16,000 Supabase databases exposed due to misconfigurations
Over 16,000 Supabase databases were found misconfigured, exposing personally identifiable information, passwords, and authentication tokens. Researchers at UpGuard analyzed 300,000 domains and discovered that more than half of the exposed databases contained sensitive data, including credit card details in some cases. Notable incidents involved a U.S. valet service exposing 100,000 customer records, a Canadian immigration service leaking 884 plaintext passwords, and an African government consulate revealing records of 25,000 individuals. The misconfigurations stem from poor security policies, including missing row-level security and misuse of public keys. UpGuard attributes these issues to a lack of understanding among developers, particularly those using AI-assisted tools.
Read the full article
Continue reading at BleepingComputer →This is an AI-generated summary. Read the original for the full story.