Summary
UpGuard research found approximately 16,000 Supabase-hosted databases exposing personal data to the public web, including names, addresses, phone numbers, and some passwords. Exposed data spans adult streaming conversations, valet license plates, immigration services, an African consulate, and a virtual SIM farm for OTP interception. The findings link the rise in AI “vibe-coded” apps to increased misconfiguration risks on the $10B-valued platform. Supabase CISO Bil Harmer said projects are “secure by default” and security is a shared responsibility with customers.
Source Analysis
[To be added during prescreening]
PreScreening Notes
- Domain fit: software — developer-platform security and data exposure at scale
- Newsworthiness: ~16,000 exposed Supabase databases; UpGuard research; AI vibe-coding misconfiguration angle on $10B platform
- Audience: Software developers — high-impact security story with BaaS relevance
- Duplicates: No active pipeline duplicate; prior Supabase evals coverage in
7-doneis a different product story - Recency: Published Sep 25, ~31h old — passes 48h gate
Evaluation Report
News Value Assessment
- Timeliness: Good — ~31h old; UpGuard report is fresh.
- Impact: Very high — ~16,000 exposed databases affecting real individuals globally.
- Prominence: Supabase ($10B), UpGuard, TechCrunch.
- Proximity: Excellent — Supabase widely used by Turkish indie developers and startups.
- Novelty: “Vibe-coding” misconfiguration angle is timely and distinctive.
Audience Fit
- Top-tier story for software developers — directly actionable security checklist.
- AI vibe-coding trend makes this immediately relevant to current development practices.
- Strong reader engagement potential.
Risk & Ethics Assessment
- Do not reproduce or link to exposed data.
- UpGuard + TechCrunch are credible; Supabase CISO response included for balance.
- Shared-responsibility framing is fair but does not diminish severity.
Publication Strategy
- Format:
standard— developer-focused with practical mitigation steps. - Related wiki: supabase, backend-as-a-service, application-security
Suggested Angle
Türkçe okuyucu için önerilen açı: “16.000 Supabase veritabanı internete açık: AI ile hızlı kodlama güvenliği nasıl tehlikeye atıyor?” — Geliştirici odaklı yazın: RLS (Row Level Security) kontrol listesi, API key yönetimi, production deploy öncesi güvenlik adımları. “Vibe-coding” trendinin güvenlik açıklarını nasıl artırdığını somut örneklerle gösterin.
Research Notes
Additional Sources
- 2026-09-25-upguard-supabase-exposure — UpGuard primary research
- 2026-09-25-runtimewire-supabase-upguard — RuntimeWire analysis
- 2026-09-25-ua-news-supabase-exposure — International corroboration
Key Facts Verified
- 16,326 exposed databases from ~300K domain scan (confirmed: UpGuard, TechCrunch)
- PII in >50%; passwords/tokens in smaller percentage (confirmed)
- Vibe-coding/Lovable misconfiguration linked (confirmed: UpGuard CVE-2025-48757 context)
- Supabase mandatory explicit grants Oct 30, 2026 (confirmed)
- CISO: secure by default, shared responsibility (confirmed)
Broader Context
- Actionable for Turkish indie developers using Supabase
- RLS checklist critical before production deploy
- AI-assisted rapid development increases misconfiguration risk
Related Wiki
supabase, backend-as-a-service, row-level-security, vibe-coding, application-security
Editorial Notes
Status: Approved for reporting
Confirmed format: standard
Reporting instructions: Sızdırılmış veriye link verme. CISO ‘secure by default’ yanıtını dahil et. Türk indie developer perspektifi ekle.
Headline Suggestions (Turkish)
- 16.000 Supabase veritabanı internete açık: Vibe-coding güvenlik riski
- UpGuard: Supabase müşterilerinde kitlesel veri sızıntısı
- AI ile hızlı kodlama güvenliği nasıl tehlikeye atıyor?
Mandatory Points
- 16.326 exposed database (~300K domain taraması)
- PII >%50; şifre/token daha düşük yüzde
- Vibe-coding/Lovable misconfiguration bağlantısı
- Supabase 30 Ekim 2026 mandatory explicit grants
- RLS kontrol listesi ve pratik mitigasyon adımları
Draft Article
16.000 Supabase veritabanı internete açık: Vibe-coding güvenlik riski
UpGuard araştırması, yaklaşık 300.000 domain taramasında 16.326 Supabase veritabanının kişisel verileri kamuya açık bıraktığını tespit etti. İsim, adres, telefon ve bazı şifreler dahil PII %50’den fazla veritabanında bulundu. Bulgular, AI destekli “vibe-coding” trendinin yanlış yapılandırma riskini artırdığına işaret ediyor.
Ana Gelişme
Sızdırılan veriler arasında yetişkin streaming konuşmaları, vale plaka kayıtları, göçmenlik hizmetleri, bir Afrika konsolosluğu ve OTP interception için sanal SIM farm’ı yer alıyor.
Supabase CISO Bil Harmer, projelerin “secure by default” olduğunu ve güvenliğin müşteriyle paylaşılan sorumluluk olduğunu belirtti. Şirket 30 Ekim 2026’da zorunlu explicit grant politikası uygulayacak.
Neden Önemli?
Türk indie developer’lar arasında Supabase yaygın. Vibe-coding ve Lovable gibi araçlarla hızlı prototipleme, RLS atlanmasına yol açabiliyor.
Geliştirici Kontrol Listesi
- RLS’yi her tabloda etkinleştir
- API key’leri client-side’da expose etme
- Production deploy öncesi güvenlik audit’i yap
- Service role key’i yalnızca backend’de kullan
Bağlam
Application security ve BaaS platformlarında bu olay, “hızlı geliştirme” ile “güvenli varsayılanlar” arasındaki gerilimi somutlaştırıyor.