AI-Induced Security Vulnerabilities Discovered in Supabase Databases

Serdar HocamAuthor & Editor

Configuration errors in applications developed with AI tools led to thousands of databases becoming exposed to the internet.

◉ 0 views
Some Supabase customers are publicly exposing reams of people's data to the web | TechCrunch

Cybersecurity firm UpGuard has discovered that sensitive personal information was leaked publicly to the internet due to configuration errors in thousands of databases hosted on the development platform Supabase.

Research Findings and Scope

Research conducted by cybersecurity firm UpGuard revealed that personal information in approximately 16,000 databases hosted on the Supabase platform was partially or completely exposed.

Artificial Intelligence and Configuration Errors

It is noted that applications rapidly developed using artificial intelligence tools can suffer from security vulnerabilities and that developers may skip necessary configuration steps.

Exposed Sensitive Information

The accessible databases contain various sensitive data such as users' names, addresses, phone numbers, passwords, and authentication tokens.

Affected Projects Across Various Sectors

It was reported that the exposed data spans many projects, ranging from private chats on adult content websites to license plates belonging to a valet service in the US, and from consulate records to virtual SIM farms.

Companies' Understanding of Responsibility

Bil Harmer, Chief Information Security Officer at Supabase, stated that projects are secure by default and that security is a shared responsibility between the company and its customers.