Summary

UpGuard research found approximately 16,000 Supabase-hosted databases exposing personal data to the public web, including names, addresses, phone numbers, and some passwords. Exposed data spans adult streaming conversations, valet license plates, immigration services, an African consulate, and a virtual SIM farm for OTP interception. The findings link the rise in AI “vibe-coded” apps to increased misconfiguration risks on the $10B-valued platform. Supabase CISO Bil Harmer said projects are “secure by default” and security is a shared responsibility with customers.

Source Analysis

[To be added during prescreening]

PreScreening Notes

  • Domain fit: software — developer-platform security and data exposure at scale
  • Newsworthiness: ~16,000 exposed Supabase databases; UpGuard research; AI vibe-coding misconfiguration angle on $10B platform
  • Audience: Software developers — high-impact security story with BaaS relevance
  • Duplicates: No active pipeline duplicate; prior Supabase evals coverage in 7-done is a different product story
  • Recency: Published Sep 25, ~31h old — passes 48h gate

Evaluation Report

News Value Assessment

  • Timeliness: Good — ~31h old; UpGuard report is fresh.
  • Impact: Very high — ~16,000 exposed databases affecting real individuals globally.
  • Prominence: Supabase ($10B), UpGuard, TechCrunch.
  • Proximity: Excellent — Supabase widely used by Turkish indie developers and startups.
  • Novelty: “Vibe-coding” misconfiguration angle is timely and distinctive.

Audience Fit

  • Top-tier story for software developers — directly actionable security checklist.
  • AI vibe-coding trend makes this immediately relevant to current development practices.
  • Strong reader engagement potential.

Risk & Ethics Assessment

  • Do not reproduce or link to exposed data.
  • UpGuard + TechCrunch are credible; Supabase CISO response included for balance.
  • Shared-responsibility framing is fair but does not diminish severity.

Publication Strategy

  • Format: standard — developer-focused with practical mitigation steps.
  • Related wiki: supabase, backend-as-a-service, application-security

Suggested Angle

Türkçe okuyucu için önerilen açı: “16.000 Supabase veritabanı internete açık: AI ile hızlı kodlama güvenliği nasıl tehlikeye atıyor?” — Geliştirici odaklı yazın: RLS (Row Level Security) kontrol listesi, API key yönetimi, production deploy öncesi güvenlik adımları. “Vibe-coding” trendinin güvenlik açıklarını nasıl artırdığını somut örneklerle gösterin.

Research Notes

Additional Sources

Key Facts Verified

  • 16,326 exposed databases from ~300K domain scan (confirmed: UpGuard, TechCrunch)
  • PII in >50%; passwords/tokens in smaller percentage (confirmed)
  • Vibe-coding/Lovable misconfiguration linked (confirmed: UpGuard CVE-2025-48757 context)
  • Supabase mandatory explicit grants Oct 30, 2026 (confirmed)
  • CISO: secure by default, shared responsibility (confirmed)

Broader Context

  • Actionable for Turkish indie developers using Supabase
  • RLS checklist critical before production deploy
  • AI-assisted rapid development increases misconfiguration risk

supabase, backend-as-a-service, row-level-security, vibe-coding, application-security

Editorial Notes

Status: Approved for reporting
Confirmed format: standard
Reporting instructions: Sızdırılmış veriye link verme. CISO ‘secure by default’ yanıtını dahil et. Türk indie developer perspektifi ekle.

Headline Suggestions (Turkish)

  • 16.000 Supabase veritabanı internete açık: Vibe-coding güvenlik riski
  • UpGuard: Supabase müşterilerinde kitlesel veri sızıntısı
  • AI ile hızlı kodlama güvenliği nasıl tehlikeye atıyor?

Mandatory Points

  • 16.326 exposed database (~300K domain taraması)
  • PII >%50; şifre/token daha düşük yüzde
  • Vibe-coding/Lovable misconfiguration bağlantısı
  • Supabase 30 Ekim 2026 mandatory explicit grants
  • RLS kontrol listesi ve pratik mitigasyon adımları

Draft Article

16.000 Supabase veritabanı internete açık: Vibe-coding güvenlik riski

UpGuard araştırması, yaklaşık 300.000 domain taramasında 16.326 Supabase veritabanının kişisel verileri kamuya açık bıraktığını tespit etti. İsim, adres, telefon ve bazı şifreler dahil PII %50’den fazla veritabanında bulundu. Bulgular, AI destekli “vibe-coding” trendinin yanlış yapılandırma riskini artırdığına işaret ediyor.

Ana Gelişme

Sızdırılan veriler arasında yetişkin streaming konuşmaları, vale plaka kayıtları, göçmenlik hizmetleri, bir Afrika konsolosluğu ve OTP interception için sanal SIM farm’ı yer alıyor.

Supabase CISO Bil Harmer, projelerin “secure by default” olduğunu ve güvenliğin müşteriyle paylaşılan sorumluluk olduğunu belirtti. Şirket 30 Ekim 2026’da zorunlu explicit grant politikası uygulayacak.

Neden Önemli?

Türk indie developer’lar arasında Supabase yaygın. Vibe-coding ve Lovable gibi araçlarla hızlı prototipleme, RLS atlanmasına yol açabiliyor.

Geliştirici Kontrol Listesi

  1. RLS’yi her tabloda etkinleştir
  2. API key’leri client-side’da expose etme
  3. Production deploy öncesi güvenlik audit’i yap
  4. Service role key’i yalnızca backend’de kullan

Bağlam

Application security ve BaaS platformlarında bu olay, “hızlı geliştirme” ile “güvenli varsayılanlar” arasındaki gerilimi somutlaştırıyor.


Kaynaklar