Follow the latest coverage, related explainers and connected technology stories.
Researchers at UpGuard found that more than 16,000 databases associated with Supabase allowed access to readable tables, containing personal data in more than half of cases, with passwords and authentication tokens present in a smaller group. The flaw is linked to incorrect security settings, including row-level security policies and improperly used public keys.
The EnterpriseDB and ControlPlane teams present a practical recipe for running OpenBao on Kubernetes with a PostgreSQL cluster managed by CloudNativePG, using synchronous replication and TLS certificates instead of passwords. The recipe also explains the design's limitations, particularly the need to restart OpenBao after certificate renewal and the backup and recovery requirements if the cluster is lost.