OZZZER · AI NEWS1 of 3 free stories opened
← Back to AI News

AI · 25 Sep 2026 · 19:29 CEST

Some Supabase customers are publicly exposing reams of people’s data to the web

TechCrunch AI · 25 Sep 2026 · 19:29 CESTRead original at TechCrunch AI ↗
Share
LinkedInX
Some Supabase customers are publicly exposing reams of people’s data to the web

Publisher preview · OZZZER analysis pending editorial review.

PUBLISHER ARTICLE PREVIEW

From the original article

Thousands of databases hosted by development platform Supabase are exposing people’s sensitive information to the public web, new security research by cybersecurity firm UpGuard has found.

UpGuard told TechCrunch that it found around 16,000 databases on which some degree of personal data was exposed while they were hosted by Supabase, which allows web and app developers to store and run their databases.

Supabase earlier this year reached a $10 billion valuation, thanks to a rise in developers hosting their vibe-coded apps on the platform. But the company has faced criticism for how it handles user security. There are widely documented cases of users misconfiguring or unknowingly exposing their databases to the broader internet, in some instances to the tune of millions of records each.

The findings highlight how vibe-coded apps and websites can spill or expose sensitive data through basic misconfigurations and improper security. While AI tools can be used to easily build websites and apps, the generated code can often contain security flaws, or apps might require specific configuration that the developer may be ignorant of.

Over the years, countless data breaches have been linked to improperly configured storage servers, databases and websites. Such cases have resulted in the leaks of sensitive military emails, immigration and visa applications, classified government files, hundreds of thousands of driver’s license scans,

Source

TechCrunch AI · 25 Sep 2026 · 19:29 CEST

Open the original at TechCrunch AI ↗