decrypted · 29 september 2026 · vulnerabilities and patching · uk policy and law · ai and llm security
Supabase's secure default skips the way most apps are built now
Sixteen thousand, three hundred and twenty six leaking databases sounds like a story about careless developers. It is really a story about a lock that only fits one door. Researchers at UpGuard scanned roughly 300,000 domains built on Supabase, the database platform behind a large share of today's AI-assisted app building, and found that many of the exposed tables were leaking real personal data: names, tokens, and in a Canadian immigration service's case, 884 plaintext passwords. The telling detail is not that developers made mistakes. It is that Supabase's own security default only switches on if you build a table one particular way, and the way most people now build tables is the other one.
The lock that only fits one door
Supabase's access control works through Row Level Security, or RLS: a policy layer that decides which rows a given key is allowed to see. Since 2025, Supabase has switched RLS on by default for any table created through its Table Editor, the point-and-click web console. But tables created programmatically, through the API, do not get RLS switched on by default. That second route is exactly how AI coding agents such as Lovable, Replit and Bolt build an app's database when someone types "build me a booking system" into a chat window. The agent calls the API, the table appears, and the safety switch that would exist if a human had clicked through the console is simply absent. Add in the habit of pasting a "public" anonymous key into client-side code as though it were a secret one, and any table without RLS is readable by anyone who finds that key sitting in the page source, which is most of them.
Whose default is it, anyway
Vendors are right to say a default cannot cover every configuration choice a developer might make. But this default fails on the single most common path in 2026: code that a person never directly wrote. UpGuard's own framing is the sharpest part of its report, arguing it is "time to rebalance the equation" the way Amazon did with S3, which flipped to private-by-default buckets after a decade of leaks, and the way GitHub did with new repositories. A secure default that quietly exempts the fastest-growing way of using a product is not a default, it is a footnote.
What UK organisations should take from this
Plenty of UK fintechs, agencies and startups are prototyping on Supabase, often through exactly the AI tooling this report describes, and moving those prototypes into production faster than anyone reviews them. A misconfigured database holding customer PII is a personal data breach under UK GDPR whether it was built by a contractor or a chatbot; "the AI did it" is not a defence the ICO has ever accepted, and there is no reason to expect it to start. The practical fix costs little: before anything built this way goes live, someone should run Supabase's own security advisor, confirm RLS is enabled on every table, and treat an anonymous key found in client-side code as a red flag rather than normal practice. Secure by Design was written for humans writing code by hand. It has to survive the case where nobody did.
Also this week
Citrix's NetScaler zero-days now have a patch, and a federal deadline. Since we covered CVE-2026-88771 and CVE-2026-88772 on Sunday, Citrix has shipped fixed builds (14.1-73.37 and 13.1-64.23 or later), and CISA has added both to its Known Exploited Vulnerabilities catalogue, ordering US federal agencies to patch by 30 September. Citrix itself has warned that applying the update can destroy forensic evidence of an earlier compromise, so anyone who left this unpatched should look for signs of intrusion first, not instead of, updating.
Bitget's $388 million theft ran through a security vendor's own zero-day. The exchange says an attacker exploited an unpatched flaw in a third-party security product to obtain high-level internal credentials, then inserted fraudulent withdrawal commands that its own approval system treated as legitimate. Bitget suspects North Korean actors, and blockchain analytics firm TRM Labs has found wallet overlaps with the group behind previous exchange thefts. The lesson for any UK firm leaning on a single vendor's tooling to gatekeep privileged access: that tooling is now part of your attack surface, not a control outside it.
TikTok has dropped its appeal against the ICO's £12.7 million children's privacy fine. The 2023 penalty covered TikTok's failure to keep an estimated 1.75 million UK under-13s off the platform and to obtain parental consent. TikTok also withdrew a separate challenge to an information notice, letting the ICO resume a 2025 investigation into how TikTok's recommender systems handle teenagers' data. The withdrawal follows an Upper Tribunal ruling that rejected TikTok's argument that its data processing counted as artistic expression.
Sources
- Everything Everywhere: Systemic Data Exposure in Supabase Apps
- Misconfigured Supabase apps expose data in over 16,000 databases
- Critical Zero-Day Vulnerabilities Exploited in Citrix NetScaler ADC and Gateway
- CISA orders feds to patch exploited Citrix flaws by Wednesday
- Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
- TikTok withdraws two appeals in children's privacy action and accepts £12.7m fine
If you'd like a second pair of eyes on how your own AI-built infrastructure is configured, get in touch.
More like this
- Roundcube's four-month-old patch is now a live attack 24 september 2026
- Zyxel switches, a five-week campaign, and the passwords nobody changed 22 september 2026
- Codex's sandbox escapes: the guard was inside the cell 20 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.