
16,326 Supabase Databases Caught Leaking Live Data
UpGuard scanned 300,000 domains and found 16,326 Supabase-hosted databases with publicly readable tables, many built by AI coding tools that skip Postgres row-level security by default.
They summarize our coverage. We write it.
Newsletters like this one rebroadcast our headlines - often without the full review, the source reading, or the analysis underneath. Our weekly briefing sends the work they paraphrase, straight from the desk, before they get to it.
Free, weekly, no spam. One email every Tuesday. Unsubscribe anytime.

UpGuard scanned 300,000 domains and found 16,326 Supabase-hosted databases with publicly readable tables, many built by AI coding tools that skip Postgres row-level security by default.

OpenAI's most capable model yet tops cybersecurity and agentic benchmarks, but a rocky rollout, user complaints of degraded output, and its own system card's warnings about hidden reasoning complicate the launch.

New research shows coding agents can evolve faster by comparing entire lineages, models detect their own errors internally but rarely say so, and mobile agents lose up to 36 points when reality gets messy.

Alibaba's 2.4 trillion parameter flagship ships with real pricing and a published benchmark table, but the open-weight release it promised for this week still hasn't shown up.

Anthropic is making Claude Code's auto mode the default for Pro, Max, and Team plans on August 14, citing a study where a classifier caught 89% of dangerous commands versus 13.6% for human reviewers.

Claude Opus 5 matches near-frontier coding scores at half the price of Anthropic's own Mythos-class models - here's the full July 2026 ranking.

Meta's second Muse model ships a public API at $1.25/$4.25 per million tokens, a 1M-token context window, and the top score on Meta's own tool-use benchmarks.

Meta's second Muse Spark ships with a real API, a 1M-token context window and the cheapest pricing among frontier-class agents, but only US developers can touch it.

Claude Opus 5 ties Claude Fable 5 on independent benchmarks at roughly a quarter of the cost, though a rough launch week and cybersecurity limits keep it from being an unqualified win.

Cognition paid a low nine-figure sum for texting assistant Poke, its second acquisition in a year, betting that how an AI agent talks matters as much as what it can do.

Anthropic's July 2026 release prices near-Fable-5 coding and agentic performance at Opus 4.8 rates, doubling Frontier-Bench scores and landing within 0.5 points of Fable 5 on CursorBench at half the cost.

Cognition rebranded Windsurf as Devin Desktop and rebuilt it around a Kanban board for managing fleets of coding agents - here's what that actually changes.