decrypted · 29 september 2026 · vulnerabilities and patching · uk policy and law · ai and llm security

Supabase's secure default skips the way most apps are built now

Sixteen thousand, three hundred and twenty six leaking databases sounds like a story about careless developers. It is really a story about a lock that only fits one door. Researchers at UpGuard scanned roughly 300,000 domains built on Supabase, the database platform behind a large share of today's AI-assisted app building, and found that many of the exposed tables were leaking real personal data: names, tokens, and in a Canadian immigration service's case, 884 plaintext passwords. The telling detail is not that developers made mistakes. It is that Supabase's own security default only switches on if you build a table one particular way, and the way most people now build tables is the other one.

The lock that only fits one door

Supabase's access control works through Row Level Security, or RLS: a policy layer that decides which rows a given key is allowed to see. Since 2025, Supabase has switched RLS on by default for any table created through its Table Editor, the point-and-click web console. But tables created programmatically, through the API, do not get RLS switched on by default. That second route is exactly how AI coding agents such as Lovable, Replit and Bolt build an app's database when someone types "build me a booking system" into a chat window. The agent calls the API, the table appears, and the safety switch that would exist if a human had clicked through the console is simply absent. Add in the habit of pasting a "public" anonymous key into client-side code as though it were a secret one, and any table without RLS is readable by anyone who finds that key sitting in the page source, which is most of them.

Whose default is it, anyway

Vendors are right to say a default cannot cover every configuration choice a developer might make. But this default fails on the single most common path in 2026: code that a person never directly wrote. UpGuard's own framing is the sharpest part of its report, arguing it is "time to rebalance the equation" the way Amazon did with S3, which flipped to private-by-default buckets after a decade of leaks, and the way GitHub did with new repositories. A secure default that quietly exempts the fastest-growing way of using a product is not a default, it is a footnote.

What UK organisations should take from this

Plenty of UK fintechs, agencies and startups are prototyping on Supabase, often through exactly the AI tooling this report describes, and moving those prototypes into production faster than anyone reviews them. A misconfigured database holding customer PII is a personal data breach under UK GDPR whether it was built by a contractor or a chatbot; "the AI did it" is not a defence the ICO has ever accepted, and there is no reason to expect it to start. The practical fix costs little: before anything built this way goes live, someone should run Supabase's own security advisor, confirm RLS is enabled on every table, and treat an anonymous key found in client-side code as a red flag rather than normal practice. Secure by Design was written for humans writing code by hand. It has to survive the case where nobody did.

Also this week

Citrix's NetScaler zero-days now have a patch, and a federal deadline. Since we covered CVE-2026-88771 and CVE-2026-88772 on Sunday, Citrix has shipped fixed builds (14.1-73.37 and 13.1-64.23 or later), and CISA has added both to its Known Exploited Vulnerabilities catalogue, ordering US federal agencies to patch by 30 September. Citrix itself has warned that applying the update can destroy forensic evidence of an earlier compromise, so anyone who left this unpatched should look for signs of intrusion first, not instead of, updating.

Bitget's $388 million theft ran through a security vendor's own zero-day. The exchange says an attacker exploited an unpatched flaw in a third-party security product to obtain high-level internal credentials, then inserted fraudulent withdrawal commands that its own approval system treated as legitimate. Bitget suspects North Korean actors, and blockchain analytics firm TRM Labs has found wallet overlaps with the group behind previous exchange thefts. The lesson for any UK firm leaning on a single vendor's tooling to gatekeep privileged access: that tooling is now part of your attack surface, not a control outside it.

TikTok has dropped its appeal against the ICO's £12.7 million children's privacy fine. The 2023 penalty covered TikTok's failure to keep an estimated 1.75 million UK under-13s off the platform and to obtain parental consent. TikTok also withdrew a separate challenge to an information notice, letting the ICO resume a 2025 investigation into how TikTok's recommender systems handle teenagers' data. The withdrawal follows an Upper Tribunal ruling that rejected TikTok's argument that its data processing counted as artistic expression.

Sources

If you'd like a second pair of eyes on how your own AI-built infrastructure is configured, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.