• Home
  • Privacy Policy
  • Terms and Conditions
  • DMCA
  • Disclaimer
  • Contact us
Monday, June 23, 2025
No Result
View All Result
NEWSLETTER defal
Lebanon Hub
NEWSLETTER
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up
No Result
View All Result
Lebanon Hub
No Result
View All Result

Microsoft Power Pages Misconfiguration Leads to Data Exposure

November 15, 2024
in Cyber Security
0
Home Cyber Security
0
VIEWS
Share on FacebookShare on Twitter


Misconfigurations inside Microsoft Energy Pages, a low-code SaaS net platform, are resulting in vital knowledge publicity.

In accordance with a brand new weblog put up by AppOmni, by granting extreme entry permissions, organizations threat exposing delicate knowledge, together with personally identifiable data (PII), to unauthorized customers.

Microsoft Energy Pages is designed to simplify web site creation and knowledge integration for companies. But, mismanagement of its safety controls has left thousands and thousands of information, reminiscent of worker data and inner recordsdata, accessible to the general public web.

Key Misconfigurations in Microsoft Energy Pages

Energy Pages makes use of a role-based entry management (RBAC) mannequin to handle person entry ranges. Nevertheless, assigning too many permissions to roles like “Nameless Customers” (unauthenticated guests) and “Authenticated Customers” (logged-in guests) can expose organizations to unintended knowledge leaks.

Since some companies enable public registration, even informal customers can entry these expanded permissions. In a single occasion, AppOmni mentioned, a service supplier for the NHS inadvertently uncovered over 1.1 million NHS staff’ knowledge, together with residence addresses, telephone numbers and e-mail addresses.

Key threat components embrace:

  • Misconfigured desk permissions that grant unrestricted entry to exterior customers

  • The usage of open registration, which can inadvertently grant customers with internal-level permissions

  • Failure to allow column-level safety, permitting delicate data to be seen to unauthorized customers

  • Lack of masking for delicate knowledge, which may in any other case obscure PII for exterior customers

“These exposures are vital – Microsoft Energy Pages is utilized by over 250 million customers each month, in addition to industry-leading organizations and authorities entities, spanning monetary companies, healthcare, automotive and extra,” defined Aaron Costello, chief of SaaS safety analysis at AppOmni.

“Our discovery highlights the numerous dangers posed by misconfigured entry controls in SaaS functions: Delicate data, together with private particulars, has been uncovered right here.”

Learn extra on knowledge safety dangers related to low-code platforms: Researchers Uncover Reply URL Takeover Problem in Azure

Greatest Practices for Securing Energy Pages Deployments

“It’s clear that organizations must prioritize safety when managing external-facing web sites, and stability ease of use with safety in SaaS platforms,” Costello added. “These are the functions holding the majority of confidential company knowledge at the moment, and attackers are focusing on them as a means into enterprise networks.”

Companies utilizing Energy Pages are suggested to evaluate their website, desk and column permissions completely. A layered strategy is important, beginning with site-level settings, then addressing desk permissions and eventually verifying column permissions for delicate fields.

Through the use of Energy Pages’ column safety and masking choices, organizations can restrict publicity and defend delicate knowledge from unauthorized entry. Moreover, Energy Pages contains backend warnings about potential dangers when setting permissions. Directors ought to heed these alerts and regulate settings to make sure delicate data stays safe.

Picture credit score: T. Schneider / Shutterstock.com



Source link

Next Post

NYT Mini Crossword today: puzzle answers for Friday, November 15

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Beirut, LB
14°
Cloudy / Wind
05:4017:50 EET
Feels like: 13°C
Wind: 34km/h SW
Humidity: 65%
Pressure: 1012.19mbar
UV index: 0
FriSatSun
14°C / 9°C
16°C / 11°C
18°C / 12°C
powered by Weather Atlas

Recent News

Grab Space Marine 2 and other Focus Entertainment games at up to 90% off

Grab Space Marine 2 and other Focus Entertainment games at up to 90% off

June 23, 2025
Neverwinter Nights 2’s new Switch 2 remaster is great for Baldur’s Gate 3 fans

Neverwinter Nights 2’s new Switch 2 remaster is great for Baldur’s Gate 3 fans

June 23, 2025
Minjee Lee wins Women’s PGA Championship, her third career golf major

Minjee Lee wins Women’s PGA Championship, her third career golf major

June 23, 2025
Germany and France win quarter-final epics

Germany and France win quarter-final epics

June 23, 2025
This major Kali Linux update could change how ethical hackers break into networks -new tools, VPN IP visibility, and more!

This major Kali Linux update could change how ethical hackers break into networks -new tools, VPN IP visibility, and more!

June 23, 2025
Should Bravo Finally Cut Jax Taylor from “The Valley?”

Should Bravo Finally Cut Jax Taylor from “The Valley?”

June 23, 2025
The 63 Best Shows on Amazon Prime Video Right Now

The 63 Best Shows on Amazon Prime Video Right Now

June 23, 2025
AC/DC Announces Homecoming Shows

AC/DC Announces Homecoming Shows

June 22, 2025
Lebanon Hub

Get the Latest Lebanon News and world News on LebanonHub.com. Local News, Sports, Technology, Music, Celebrity, Gaming News and Cryptocurrency Updates.

Category

  • Altcoin
  • Australia
  • Bitcoin
  • Blockchain
  • Celebrity
  • Cyber Security
  • Ethereum
  • Exchange
  • Litecoin
  • Local News
  • Mobile
  • Movies
  • Music
  • New Released
  • PC
  • PlayStation
  • Popular
  • Reviews
  • Sports
  • Startups
  • Technology
  • TV
  • XBOX

Recent News

Grab Space Marine 2 and other Focus Entertainment games at up to 90% off

Grab Space Marine 2 and other Focus Entertainment games at up to 90% off

June 23, 2025
Neverwinter Nights 2’s new Switch 2 remaster is great for Baldur’s Gate 3 fans

Neverwinter Nights 2’s new Switch 2 remaster is great for Baldur’s Gate 3 fans

June 23, 2025
  • Home
  • DMCA
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact us

Copyright © 2022 - Lebanon Hub.

No Result
View All Result
  • Home – Lebanon hub
    • About us
    • Radio & Live Hosting
      • Home
      • Podcast
      • About us
      • Contact us
  • Blog
    • Submit Blog
  • News
    • International
      • Lebanon
      • Australia
      • Sports
      • Tech
      • Cyber Security
      • Music
      • Celebrity
      • TV
      • Movies
    • Gaming
      • Reviews
      • XBOX
      • PlayStation
      • PC
      • Mobile
      • New Released
      • Popular
    • Cryptocurrency
      • Blockchain
      • Bitcoin
      • Altcoin
      • Exchange
      • Startups
      • Ethereum
      • Litecoin
  • Business
    • Business Dashboard
    • Add New Business
  • Events
    • Event Dashboard
  • Apply Job
    • All Jobs
    • All Resumes
  • Contact us
  • Sign in
  • Sign up

Copyright © 2022 - Lebanon Hub.