16,000 Supabase Databases Left Wide Open: The Config Mistake That Exposed PII
7 min read · 10 sources
- UpGuard found over 16,000 misconfigured Supabase databases exposing PII, passwords, and auth tokens.
- Microsoft paused KB5002907 after it deactivated perpetual Office 2016 and 2019 licenses on some devices.
- Cloudflare fixed a cross-tenant container flaw that let Workers Paid users recover residual data from 18 of 24 storage placements.
- Anthropic launched Claude Marketplace with over 2,000 plugins and connectors from major vendors.
- Google Meet's new "Take notes for me" admin and end-user settings take effect September 29th.
Sixteen thousand databases. That is the number of misconfigured Supabase instances that UpGuard found sitting on the public internet with readable tables, and more than half of them look like they can hand over personal information. A US valet service exposed 100,000 customer records. A Canadian immigration service left 884 plaintext passwords lying around. An India-based adult platform leaked 100,000 private messages. This is not a platform vulnerability – it is a configuration failure at scale, and it is the story you need to act on today.
The rest of the day is a mix of Microsoft breaking Office licenses, Anthropic turning Claude into an app store, and Cloudflare quietly fixing a cross-tenant leak that should make any Workers customer think twice. None of it requires a heroics-level response, but all of it changes what you should be checking in your own estate.
UpGuard found over 16,000 misconfigured Supabase databases exposing readable tables with PII, passwords, or auth tokens.
16,000 Supabase databases are leaking PII, passwords, and auth tokens
Source: bleepingcomputer.com ↗
UpGuard identified over 16,000 Supabase databases exposing readable tables. Schema analysis showed more than half could expose personal information, with smaller subsets potentially leaking passwords or authentication tokens. The root cause is missing or ineffective row-level security (RLS) policies and misuse of public keys – not a newly discovered flaw in Supabase itself.
The concrete damage is already visible. A US valet service exposed 100,000 customer records. A Canadian immigration service had 884 plaintext passwords. An India-based adult platform leaked 100,000 private messages. If you run Supabase, this is a direct call to audit your RLS configuration: check every table, verify that RLS is actually enabled (it is off by default), and test with an unauthenticated role. The platform is fine; your policies are the attack surface.
Microsoft pauses KB5002907 after Office license deactivations
Source: bleepingcomputer.com ↗
Microsoft has paused the KB5002907 optional update after reports that it deactivated or, in rare cases, removed perpetual Office 2016 and Office 2019 installations. The update was meant for Microsoft 365 Apps installations over 90 days out of date, but some devices installed it automatically despite it being optional.
Recovery is mostly straightforward: re-entering the original product key restores activation. The nasty edge case is mixed 32-bit and 64-bit Office components, where the reinstall can fail entirely, leaving devices with no Office at all. Support teams should check update history before treating unexpected licensing tickets as subscription or account problems. And if you manage updates via Group Policy or Cloud Update, KB5002907 makes no changes – so verify your update channel before blaming this one.
The 82% of IT managers who were never trained to manage
IT managers fail to exceed expectations largely because they were never trained to manage. A study cited in the piece found 82% of managers rose to their positions without formal management training. The skills that matter are critical thinking, business acumen, innovation, collaboration, and leadership – not the technical depth that got them promoted.
For engineers, this explains a lot of friction: poor vision-selling, weak partnerships with the business, and mediocre execution all trace back to a promotion system that rewards technical output over people management. The operational takeaway for CIOs is to define what managers actually own, coach them on business outcomes, and create advancement paths for specialists who should remain individual contributors. Promoting your best engineer into management without training is how you lose both a good engineer and gain a mediocre manager.
Atlassian's CEO on the SaaSpocalypse that wasn't
Atlassian CEO Mike Cannon-Brookes pushed back on the idea that AI will destroy SaaS businesses in a Decoder interview. His argument: AI is actually increasing usage of Jira and Trello, and chatbots are not the future of work. Structured systems and human judgment still matter.
He also addressed Atlassian’s layoffs, saying the company needs a different mix of skills as AI changes how software companies operate. For IT leaders, the interesting question is who owns the combined work of employee enablement, system integration, and AI cost management. Treating each as a separate rollout misses the point – adoption and business systems are tightly connected, which is why Atlassian combined internal IT and AI enablement under its people leadership.
Anthropic turns Claude into an AI marketplace with 2,000+ plugins
Source: bleepingcomputer.com ↗
Anthropic launched Claude Marketplace, bringing together more than 2,000 plugins and connectors from Atlassian, Google, Microsoft, Notion, and Salesforce. Developers can build connectors using Model Context Protocol (MCP) and Agent Skills, and companies selling Claude-powered software can apply for listing. Consulting partners like Accenture and Deloitte are in too.
