FacebookInstagramTwitterContact

 

National Speech Contest           >>           Beta-Alanine Supplementation May Improve Power Output During Leg Exercises           >>           HIDDEN DANGER: Beware Of Arsenic Contamination In Rice           >>           Boysenberries Found To Improve Cholesterol, Help Prevent Heart Disease           >>           Girl Said She Heard ‘Monsters’ In Her Bedroom Wall – It Turned Out To Be Something Much Worse           >>           People Are Going Crazy For This Mayor’s Little Toes           >>           Jersey Shore's Pauly D Shares Rare Update On Life With 10-Year-Old Daughter Amabella           >>           Colleen Hoover's Verity Book Becoming A Movie After It Ends With Us           >>           Asteroid Ryugu Holds Secrets Of Our Solar System's Past, Present And Future           >>           US will require all new cars to have advanced automatic braking systems by 2029           >>          

 

SHARE THIS ARTICLE




REACH US


GENERAL INQUIRY

[email protected]

 

ADVERTISING

[email protected]

 

PRESS RELEASE

[email protected]

 

HOTLINE

+673 222-0178 [Office Hour]

+673 223-6740 [Fax]

 



Upcoming Events





Prayer Times


The prayer times for Brunei-Muara and Temburong districts. For Tutong add 1 minute and for Belait add 3 minutes.


Imsak

: 05:01 AM

Subuh

: 05:11 AM

Syuruk

: 06:29 AM

Doha

: 06:51 AM

Zohor

: 12:32 PM

Asar

: 03:44 PM

Maghrib

: 06:32 PM

Isyak

: 07:42 PM

 



The Business Directory


 

 



Security & Privacy


  Home > Security & Privacy


Data Leak Exposed 38 Million Records, Including COVID-19 Vaccination Statuses


BeeBright via Getty Images

 


 August 24th, 2021  |  16:00 PM  |   667 views

WASHINGTON, UNITED STATES

 

A Microsoft misconfiguration reportedly left data from more than 1,000 web apps in the open.

 

Around 38 million records from north of a thousand web apps that use Microsoft's Power Apps portals platform were left exposed online, according to researchers. The records are said to have included data from COVID-19 contact tracing efforts, vaccine registrations and employee databases, such as home addresses, phone numbers, social security numbers and vaccination status.

 

Data from some large companies and institutions was exposed in the incident, according to Wired, including American Airlines, Ford, the Indiana Department of Health and New York City public schools. The vulnerability has mostly been resolved.

 

Researchers from security company Upguard started looking into the issue in May. They found data from many Power Apps portals that was supposed to be private was available for anyone to access if they knew where to look.

 

The Power Apps service aims to make it easy for customers to make their own web and mobile apps. It offers application programming interfaces (APIs) for developers to use with the data they collect. However, Upguard found that using those APIs makes the data obtained through Power Apps Portals public by default, and manual reconfiguration was required to keep the information private.

 

Upguard says it sent a vulnerability report to the Microsoft Security Resource Center on June 24th, including links to Power Apps portals accounts on which sensitive data was exposed and steps to identify APIs that enabled anonymous access to data. Researchers worked with Microsoft to clarify how to reproduce the issue. However, an Microsoft analyst told the firm on June 29th that the case was closed and they “determined that this behavior is considered to be by design.”

 

Upguard then started notifying some of the affected companies and organizations, which moved to lock down their data. It raised an abuse report with Microsoft on July 15th. By July 19th, the company says that most of the data from the Power Apps portals in question, including the most sensitive information, had been made private.

 

Microsoft provided us with the following statement after this story was first published: "Our products provide customers flexibility and privacy features to design scalable solutions that meet a wide variety of needs. We take security and privacy seriously, and we encourage our customers to use best practices when configuring products in ways that best meet their privacy needs."

 

Earlier this month, Microsoft said Power Apps portals apps will keep data private by default when developers harness the APIs. In addition, it released a tool for developers to check their settings.

 

There's no indication as yet that any of the exposed data has been compromised. Among the most sensitive information that was left in the open were 332,000 email addresses and Microsoft employee IDs that are used for payroll, according to Upguard. The company also says that more than 39,000 records from portals related to Microsoft Mixed Reality were exposed, including users' names and email addresses.

 

The incident underscores the fact that a misconfiguration, no matter how seemingly minor, could lead to serious data breaches. That doesn't appear to be the case here, thankfully. Still, it goes to show that developers should probably triple check their settings, especially when plugging in an API they haven't designed themselves.

 

Update 8/23 3:45PM ET: Added a statement from Microsoft.

 

Update 8/23 4:30PM ET: Clarified that the issue concerned Power Apps portals, and not Power Apps as a whole.

 


 

Source:
courtesy of ENGADGET

by Kris Holt

 

If you have any stories or news that you would like to share with the global online community, please feel free to share it with us by contacting us directly at [email protected]

 

Related News


Lahad Datu Murder: Remand Of 13 Students Extende

 2024-03-30 07:57:54

'Close Enough To See Their Faces': Chased Down By China In South China Sea

 2024-05-02 00:57:36

Tesla Staff Say Firm's Entire Supercharger Team Fired

 2024-05-02 00:12:47