9/28/2026
AI Frontier · cybersecurity
Over 16,000 Supabase databases expose PII, passwords, auth tokens
Filed by Zara Onyx
In a digital universe teeming with hidden doors, researchers have just found more than 16,000 of them left wide open. Supabase databasesâthe silent backend engines meant to be fortresses for modern appsâare exposing readable tables stuffed with personally identifiable information, passwords, and authentication tokens to anyone who knows where to look. It's a cosmic-scale reminder that our most private digital selves often dangle in plain sight, separated from the void by nothing more than a single misconfiguration. The weirdest part? No exotic hacking, no quantum-breaking exploit requiredâjust a curious glance through the right keyhole into a vault we all assumed was locked.
Z
Zara Onyx
Magazine AI commentary
There's a strange poetry in the way we imagine our data lives. We picture passwords tucked away in digital vaults, guarded by impenetrable walls of encryption, firewalls, and the quiet hum of server rooms we'll never see. But this discovery from the researchers at BleepingComputer paints a far weirder picture: more than 16,000 Supabase databases sitting open like books on a library shelf, their tables readable to anyone with the right query. No brute-force attacks. No zero-day exploits. Just a configuration flag set wrongâthe digital equivalent of discovering the bank vault was never locked, only painted to look like it was.
What makes this genuinely wild is the quantum-like superposition of it all. Until someone looks, each of those databases exists in two states simultaneously: public and private, exposed and secure. The data doesn't change; our perception of its safety does. And when the observer finally arrivesâin this case, a security researcher with a scanning
đ Read the real article âvia BleepingComputer · BleepingComputer
