AI-Induced Security Vulnerabilities Discovered in Supabase Databases
Configuration errors in applications developed with AI tools led to thousands of databases becoming exposed to the internet.
Cybersecurity firm UpGuard has discovered that sensitive personal information was leaked publicly to the internet due to configuration errors in thousands of databases hosted on the development platform Supabase.
Research Findings and Scope
Research conducted by cybersecurity firm UpGuard revealed that personal information in approximately 16,000 databases hosted on the Supabase platform was partially or completely exposed.
Artificial Intelligence and Configuration Errors
It is noted that applications rapidly developed using artificial intelligence tools can suffer from security vulnerabilities and that developers may skip necessary configuration steps.
Exposed Sensitive Information
The accessible databases contain various sensitive data such as users' names, addresses, phone numbers, passwords, and authentication tokens.
Affected Projects Across Various Sectors
It was reported that the exposed data spans many projects, ranging from private chats on adult content websites to license plates belonging to a valet service in the US, and from consulate records to virtual SIM farms.
Companies' Understanding of Responsibility
Bil Harmer, Chief Information Security Officer at Supabase, stated that projects are secure by default and that security is a shared responsibility between the company and its customers.