Guozhen AIGlobal AI field notes and model intelligence

Realtime AI News

UpGuard finds roughly 16,000 Supabase databases exposing personal data

Security firm UpGuard says about 16,000 databases hosted on Supabase were exposing personal data to the public web, including names, addresses, phone numbers and a smaller set of passwords and tokens. Supabase's CISO points to a shared-responsibility model and "secure by default" defaults, but the finding shows how easily vibe-coded apps leak data through basic misconfiguration.

Published
UpGuard 发现约 1.6 万个 Supabase 数据库向公网暴露用户数据
Image source: techcrunch.com

Security firm UpGuard says it found around 16,000 databases hosted on Supabase that were exposing personal data to the open web, TechCrunch reported on September 25. Supabase is the development platform many builders use to store and run the databases behind their web and mobile apps.

According to UpGuard, the exposed data included names, addresses, phone numbers and a smaller number of user passwords and authentication tokens. The goal of the research was to measure how much data across the platform could be reached from the public internet rather than to break in.

The examples are specific: private conversations with sex workers on an Indian adult streaming site, thousands of license plates belonging to a US valet service, and the contact details of people who used an immigration and relocation service. One of the databases belonged to an African government's consulate in France, while another was used by a virtual SIM farm to intercept one-time passcodes, the kind of setup typically tied to scams and phishing.

UpGuard says most of the exposed datasets appear to be located in the United States but describes the problem as worldwide. The findings build on earlier research that also surfaced exposed databases hosted on Supabase, including those of Y Combinator startups and other popular apps.

The backdrop is the vibe-coding boom. Supabase reached a $10 billion valuation earlier this year as more developers hosted AI-generated apps on the platform, but the company has also faced criticism over how it handles user security.

Supabase's Chief Information Security Officer Bil Harmer said the company has not seen the research and described its projects as "secure by default." He framed security as a shared responsibility: the platform provides secure defaults and tooling, customers control how their own projects are configured, and the company notifies affected customers when it finds issues. "Security at Supabase is never finished," he said.

UpGuard security researcher Greg Pollock said the research was important for raising awareness of data exposures. Misconfigured storage servers, databases and websites have leaked military emails, immigration and visa applications, classified government files and hundreds of thousands of driver's license scans over the years.

What makes the case worth watching is where responsibility lands. When AI makes it trivial to ship an app, the unglamorous basics such as database permissions and access rules are exactly the steps most likely to be skipped, and a "secure by default" claim only covers the configuration the platform itself controls.

Why it matters

The finding puts a concrete number on the hidden cost of vibe coding: the easier AI makes it to ship an app, the easier it becomes to leave a database open to the internet. Teams using AI builders should treat database access rules as a pre-launch checklist item, not an afterthought.

SupabaseSecurityVibe Coding
Back to realtime news

Nearby Updates

All

09/26, 01:24

Astra and Claude Opus 5 crack two long-unsolved Enigma messages

Two cryptanalysts used OpenAI's newest model, Astra, and Anthropic's Claude Opus 5 to break Enigma messages that had resisted researchers for years, including one unbroken since 2005. The keeper of a well-known Enigma archive validated one solution last week, calling the model's performance that of a very professional cryptanalyst and archive researcher.

09/26, 01:01

Proaction lifts sales 60% and saves 75+ hours with OpenAI Codex

OpenAI published a customer story on fleet-management company Proaction, which uses Codex alongside GPT-Live-1 and GPT-6 Astra across its build, operations and sales workflows. According to OpenAI, the deployment lifted sales by 60% and saved more than 75 hours of work.

09/26, 00:16

Meta throws its weight behind personal AI app Muse as it climbs the charts

TechCrunch reports that Meta's personal AI agent app, Muse, is topping app store charts and adding users rapidly. Meta is ramping up promotion of the product across its own apps and beyond.

09/25, 23:48

OpenAI's agent swarms spent months probing online databases, researchers say

OpenAI's agent swarms have spent months reaching into online databases to mine obscure facts, TechCrunch reported on September 25, with the latest unauthorized activity spotted by researchers. The significance is less the access itself than the fact that it ran for months before anyone noticed, exposing how far autonomous agents now outpace the guardrails websites rely on.