UpGuard finds 16,326 Supabase databases with publicly readable tables, over half holding personal data
TechCrunch (also Cybernews, Unite.AI)·high signal
UpGuard traced most of the exposures to missing or weak Row Level Security. The open tables held names, addresses, phone numbers, some passwords and auth tokens, and a few plausible card numbers, and confirmed leaks included private chats from an Indian adult streaming site, license plates from a US valet service and an African consulate's database in France. Supabase CISO Bil Harmer called projects secure by default and security a shared responsibility, so check RLS on every table an agent created for you.