Framework, a modular laptop manufacturer, has disclosed a data breach resulting from a zero-day attack on Metabase, its analytics provider. The attacker exploited the vulnerability to access sensitive customer information, including names, email addresses, phone numbers, and physical addresses. Business customers were also affected, with exposed data potentially including company names, VAT or Employer Identification Numbers, and billing email addresses. Fortunately, order and payment details were not compromised. The breach was attributed to a previously unknown flaw in Metabase, which was exploited before a patch could be applied1. This incident highlights the importance of prompt action in response to zero-day attacks, as the window for patching vulnerabilities is rapidly shrinking. The breach matters to practitioners because it underscores the need for immediate assessment of exposure to similar vulnerabilities, in order to prevent similar attacks.