Plugavel.
  • Home
  • Tech
  • Car
  • More
    • Privacy policy
    • About us
    • Contact us
No Result
View All Result
Plugavel.
  • Home
  • Tech
  • Car
  • More
    • Privacy policy
    • About us
    • Contact us
No Result
View All Result
Plugavel.
No Result
View All Result
ADVERTISEMENT

Misconfigured, a Microsoft software suite made millions of personal data accessible

24 de August de 2021
in Tech
L’absence d’un simple réglage réduisait la sécurité des données à zéro. © pdusit, Adobe Stock
ADVERTISEMENT

Tens of millions of personal, health, or social data exploited by nearly 50 U.S. entities in healthcare, industry, and transportation have been left unprotected. This is due to a default setting in the configuration of service portals created from Microsoft’s Power Apps suite.

You will also be interested


[EN VIDÉO] Cyber ​​espionage: what are the threats?
Interference with elections, theft of industrial data, hacking of military systems… Cyber ​​espionage has been on the rise over the past two decades.

Thirty-eight million pieces of personal data, including names, addresses, tax or Social Security identifiers, for example from the health services of certain American states and linked to the monitoring of Covid-19, American Airlines, the manufacturer Ford, or even the public transport services of New York, found themselves exposed without any security. This is what a report from the computer security specialist indicates UpGuard. Posted Monday, he points to the use of the software suite Power Apps from Microsoft. These are tools for creating dashboards, applications tailor-made online trades, through portal sites and based on user data. In all, 47 more or less important entities were affected by this gaping breach. According to UpGuard, however, the exposed data would not have been compromised.

No password needed to access data

Concretely, there was no need to password to access this personal data hosted in the form of spreadsheets on Microsoft’s Dataverse service servers. The Access API was just not configured by default by Microsoft to prevent data exposure. This had to be done manually. A subtlety that the developers of these entities have probably not considered. Microsoft responded by pushing an update earlier this month. It applies the correct default security settings.

The firm has also published a tool to perform a security audit on portals made with Power Apps. That said, in its explanations, Microsoft seeks to clear itself by returning the responsibility to its customers who did not correctly configure the services, while adding that it took care to inform them when potential risks of leaks were identified. In the end, it is fortunate that this personal data was not collected by malicious people.

Interested in what you just read?

.

ADVERTISEMENT
Tags: accessiblecomputer flawcybersecuritydataMicrosoftMicrosoft Power AppsmillionsMisconfiguredpasswordpersonalpersonal datasecuritysecurity breachsoftwaresuiteUpGuard
ShareTweetPin

Related Posts

Comment connaître son adresse IP publique et privée sous Windows ou macOS ? © evryka, Shutterstock
Tech

Know your public IP address and your private IP address

What is the difference between the private IP address and the public IP address on your broadband box? How to...

28 de May de 2022
Bouygues Telecom baisse ses prix pour la rentrée © Andrea Piacquadio, Pexels
Tech

Bouygues Telecom: the 80 GB mobile plan is displayed at only €11.99

The B&You 80 GB package is on sale until Tuesday, May 31 at 11:59 p.m. Without commitment, the mobile plan...

28 de May de 2022
Le forfait prépayé 80 Go est en promotion chez Lebara - Photo de Reafan Gates provenant de Pexels
Tech

Good plan mobile plan: 80 GB at only €9.99 on the Orange network and not just for the first year

If you are looking for a complete, inexpensive and easy-to-use mobile offer, Lebara's 80 GB plan will interest you. On...

28 de May de 2022
Cdiscount Mobile lance deux super promos forfait mobile Pexels © Pixabay
Tech

The 100 GB package at only €7.99 at Cdiscount Mobile and not just for the first year

Until next Tuesday, May 31, Cdiscount Mobile is offering you two non-binding mobile plans of 100 GB and 150 GB...

28 de May de 2022
Next Post
Seat Ibiza 2021 test: made up, but shy Iberian

Seat Ibiza 2021 test: made up, but shy Iberian

Good deal: 89% off your Photoshop training

Udemy good deal: 80% off your Photoshop training

Recommended

Fuel: discontent rises in Sweden

22 de February de 2022

F1 2022 – Mercedes F1 W13: the live revelation – VIDEO

18 de February de 2022

This motorist wanted to see the sea a little too close…

24 de February de 2022

Mercedes is the most popular brand among singers

22 de February de 2022
ADVERTISEMENT

Categories

  • Car
  • Carros
  • Tech
  • Tecnologia
ADVERTISEMENT
  • Home
  • Privacy policy
  • About us
  • Contact us
© 2021 Plugavel - News about technology and cars on one site Plugavel.
No Result
View All Result
  • Home
  • Tech
  • Car
  • More
    • Privacy policy
    • About us
    • Contact us