The exposed data encompasses a diverse range of sensitive materials, including private conversations from an adult streaming site, license plate logs from a valet service, and contact information linked to an immigration consultancy. UpGuard also discovered a database belonging to an African government consulate in France and another utilized by a virtual SIM farm to intercept text messages for potential phishing scams. While the majority of these instances are concentrated in the United States, the vulnerability affects projects on a global scale.
Thousands of Supabase Databases Found Leaking Sensitive User Information
Security researchers at UpGuard have identified approximately 16,000 databases hosted on the Supabase platform that are publicly exposing sensitive personal information to the open web. The findings reveal a widespread pattern of misconfiguration that leaves millions of private records, including addresses and authentication tokens, vulnerable to unauthorized access.

This incident underscores the risks inherent in the rise of rapid application development. As developers increasingly rely on AI-driven coding tools to build and deploy platforms, they often lack the expertise to manage complex security configurations. Bil Harmer, Chief Information Security Officer at Supabase, maintained that the platform remains secure by default. He emphasized that security is a shared responsibility, asserting that the company provides the necessary tooling while customers retain control over individual project settings. Supabase continues to implement platform updates aimed at simplifying secure deployment for its user base.



Comments (0)
No comments yet. Be the first!