Active data extortion operations targeting low-code web portal infrastructure continue to compromise enterprise data vaults without dropping binary malware. Adversaries systematically scan public web portals to extract millions of sensitive records through exposed database API endpoints.
The campaign, led by extortion cluster ExfilSquad, targets public-facing Microsoft Power Pages portals connected to Microsoft Dynamics 365 environments. Permissive default table permissions allow unauthenticated site visitors to submit structured OData queries against backend database tables, exfiltrating municipal datasets, policyholder records, and corporate user profiles. Because the exfiltration relies entirely on legitimate web requests, standard endpoint detection tools fail to generate initial access alerts.
Exposing public access controls on low-code web portal platforms introduces severe corporate privacy and compliance exposure. When public web portals share direct database queries with core enterprise resource planning platforms, administrative misconfigurations grant external threat actors unmonitored access to sensitive customer databases.
– Conduct immediate access control audits across all public Microsoft Power Pages portals to verify anonymous read permissions on custom tables.
– Enforce strict row-level security parameters and authenticated table permissions across connected Dynamics 365 environments.
– Inspect portal API gateway logs for high-volume OData queries originating from unrecognized public IP address pools.
– Apply web application firewall rate-limiting rules to restrict bulk database extraction queries targeting public web endpoints.
Low-code cloud platform defense depends on continuous permission auditing and strict zero-trust access controls to ensure public web portals do not expose internal enterprise databases. #CodeDefence #Microsoft #PowerPages #Dynamics365 #DataExfiltration #AppSec #CloudSecurity #Extortion
/
