
Over 16,000 Supabase Databases Exposed Due to Misconfiguration
Security researchers found more than 16,000 misconfigured Supabase databases with publicly readable tables exposing PII, passwords, and tokens.

Security researchers found more than 16,000 misconfigured Supabase databases with publicly readable tables exposing PII, passwords, and tokens.

Microsoft disclosed NeedyMantis malware used in targeted attacks against telecommunications, universities, medical nonprofits, and government contractors.

Bitget disclosed that attackers exploited a third-party security product vulnerability to steal $388 million on September 24. North Korean actors

Stolen infostealer data exposed AI service credentials from over 80,000 corporate domains, enabling account takeover and LLMjacking attacks.

Cameron John Wagenius sentenced to 70 months in prison for hacking 10 U.S. technology and telecommunications companies while on active

Carbonato malware installs Hermes Agent AI framework on exposed Docker daemons, then controls the agent via Telegram with a modified

Washington D.C. Department of Health Care Finance exposed approximately 400,000 Medicaid beneficiary records through a misconfigured web portal accessible without

Bitget cryptocurrency exchange disclosed a $351.6 million theft from hot and warm wallets on September 25, with attribution pointing to

Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in

Cloudflare disclosed a vulnerability allowing customers to read leftover disk data from other customers’ previous containers, violating tenant isolation controls.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.