Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Over 16,000 misconfigured Supabase databases expose personal data passwords and auth tokens

UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens, with a very small subset appearing to include credit card data. Supabase is an open-source PostgreSQL development platform, popular with developers using AI tools, which now account for more than 60 percent of newly created databases. UpGuard analyzed about 300,000 domains showing Supabase use and inferred exposed data types from table schemas. More than half of the exposed databases held PII, with a smaller subset exposing passwords and tokens. One US valet service alone exposed over 100,000 customer records, showing how missing access controls turn convenient backends into open data stores.

Check
Audit Supabase projects for tables readable without authentication, enable row-level security and proper policies, and rotate any exposed tokens or passwords.
Affected
Supabase projects deployed without row-level security or access policies expose their tables, leaking PII, credentials, and auth tokens to anyone who queries them.
Fix
Turn on row-level security, restrict anonymous access, review AI-generated backends for missing controls, and monitor for unauthorized table reads.

Bitget says attacker used third party security product flaw to steal 388 million dollars

Cryptocurrency exchange Bitget said the attacker who stole about 388 million dollars gained access through a vulnerability in a third-party security product the exchange used. The attacker exploited the flaw to obtain high-level internal credentials, then on September 24 used them to reach an internal management system and insert fraudulent withdrawal commands into wallet backend services, where they were treated as legitimate. The stolen funds came from Bitget's hot and warm wallets, while its offline cold wallets were unaffected. CEO Gracy Chen described the incident publicly, confirming the earlier statement that a critical wallet backend system had been compromised and used to spoof transaction data and trigger approvals.

Check
Review third-party security products in privileged positions for patch status and blast radius, and treat their credentials as high-value targets requiring isolation.
Affected
Organizations relying on a vulnerable third-party security product can have its high-level credentials stolen and abused to command core backend systems.
Fix
Inventory and patch third-party security tooling, scope its access tightly, add out-of-band approval for high-value transfers, and monitor for anomalous internal commands.

CenterPoint Energy breach traced to an external API with no authentication

Texas utility CenterPoint Energy confirmed that an unauthorized party obtained customer personal information through an external-facing system. A threat actor claimed on a cybercrime forum to have pulled about 7.49 million records, including names, addresses, account and billing details, and partial Social Security numbers, through a company API that lacked authentication, rate limiting, and web-application-firewall protection. CenterPoint confirmed the incident in a regulatory filing but not the record count, and said energy services were unaffected. It is a textbook example of an exposed API being scraped at scale: without authentication and throttling, a public endpoint hands attackers a bulk export of customer data. The investigation is ongoing.

Check
Inventory external-facing APIs and confirm each one enforces authentication, authorization, rate limiting, and monitoring, and test them for endpoints that return customer data to unauthenticated callers.
Affected
About 7.49 million CenterPoint customers, per the attacker's claim, whose personal, account, and partial Social Security data may have been scraped; unauthenticated, unthrottled external APIs let attackers bulk-export such data with ease.
Fix
Require authentication and rate limiting on every external API, put them behind a web application firewall, monitor for bulk or anomalous access, and treat customer-data endpoints as high-value assets to test.

Revolut handed customer passports and crypto histories to a fake government email

Fintech Revolut disclosed that it released sensitive customer data to attackers who sent a fraudulent information request from an email account operating inside a real government agency's domain. Because the message passed standard email-authentication checks, Revolut treated it as a genuine legal or government request and complied. The exposed data for a limited number of users included passport or driver's license copies, verification selfies, full identity and contact details, and complete transaction histories including Bitcoin activity. It was not a breach of Revolut's systems but an abuse of the trusted legal-request process. The combined identity and financial data enables convincing impersonation, SIM-swapping, and targeted attacks on cryptocurrency holders.

Check
Organizations that fulfill legal or government data requests should verify them out of band through a known contact, not just by trusting domain authentication, since a spoofed mailbox can pass those checks.
Affected
A limited number of Revolut customers whose passports, selfies, identity details, and Bitcoin transaction histories were exposed; the combined data supports impersonation, SIM-swapping, and fraud, and identity documents cannot be reissued.
Fix
Build out-of-band verification into legal and law-enforcement data-request handling, limit what any single request returns, log and review disclosures, and warn affected customers about impersonation and crypto-targeted scams.

Identity firm IDScan breach exposes scans of 153 million driver's licenses

Identity-verification company IDScan confirmed that attackers accessed customer data in its cloud, behind a dark-web marketplace offering scans of more than 153 million US and Canadian driver's licenses, plus names and government-ID numbers. IDScan authenticates government IDs for businesses ranging from banks to car-rental agencies to cannabis and gun retailers, which makes it an aggregator of everyone's identity documents and a single point of mass failure. Investigative journalist Brian Krebs traced the marketplace back to IDScan by matching document scans to occasions when IDs were presented. The FBI is investigating and lawsuits have been filed. Because these are scanned government IDs, victims cannot simply rotate a leaked driver's license.

Check
People who presented IDs to businesses using IDScan should watch for identity and document fraud and use any offered monitoring, and organizations should reassess how much identity-document data their verification vendors retain.
Affected
Roughly 153 million people whose driver's license scans, names, and government-ID numbers were exposed through IDScan; scanned identity documents enable durable document fraud a victim cannot undo by changing a password.
Fix
For organizations, minimize retained identity-document images, encrypt and tightly access-control them, vet identity-verification vendors as high-value aggregators, and prefer verification methods that avoid storing reusable copies of government IDs.

