Three recently patched vulnerabilities in Microsoft Dynamics 365 and Power Apps Web API were found to expose sensitive data, according to Melbourne-based cybersecurity firm Stratus Security. The flaws, fixed as of May 2024, involve weaknesses in the Power Platform’s OData Web API Filter and FetchXML API. The first vulnerability stems from inadequate access controls in the OData Web API Filter, enabling unauthorized access to the contacts table, which stores sensitive data such as names, phone numbers, addresses, financial details, and password hashes. An attacker could exploit this flaw using a boolean-based search to extract password hashes character by character, such as by querying strings like startswith(adx_identity_passwordhash, 'a') and continuing sequentially until the entire hash is revealed. The second flaw involves the misuse of the orderby clause within the same API, allowing attackers to retrieve specific data, such as email addresses, from the contacts table. The third vulnerability is tied to the FetchXML API, which can bypass access controls when combined with an orderby query on any column. Unlike the previous vulnerabilities, this method doesn’t require the query to be in descending order, granting attackers greater flexibility in their exploitation. Exploiting these flaws could allow attackers to compile and sell lists of emails and password hashes or crack the passwords. Stratus Security emphasized the importance of robust cybersecurity for platforms like Microsoft’s, stating, These discoveries highlight the need for constant vigilance, especially for organizations managing vast amounts of sensitive data.
Gyazo, the cloud-based screenshot and screen-recording platform operated by Helpfeel, confirmed a data breach after attackers exploited a server vulnerability on September 11, 2026...
Plugin4Shell is a high-severity supply-chain vulnerability affecting major AI coding agents, including Anthropic Claude Code, OpenAI Codex, GitHub Copilot, and Google Gemini CLI. T...
A newly identified Windows malware framework dubbed MovieReaper is being distributed through compromised torrent infrastructure and fake downloads of popular movies. Security resea...