UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens, with a very small subset appearing to include credit card data. Supabase is an open-source PostgreSQL development platform, popular with developers using AI tools, which now account for more than 60 percent of newly created databases. UpGuard analyzed about 300,000 domains showing Supabase use and inferred exposed data types from table schemas. More than half of the exposed databases held PII, with a smaller subset exposing passwords and tokens. One US valet service alone exposed over 100,000 customer records, showing how missing access controls turn convenient backends into open data stores.
VPN provider Surfshark disclosed that attackers accessed an internal engineering test server that a configuration error had left reachable from the internet, along with a proxy server used for content optimization. Surfshark says the exposure was limited to a non-production environment and included service configurations, build-related credentials, system binaries, and portions of code history, but did not reach customer data, VPN traffic, encryption keys, or production systems. The company detected the activity on August 31, contained it by September 2, rotated credentials, revoked tokens, and completed remediation within days. It is a reminder that misconfigured internet-exposed test environments remain a common and avoidable breach path, even at security-focused companies.
Researchers found that an official Vatican prayer app exposed the personal information of more than 700,000 users worldwide through an insecure configuration. The exposed data included details that can identify individuals and tie them to their use of the app. Faith and health apps are sensitive because the mere fact of using them can be revealing, and religious affiliation is a protected category in many jurisdictions, so even a modest data set carries outsized risk for the people in it. The exposure stemmed from the way the app's backend was set up rather than a sophisticated intrusion, a recurring pattern in mobile app data leaks where access controls are misconfigured.
Pitney Bowes customer and employee data was leaked publicly after the company refused to pay ShinyHunters' extortion demand. Have I Been Pwned added the breach yesterday with 8.2 million unique email addresses, plus names, phone numbers, and physical addresses. A subset includes Pitney Bowes employee records with job titles - a useful starter pack for highly-targeted phishing against named staff. The data came from a misconfigured Salesforce Experience Cloud 'Guest User' permission that let unauthenticated visitors query CRM records directly. ShinyHunters had posted Pitney Bowes on its leak site April 18 with a three-day deadline.