This is effectively a Play Store for AI tools, and it creates a new procurement channel you need to manage. Eligible partner software is purchasable using a portion of committed Anthropic spending. For internal AI platform teams, the significant change is the growing catalog of connections between assistants and business systems. Marketplace availability should not replace reviewing permissions, data access, integration ownership, and how access gets removed when someone leaves.
Workday Total Benefits bundles health, wealth, and wellbeing
Source: newsroom.workday.com ↗
Workday launched Workday Total Benefits, an AI solution combining benefits-provider integrations, administration services, and employee guidance in one offering. Workday Wellness is available to US customers now, while benefits guidance through its Self-Service Agent hits general availability in October. It includes Life and Money Solutions for personal financial needs and Benefits Administration Services for hands-on HR support.
The timing is no accident: employers expect a median 9% rise in health care costs in 2026. Evaluation should cover provider compatibility, sensitive employee-data sharing, and whether the new workflows can replace existing portals and manual administration rather than adding another layer. AI-driven automation of benefits administration is the pitch; whether it actually reduces your HR workload depends on your provider stack.
Suspend BitLocker, don't disable it
Disabling BitLocker in Windows 11 permanently decrypts the drive, which is time-consuming and usually the wrong response for short-term tasks. Suspending BitLocker is better for BIOS or firmware maintenance and upgrade troubleshooting – it temporarily exposes the encryption key without decrypting the volume.
Permanent removal is only recommended for device repurposing or disposal. The operational takeaway: make resuming and verifying protection part of the endpoint maintenance runbook, not optional cleanup after the support ticket closes. Forgetting to re-enable BitLocker after a suspension leaves data exposed indefinitely, and the whole point of the exercise was to avoid that.
Pay-as-you-go OneDrive storage at $0.20/GB/month
Microsoft added pay-as-you-go pricing for OneDrive storage, letting Microsoft 365 business customers pay for extra capacity as consumed rather than buying packs upfront. The option is in public preview now with general availability in November, costs $0.20/GB/month, and is off by default. The 25TB per-user limit remains.
Admins can set budget limits and alerts via the admin center, and choose which users are eligible. This follows a similar move for SharePoint. Enterprise SaaS is shifting toward usage-based pricing, giving IT more flexibility but making cost monitoring part of day-to-day platform management. If you have users who occasionally spike past their licensed storage, this beats buying a permanent pack they will never fill.
Google Meet's note-taking defaults land today
Source: workspaceupdates.googleblog.com ↗
Google Meet’s new “Take notes for me” settings take effect September 29th. Admins can now enable automatic note-taking for all meetings, none, or only meetings with three or more people. It is ON by default for Business Standard and Plus, OFF for Enterprise Standard, Enterprise Plus, and Frontline Plus. End users can also enable note-taking for meetings with 3+ participants.
If you are an admin, review the admin console settings before the rollout hits your tenant. The default for your plan may not be what you want, and the settings are now live. This is a five-minute check that saves you from a meeting-notes surprise later.
Cloudflare fixes a cross-tenant flaw in Containers
Source: bleepingcomputer.com ↗
Cloudflare fixed a cross-tenant vulnerability in Containers and Sandboxes that allowed Workers Paid customers to recover residual data from other customers’ containers. The flaw was in a shared storage pool that skipped zeroing reused 64 KiB blocks, letting attackers read files like SQLite databases and .env files.
Researchers found residual material on 18 of 24 container placements, though no real customer data was exposed in testing. Cloudflare completed remediation by September 19, found no evidence of malicious exploitation in available telemetry, and requires no customer-side action. Exploitation required a Workers Paid account, which narrows the attacker pool, but this is a tenant-isolation boundary issue – the kind of flaw that should not exist. If you run sensitive workloads on Cloudflare Containers, it is worth noting that the fix is done, and there is nothing for you to patch.
You May Also Like
Anthropic Picks Accenture to Police Its Own AI Slowdown, Codex Sandbox Falls, and Cloudflare Cuts 100TB
Anthropic named Accenture's Faculty unit as its first embedded evaluator for CEO Dario Amodei's three-step AI slowdown proposal, with both firms investing at …
Huawei's Ascend 960DT jumps to Q1 2027, and OpenAI's models got caught hiding misbehavior
Huawei pulled its Ascend 960DT AI chip launch forward to Q1 2027, though analyst questions about a smaller-than-expected SuperPoD scale suggest architectural …
Anthropic Researcher Puts AI Extinction Odds at >10% - and Nobody Has a Plan
Anthropic's Alignment Science Lead Evan Hubinger says he personally believes there is a greater than 10% chance AI kills all humans within a decade, and admits …




