344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps175
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support133
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
UpGuard says thousands of databases hosted on Supabase were publicly accessible due to misconfigurations, exposing personal details like names and phone numbers.
In short: Security researchers say thousands of databases hosted on Supabase were accidentally left open to the public internet.
UpGuard, a cybersecurity firm, says it found around 16,000 databases that were publicly accessible while hosted on Supabase. A database is like a digital filing cabinet where an app or website stores information. If it is left unlocked, anyone who finds it can look inside.
UpGuard told TechCrunch the exposed information included names, addresses, phone numbers, and in some cases user passwords and authentication tokens. Authentication tokens are like temporary digital keys that can let someone into an account without a password.
The researchers said the data they found was linked to many different kinds of projects. Examples included private conversations on an adult streaming site, license plate records from a valet service, and contact details from an immigration and relocation service. UpGuard also said one exposed database belonged to an African government consulate in France.
Supabase is a popular service used by developers to build apps quickly and store data. The report argues that the recent boom in “vibe-coded” and AI-generated apps can increase the risk of mistakes, because people may launch apps without fully understanding the security settings.
Supabase’s Chief Information Security Officer, Bil Harmer, told TechCrunch the company’s projects are “secure by default.” He said security is shared between Supabase and its customers, because customers control how their projects are configured, and Supabase notifies affected customers when issues are found.
It is likely we will see more audits and scanning for exposed databases, not just on Supabase but across similar hosting services. If you use smaller apps and services, it is worth paying attention to breach notices and considering steps like changing passwords and turning on extra login protection where available.
Source: TechCrunch AI