
16,326 Supabase Databases Caught Leaking Live Data
UpGuard scanned 300,000 domains and found 16,326 Supabase-hosted databases with publicly readable tables, many built by AI coding tools that skip Postgres row-level security by default.
They summarize our coverage. We write it.
Newsletters like this one rebroadcast our headlines - often without the full review, the source reading, or the analysis underneath. Our weekly briefing sends the work they paraphrase, straight from the desk, before they get to it.
Free, weekly, no spam. One email every Tuesday. Unsubscribe anytime.

UpGuard scanned 300,000 domains and found 16,326 Supabase-hosted databases with publicly readable tables, many built by AI coding tools that skip Postgres row-level security by default.

A missing noindex tag let Google surface hundreds of private Claude conversations and Artifacts in late July 2026, the third time in eleven months a major chatbot's share feature has leaked user chats onto the open web.

A hacker leaked Suno source code showing exactly how it scraped YouTube, Deezer, Genius, and a million hours of podcasts for AI training data.

A private Discord group has been quietly using Anthropic's most restricted AI model since the hour it shipped. They got in with a stolen contractor badge and a URL guessed from the Mercor breach.

A fresh warning from developer Morgan Linton says free Lovable accounts can still read other users' AI chat histories, source code, and database credentials on projects created before November 2025. The pattern is the same one that earned the platform CVE-2025-48757 last year.

Swiss broadcaster RTS reopens the 2023 Tesla Files leak in context of the confirmed $243M Miami verdict. The combined record: 2,400+ concealed sudden-acceleration complaints, 1,000+ undisclosed crashes, and a federal court that found Tesla knew.

A default-public setting in Anthropic's CMS accidentally exposed 3,000 unpublished assets, including a draft blog post revealing Claude Mythos - a new flagship model the company says poses serious cybersecurity risks.

A CMS misconfiguration exposed nearly 3,000 unpublished Anthropic assets, including draft details of Claude Mythos, a new model tier the company says poses serious cybersecurity risks.

Two pull requests in OpenAI's public Codex GitHub repo referenced GPT-5.4 before being scrubbed - one adding full-resolution vision support, the other a fast mode toggle. Seven force pushes and a deleted employee screenshot confirm this was not intentional.

An unknown attacker used over 1,000 prompts to jailbreak Anthropic's Claude, generating exploit code that breached six Mexican government agencies and exfiltrated 195 million taxpayer records.

DeepSeek's V4 Lite model has leaked through inference provider testing under strict NDAs, revealing a 1M token context window, native multimodal capabilities, and the internal codename sealion-lite.

Turkish AI company Codeway left Firebase and Google Cloud Storage wide open, exposing 300 million chat messages from 25 million users and 8.27 million photos and videos across two apps. Over 12 TB of user data leaked.