CiberLATAMbywhalemate

Supabase and Cloudflare exposed data due to errors

UpGuard found 16,326 Supabase databases with readable tables exposed online. Cloudflare also fixed a cross-tenant Containers flaw.

Whalemate Labs · AI-assisted researchPublished:2 min read

UpGuard identified 16,326 databases hosted on Supabase with readable tables exposed to the public web. The issue was attributed to a configuration mistake, not a hack of the provider. At the same time, Cloudflare fixed a Containers flaw that could expose data between customers because of shared storage, while Infobae Perú reported a new backdoor in attacks against government entities in the region, with mention of Peru.

UpGuard identified 16,326 databases hosted on Supabase with readable tables exposed to the public web. The investigation described the issue as a configuration error, not a hack of the provider. At the same time, Cloudflare fixed a Containers flaw that could expose data between customers, and in Peru, a new backdoor was reported in attacks against government entities in several countries in the region.

What did UpGuard find in Supabase?

UpGuard found 16,326 databases in Supabase with readable tables exposed to the public web. Coverage of the research said a bad configuration left more than 16,000 databases reachable on the internet, with data such as passwords, phone numbers and addresses exposed.

A technical summary cited by Unite.AI also said that more than half of the exposed databases showed signs of personal information. A smaller share contained passwords or authentication tokens, and a very small number included plausible credit card data. The same material clarified that these were indicators observed by the researcher, not a count of affected users or proof of malicious access.

What problem did Cloudflare fix?

Cloudflare fixed a Containers flaw that could leave residual data from other customers exposed because of shared storage configuration. According to the company’s disclosure, the system was set to skip wiping reused 64 KiB blocks, which could allow cross-tenant exposure.

HawkEye said the scenario required a Workers Paid account and that the exposed information could include file system metadata, directory structures, database pages and entire SQLite databases. Matrice Digitale added that the risk did not allow an attacker to choose a victim directly or read active disks, because it depended on physically reused blocks. The problem was recovering residual data from earlier workloads on the same host.

What was reported in the region?

Infobae Peru reported that a new backdoor was detected in attacks against government entities in several countries in the region, including Peru. The detail was included in local coverage of a cyberattack that could expose military and national security information.

Against that backdrop, the available material points to a run of incidents tied to exposed configurations and isolation flaws in cloud infrastructure, with potential impact for organizations operating in the region and for environments that rely on managed services.

Sources

View all