frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

Open in hackernews

Supabase MCP can leak your entire SQL database

https://simonwillison.net/2025/Jul/6/supabase-mcp-lethal-trifecta/
3•doppp•9h ago

Comments

rvz•8h ago
> Given the enormous risk involved even with a read-only MCP against your database, I would encourage Supabase to be much more explicit in their documentation about the prompt injection / lethal trifecta attacks that could be enabled via their MCP!

What if MCP itself is a completely flawed standard? You can easily manipulate the agent to leak sensitive data with really basic prompt injection attacks.

We already have seen many flaws and attacks on other MCP servers such as one from Heroku's MCP server [0] and one from Anthropic's MCP inspector [1]. This issue from Supabase for poor documentation is no different.

This protocol is quickly becoming one of the most insecure standards I have seen and once again, nobody cares.

(Until we get a totally avoidable data breach via a MCP server left wide open somewhere).

[0] https://news.ycombinator.com/item?id=44434776

[1] https://nvd.nist.gov/vuln/detail/CVE-2025-49596

Is ChatGPT Killing Higher Education?

https://www.vox.com/the-gray-area/418793/chatgpt-claude-ai-higher-education-cheating
1•jruohonen•1m ago•0 comments

The Missing Compass

https://thedesignleader.substack.com/p/day-5-the-missing-compass
1•almost-exactly•4m ago•0 comments

HAProxy and Couchbase Integration

https://medium.com/@mitendra_mahto/haproxy-and-couchbase-integration-5353dcc1bf34
1•miggy•5m ago•0 comments

Wildfires Are Challenging Air Quality Monitoring Infrastructure

https://undark.org/2025/07/04/wildfires-aqi-infrastructure/
1•EA-3167•5m ago•0 comments

Each of These Tires Costs More Than a Brand New Car

https://www.jalopnik.com/1899775/worlds-largest-tire-cost/
1•rntn•7m ago•0 comments

The Jellyfish and the Beginner's Mind

https://thedesignleader.substack.com/p/day-4-the-jellyfish-and-the-beginners
1•almost-exactly•10m ago•0 comments

Show HN: Compears – Compare Grocery prices across Supermarkets

https://www.compears.shop/nl
1•tha_infra_guy•13m ago•0 comments

America Party (AMEP) FEC Form 1

https://docquery.fec.gov/cgi-bin/forms/C00910323/1898441
2•dctoedt•15m ago•1 comments

There's no need to over engineer a URL shortener

https://www.luu.io/posts/2025-over-engineer-url-shortener
1•thunderbong•16m ago•0 comments

Show HN: BrowseAnything – An AI agent that automates any website task

https://www.browseanything.io/
1•bahra_mehdi•17m ago•0 comments

We turned our Hackathon win into a (free) product: AI Yoga Coach

https://pamelai.net/
2•lusxvr•18m ago•0 comments

GPS Week Number Rollover

https://en.wikipedia.org/wiki/GPS_week_number_rollover
3•walterbell•24m ago•0 comments

Tech Nostalgia: Amiga Forever and C64 Forever Turn 11

https://www.thurrott.com/classic-technology/322993/tech-nostalgia-amiga-forever-and-c64-forever-turn-11
3•Bluestein•27m ago•0 comments

React Bits – Animated UI Components for React

https://reactbits.dev
2•EPendragon•30m ago•0 comments

Beyond the Evolution versus Learning Fallacy [pdf]

https://www.laithalshawaf.com/uploads/1/3/5/8/135897893/beyond_the_evolution_vs_learning_fallacy_--_al-shawaf.pdf
2•mpweiher•32m ago•0 comments

Show HN: Simple wrapper for Chrome's built-in local LLM (Gemini Nano)

https://github.com/kstonekuan/simple-chromium-ai
5•kstonekuan•34m ago•0 comments

Lessons from 863 episodes of This American Life

https://indarktrees.com/misc/tal/
3•cryzinger•34m ago•0 comments

Study detects AI fingerprints in scientific papers

https://phys.org/news/2025-07-massive-ai-fingerprints-millions-scientific.html
3•giuliomagnifico•34m ago•0 comments

Unsoundness and accidental features in the [target_feature] attribute

https://predr.ag/blog/unsoundness-and-accidental-features-in-target-feature/
3•brson•35m ago•0 comments

Augmenting Long-Term Memory

https://augmentingcognition.com/ltm.html
2•gneray•35m ago•0 comments

My Two and a Half Years at TikTok E-Commerce in the US: Hope to Disillusion

https://dilemmaworks.substack.com/p/special-submission-my-two-and-a-half
2•dworks•41m ago•0 comments

Fake-will fraudsters steal millions from the dead

https://www.bbc.co.uk/news/articles/cx2390x51zqo
4•sarreph•42m ago•0 comments

Why are there no good dinosaur films?

https://briannazigler.substack.com/p/why-are-there-no-good-dinosaur-films
2•bookofjoe•47m ago•0 comments

Cool People [pdf]

https://www.apa.org/pubs/journals/releases/xge-xge0001799.pdf
2•ilamont•48m ago•1 comments

30 Years of JavaScript: 10 Milestones That Changed the Web

https://thenewstack.io/30-years-of-javascript-10-milestones-that-changed-the-web/
3•maxloh•52m ago•1 comments

What Was the Turbo Button on Old '90s PC for and Why Don't We Have It Anymore?

https://www.slashgear.com/1902184/what-is-turbo-button-old-90s-pc-for/
5•Bluestein•53m ago•0 comments

Conventional Commits makes me sad

https://srazkvt.codeberg.page/posts/2025-07-06-conventional-commits-makes-me-sad.html
3•todsacerdoti•56m ago•0 comments

TikTok building new version of app ahead of expected US sale

https://www.reuters.com/world/china/tiktok-building-new-version-app-ahead-expected-us-sale-information-reports-2025-07-06/
4•thm•57m ago•0 comments

'Shit in, shit out', AI is coming for agriculture, but farmers aren’t convinced

https://theconversation.com/shit-in-shit-out-ai-is-coming-for-agriculture-but-farmers-arent-convinced-259997
4•lr0•59m ago•0 comments

Show HN: Autoresume – OpenSource, Resume Builder and TeX Editor with AI Features

https://github.com/aadya940/autoresume
3•aadyachinubhai•1h ago•0 comments