Over 16,000 Supabase databases expose sensitive user data
Security researchers found over 16,000 Supabase databases with misconfigurations exposing user data including personally identifiable information, passwords, and authentication tokens. Some of the leaked records also include credit card data. The exposures span businesses globally and affect services ranging from a U.S. valet service to an African government consulate. Researchers attribute the leaks to poor security configurations, often linked to AI-assisted app development.
- Researchers found exposed PII, passwords, and tokens
- Databases were left readable due to poor security settings
- AI-assisted development is common among affected projects
- Data exposed worldwide, from businesses to government entities
- Researchers notified app owners in severe cases
Sources covering this
In this story
More in Cybersecurity
Critical zero-days in Citrix NetScaler exploited, patches released
Citrix has confirmed that two critical zero-day vulnerabilities affecting NetScaler ADC and Gateway devices have been exploited.
GitHub AI tool finds 24 vulnerabilities in Android apps
GitHub's Security Lab developed an open source AI agent that identified 24 vulnerabilities in Android applications using automated…
Apple fixes CoreGraphics flaw after targeted attacks
Apple has released security updates for iOS, iPadOS, and macOS to fix a CoreGraphics vulnerability that may have been used in highly…
AI-powered JadePuffer ransomware attacks destroy Azure resources
Researchers say the JadePuffer ransomware group has been using agentic AI to automate attacks targeting Microsoft Azure tenants,…