Science

#Millions of Microsoft-stored data records mistakenly exposed

#Millions of Microsoft-stored data records mistakenly exposed

The vulnerabilities were detected in a Microsoft product called Power Apps, which allows for the creation of websites and mobile
The vulnerabilities were detected in a Microsoft product called Power Apps, which allows for the creation of websites and mobile apps to interact with the public.

Some 38 million records stored on a Microsoft service, including private information, were mistakenly left exposed this year, security firm UpGuard said Monday.

The data, including names, addresses, financial information and Covid-19 vaccination statuses, was made vulnerable—but not compromised—before the problem was resolved, according to the digital security company’s investigation.

Among the 47 affected organizations were American Airlines, Ford, JB Hunt and public agencies such as the Maryland Department of Health and New York City’s public transit system.

They all used a Microsoft product called Power Apps, which allows for the creation of websites and mobile apps to interact with the public.

The service’s default software configuration setting meant the data of the affected organizations was left without protection up until June 2021, according to UpGuard.

“As a result of this research project, Microsoft has since made changes to Power Apps portals,” the report said.

Microsoft said it had let clients know when potential security risks were uncovered so that they could fix the problems themselves.

“We take security and privacy seriously, and we encourage our customers to use best practices when configuring products in ways that best meet their privacy needs,” a spokesperson said.

But UpGuard said it would have been better to change the way the software works at the source, and based on how customers use it, rather than “to label systemic loss of data confidentiality an end user misconfiguration, allowing the problem to persist.”


Indiana notifying 750K after COVID-19 tracing data accessed


© 2021 AFP

Citation:
Millions of Microsoft-stored data records mistakenly exposed (2021, August 24)
retrieved 25 August 2021
from https://techxplore.com/news/2021-08-millions-microsoft-stored-mistakenly-exposed.html

This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no
part may be reproduced without the written permission. The content is provided for information purposes only.

If you liked the article, do not forget to share it with your friends. Follow us on Google News too, click on the star and choose us from your favorites.

For forums sites go to Forum.BuradaBiliyorum.Com

If you want to read more Like this articles, you can visit our Science category.

Source

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Close

Please allow ads on our site

Please consider supporting us by disabling your ad blocker!