Surfshark VPN says a misconfigured test server let attackers reach build credentials

VPN provider Surfshark disclosed that attackers accessed an internal engineering test server that a configuration error had left reachable from the internet, along with a proxy server used for content optimization. Surfshark says the exposure was limited to a non-production environment and included service configurations, build-related credentials, system binaries, and portions of code history, but did not reach customer data, VPN traffic, encryption keys, or production systems. The company detected the activity on August 31, contained it by September 2, rotated credentials, revoked tokens, and completed remediation within days. It is a reminder that misconfigured internet-exposed test environments remain a common and avoidable breach path, even at security-focused companies.

Check
Inventory internet-facing assets for exposed test, staging, and engineering servers, remove public access to non-production systems, and rotate any build credentials or tokens that a test environment could expose.
Affected
Organizations with internal test or engineering servers unintentionally reachable from the internet; attackers can obtain build credentials, configurations, and source history, which can seed further compromise even when production data is untouched.
Fix
Keep non-production environments off the public internet, apply production-level access controls to test systems, store credentials in dedicated vaults rather than build environments, continuously scan your external attack surface, and rotate secrets.

AdaptHealth breach tied to ShinyHunters exposes health data of 4.1 million

AdaptHealth, a US network of more than 680 medical-equipment facilities, confirmed that a breach attributed to the ShinyHunters group exposed the personal, health, and insurance information of about 4.1 million people. The attackers got in by socially engineering a third-party contractor's privileged account, then reached AdaptHealth's cloud business applications, patient-management systems, and electronic health record portals, and stole a password file tied to insurance billing. It fits ShinyHunters' pattern of tricking a person into handing over access to connected cloud services, and it is the latest in a wave of large healthcare breaches this year alongside Aesto, CareCloud, and McKesson. Social security and financial data were reportedly not taken.

Check
Affected patients should watch for medical, insurance, and identity fraud and use the offered monitoring, and healthcare organizations should tighten third-party and contractor account access against social engineering.
Affected
About 4.1 million people whose names, contact details, and health and insurance information were exposed; the data supports targeted phishing and insurance fraud, and the contractor-account entry shows the third-party path.
Fix
Require phishing-resistant authentication and least privilege for contractors and third parties, monitor connected cloud apps for anomalous access, verify help-desk and account changes, and treat contractor accounts as a primary attack surface.

ShinyHunters claims theft of Florida driver records through a password-reset flaw

The extortion group ShinyHunters claims it breached Florida's DAVID system, an internal driver and vehicle database used by law enforcement and state officials, and stole more than 200,000 records. According to the group, a password-reset flaw let it take over several internal accounts, including those of motor-vehicle employees and, notably, an FBI agent, which it then used to pull driver files, photos, and signatures by cycling through record IDs. It posted a sample it says is a public figure's license as proof and set a leak deadline. Florida's agency has not confirmed the breach, and the claim is unverified, but the group is reportedly probing other states' motor-vehicle systems the same way.

Check
Organizations with self-service password-reset flows should test them for account-takeover flaws, and agencies operating sensitive lookup systems should monitor for accounts enumerating records by ID and for logins from unexpected sources.
Affected
Government and law-enforcement lookup systems reachable with staff accounts; a password-reset weakness let attackers hijack employee and agent logins and mass-download driver records, exposing highly sensitive identity and vehicle data for extortion.
Fix
Harden password-reset and authentication flows, require phishing-resistant authentication for privileged lookup systems, alert on bulk record access and ID enumeration, limit how much any single account can pull, and verify breach claims.

Exposed airline passenger database leaked 220 million records with passport data

Researchers found an exposed database holding more than 220 million airline passenger and crew records, including passport numbers and full flight itineraries, left reachable online. The data came from an Advance Passenger Information System, the kind airlines use to send traveler identity and passport details to border authorities, and it covered anyone who flew to, from, or through Vietnam between 2017 and 2026. Exposed fields included names, dates of birth, nationalities, passport numbers with issuing countries, and flight, seat, and baggage details. Researchers reached it by chaining misconfigurations and default credentials, and it was later secured, though whether the data was copied first is unknown because no access logs existed.

Check
Travelers who flew through the region should watch for identity theft and travel-themed phishing using real passport or itinerary details, and organizations holding traveler data should audit exposed databases and default credentials.
Affected
More than 220 million passenger and crew records with passport numbers, birth dates, nationalities, and flight itineraries were exposed; the data enables identity theft, document fraud, targeted phishing, and surveillance of travelers.
Fix
For organizations, inventory internet-facing databases, remove default credentials, require authentication and encryption on data stores, and enable access logging; aggregators of passport and travel data should treat exposure as high-impact risk.

Thomson Reuters court software breach exposed personal and sealed case records

Thomson Reuters disclosed that attackers obtained files from C-Track, a court case-management platform sold by its West Publishing unit, affecting courts across eleven US states, the US Virgin Islands, and Ontario, Canada. The intrusion happened in March and was not discovered until the end of June. Exposed records may include names, Social Security numbers, driver's license numbers, dates of birth, and medical and insurance information, and at some courts confidential, redacted, or sealed court information may also have been taken. The stolen data came from database backups that courts had supplied to the vendor for troubleshooting. How the attackers got in, and why they went unnoticed for months, remains unanswered.

Check
People in affected court cases should watch for identity theft and use the offered credit monitoring, and organizations should limit the sensitive and backup data they hand to software vendors for support.
Affected
Individuals whose details appear in affected court records, including some sealed cases; exposed names, Social Security numbers, and health data enable identity theft and fraud, with added risk from sealed-case exposure.
Fix
Affected people should monitor credit and court accounts; organizations should minimize data shared with vendors, avoid supplying sensitive backups for troubleshooting, encrypt vendor-held data, and hold third parties to strong security terms.