators can be used by organizations to monitor their systems for potential vulnerabilities and take action to prevent future attacks.
Macnica, a Japanese company, has also reported an increase in web data leaks, with 119 incidents made public in the first half of 2026. This represents a significant increase from the 84 incidents reported in 2025 and 62 in 2024.
The Macnica report notes that the attackers are searching each site and its APIs for any flaw that allows them to obtain data. The flaws include APIs that return more data than necessary, APIs with excessive privileges, member functions accessible to anonymous users, logic errors, and session management faults.
To mitigate these risks, Macnica recommends that organizations implement a range of security measures, including:
* Implementing access controls on every API endpoint
* Enforcing rate limits on API requests
* Regularly updating software to patch known vulnerabilities
* Implementing a web application firewall (WAF) to detect and prevent attacks
* Conducting regular security audits and vulnerability assessments
Furthermore, the Macnica report notes that the attackers may be reusing a method that worked on one target against others, and in some cases, share source IP addresses. This highlights the importance of staying vigilant and monitoring for potential vulnerabilities.
In conclusion, the recent web data leaks in Japan highlight the need for organizations to take immediate action to secure their web systems. By implementing access controls, enforcing rate limits, and regularly updating software, organizations can reduce the risk of these types of attacks and protect their sensitive data.
Related Information:
https://www.ethicalhackingnews.com/articles/A-Rising-Tide-of-Web-Data-Leaks-in-Japan-A-Growing-Concern-Amid-Mobile-API-Abuse-and-Metabase-Attacks-ehn.shtml
https://thehackernews.com/2026/10/japan-sees-sharp-rise-in-web-data-leaks.html
Published: Thu Oct 8 13:19:24 2026 by llama3.2 3B Q4_K_M