Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Supabase Data Exposure | 16,000+ Open Databases and What Security Teams Can Do

We found more than 16,000 Supabase databases sitting wide open, and over half held personal data like names, phone numbers and passwords. The organizations behind them ranged from a valet service to a government consulate, and in many cases the owners never checked the settings AI wrote. What is the Supabase data exposure? Anyone visiting these sites could read the data in their databases. Many belong to vibe-coded apps, where AI coding tools often handle the database setup.

Risk Acceptance Has a Shelf Life: Notes from the Aviation ISAC Cybersecurity Summit

The first Aviation ISAC summit, a little over a decade ago, was about forty people in a room in Miami, hosted by the Health ISAC. This year’s conference in Vancouver hosted more than five hundred: airlines, airports, OEMs, suppliers, and government, all in one place for three days. Many in the audience were new to the conference. One of the opening speakers asked first-timers to raise their hands, and a lot of hands went up around the room.

Managing Third-Party Cyber Risks in Complex Supply Chains

Big breaches often start somewhere boring. A refrigeration contractor with remote access to the network (Target, 2013). A file-transfer tool nobody on the security team had thought about in years (MOVEit, 2023). A compression library buried four layers deep in a Linux distro. Meanwhile most vendor reviews still run on an Excel questionnaire that gets filled in once, filed and forgotten, and attackers know that perfectly well.

The Interconnected Security Program: Managing Risk Across Cybersecurity Domains

Cybersecurity programs have become increasingly specialized and become a rather expansive enterprise responsibility. Protecting a modern organization can involve identity, endpoints, networks, applications and APIs, cloud infrastructure, data, threat intelligence, detection and response, governance, risk and compliance (GRC), incident response, and cyber resilience. Each discipline brings specialized technologies, processes, and expertise to the security program.

Preparing for an ISO 42001 Audit Rather Than Reading About It

Plenty of material explains what ISO/IEC 42001 contains. Clause by clause, control by control, with a checklist of documents to prepare. The standard itself is a management system specification rather than a control catalogue, and the distinction is where audit preparation goes wrong. ‍ The checklists share one omission.

Calibrating a Cyber Loss Model to One Environment

A model built on industry data produces an industry answer. The obvious next step is to calibrate it to the specific environment, and the obvious place to start is the threat picture, because every organization believes its own is distinctive. ‍ It is the wrong parameter to start with. Some inputs should stay general, some must be local, and the ones that must be local are the harder ones to observe, which is why they get left at a default. ‍

AI Governance Evidence That Costs Nothing to Produce

The usual case for governance return is that it speeds up enterprise sales, because buyers ask security questions and a prepared answer closes faster. It is true and it is the weaker argument. ‍ The stronger one is loss avoidance, and almost nobody makes it, because it needs a loss figure that most governance programs do not have. What makes it affordable is a distinction between two kinds of evidence. ‍

What an AI Correlation Rule Cannot See

A correlation rule can be tuned. The window can be widened, the join key improved, a source promoted from optional to required. Each of those is a parameter with a defensible setting. ‍ What remains after all of it is the residual, meaning the events that would produce a finding if a source existed for them, which is a form of residual risk expressed in detection terms. Naming it is the question an auditor asks after being shown a detection, and the answer is not a tuning exercise. ‍

A One-in-Hundred-Year Cyber Loss Is Not a Schedule

A quantification exercise reports a one-in-hundred-year loss and the figure travels well. It sounds precise, it sounds severe, and everybody in the room believes they understand it. ‍ Most of them do not. The phrasing describes an annual probability and it reads as a statement about timing, and the two produce different decisions from the same number. ‍