Select a theme from the list.
Insights

From our experts

Latest
Apple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent AttacksApple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksThousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentNeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksLunex Leaves Security Tools Running but Blind Before Raiding BrowsersCloudflare Container Flaw Broke the Wall Between Customer WorkloadsStorm-3168 Turns Stolen Azure Identities Into a Seven-Minute WipeoutOne Encoded Character Lets Attackers Slip Past WAFs and Hit PeopleSoftClop Ransomware Gang Gets Hacked Through Its Own Outdated CMSMicrosoft Pushes Data-Loss Prevention Into the Path of Shadow AIDormant GitHub Actions Reawakened With Their Malicious Payloads IntactKiteworks Calls for Emergency Shutdown as Authorities Warn of Imminent Attacks
Security Insight

Thousands of Supabase Databases Leak the Secrets Behind Rapid App Development

Thousands of Supabase Databases Leak the Secrets Behind Rapid App Development
Photo by Ann H on Pexels

Researchers identified more than 16,000 improperly secured Supabase databases that exposed readable information, including personal records, passwords and authentication tokens. The findings show how weak access policies can turn a convenient cloud development platform into a direct channel for data leakage.

More than 16,000 Supabase databases have been found exposing information through insecure application configurations, according to research reported by BleepingComputer. The accessible records included personally identifiable information, passwords, authentication tokens, private messages and, in a small number of cases, possible payment-related data.

Convenience Without Access Control

Supabase is an open-source development platform built around PostgreSQL. It gives developers ready-made database, authentication, storage and application programming interface capabilities, making it attractive to startups, rapid prototypes and teams using AI coding assistants.

Researchers examined approximately 300,000 domains showing signs of Supabase use. They discovered that thousands of applications allowed outsiders to query tables because row-level security was absent, incomplete or ineffective. In other cases, developers appeared to misunderstand how public application keys should be combined with database access policies.

The exposed systems reportedly included a valet service with more than 100,000 customer records, an immigration service storing plaintext passwords, a messaging platform containing private communications and a government consular service holding sensitive personal details.

The research highlighted the growing use of AI-assisted development, but it did not prove that every exposed application had been created by an AI agent. That distinction matters. The underlying problem is not AI itself, but the deployment of generated code without a competent security review or a clear understanding of the platform's authorization model.

How Development Teams Can Respond

  • Enable row-level security on every table containing user or business information.
  • Test database access as anonymous, authenticated and unauthorized users.
  • Keep privileged service-role credentials out of browsers and mobile applications.
  • Review storage buckets, database functions and automatically generated APIs.
  • Add configuration testing to continuous integration and deployment pipelines.
  • Rotate credentials and notify affected users when exposure is confirmed.

I believe this incident reflects a widening gap between the speed of application creation and the maturity of application ownership. A developer can now assemble a working service in hours, but the security consequences may persist for years if nobody validates who can retrieve the underlying data.

Organizations should treat backend-as-a-service platforms as production infrastructure, not as harmless development shortcuts. Secure defaults help, but they cannot replace authorization testing, data classification and accountable human review before an application is exposed to the internet.

Talk to our team →

Latest

Apple Closes CoreGraphics Flaw Linked to Sophisticated Targeted AttacksSep 29, 2026Thousands of Supabase Databases Leak the Secrets Behind Rapid App DevelopmentSep 29, 2026NeedyMantis Gives Targeted Intruders a Modular Foothold Inside Windows NetworksSep 29, 2026SharePoint Code-Execution Flaw Moves From Patch Notes to Active AttacksSep 28, 2026Lunex Leaves Security Tools Running but Blind Before Raiding BrowsersSep 28, 2026Cloudflare Container Flaw Broke the Wall Between Customer WorkloadsSep 28, 2026

Most read

1Sophos Turns Its Own Network Into a Proving Ground for Safer Enterprise AI2Sophos Fusion Recasts the Security Platform as an AI-Driven Defense System3Microsoft Makes Passkeys the Entra ID Default and Sets a Deadline for Native SMS Authentication4Global CMS Exploitation Wave Plants Webshells on Business Websites5Critical NGINX Overflow Puts Internet-Facing Servers on an Urgent Upgrade Path6Laser Attack Exposes an Unpatchable Weakness in Tangem Crypto Wallet Cards