Friday, May 29, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | Science & Tech | Default Settings In Microsoft Tool Exposes 38 Million Users Data

Default settings in Microsoft tool exposes 38 million users’ data

According to security research network UpGuard, the types of data included personal information used for Covid-19 contact tracing, vaccination appointments, social security numbers for job applicants, employee IDs

By IANS
Published Date - 25 August 2021, 04:27 PM
Default settings in Microsoft tool exposes 38 million users’ data
whatsapp facebook twitter telegram

New Delhi: A default permissions settings in Microsoft Power Apps might have exposed data of 38 million users online, cyber security researchers reported.

According to security research network UpGuard, the types of data included personal information used for Covid-19 contact tracing, vaccination appointments, social security numbers for job applicants, employee IDs, and millions of names and email addresses.


UpGuard notified 47 entities of exposures involving personal information, including governmental bodies like Indiana, Maryland, and New York City, and private companies like American Airlines, J.B. Hunt, and Microsoft, for a total of 38 million records across all portals.

“The number of accounts exposing sensitive information, however, indicates that the risk of this feature — the likelihood and impact of its misconfiguration — has not been adequately appreciated,” the UpGuard team said in a blog post.

Microsoft Power Apps are a product for making “low code”, cloud-hosted business intelligence apps. Power Apps portals are a way to create a public website to “give both internal and external users secure access to your data.”

Users can create websites in the Power Apps UI with application capabilities like user authentication, forms for users to enter data, data transformation logic, storage of structured data, and APIs to retrieve that data by other applications.

“Our conversations with the entities we notified suggested the same conclusion: multiple governmental bodies reported performing security reviews of their apps without identifying this issue, presumably because it has never been adequately publicised as a data security concern before,” they added.

There is, however, no evidence that the data has been exploited.

On May 24, an UpGuard analyst first discovered that the OData API for a Power Apps portal had anonymously accessible list data including personally identifiable information.

The owner of that application was notified and the data secured.

“That case led to the question of whether there were other portals with the same situation — the combination of configurations allowing lists to be accessed anonymously via OData feed APIs, and sensitive data collected and stored by the apps,” the team noted.

As reported by Wired, Microsoft has now changed the default permissions settings responsible for the exposure.

  • Follow Us :
  • Tags
  • Microsoft

Related News

  • Microsoft cuts Claude Code access as AI coding costs surge

    Microsoft cuts Claude Code access as AI coding costs surge

  • Microsoft veteran and VC leader Soma Somasegar dies, tributes pour in

    Microsoft veteran and VC leader Soma Somasegar dies, tributes pour in

  • Thousands of IT jobs set to disappear as Meta, Microsoft restructure workforce in AI era

    Thousands of IT jobs set to disappear as Meta, Microsoft restructure workforce in AI era

  • Musk seeks up to $134 billion in damages from OpenAI, Microsoft

    Musk seeks up to $134 billion in damages from OpenAI, Microsoft

Latest News

  • Like Indiramma, NTR is equally important to us, says Revanth Reddy

    2 hours ago
  • Fake doctor dupes youth of smartphone in Bhadrachalam

    2 hours ago
  • TGIIC’s Raidurg e-auction sets record with Rs 237 crore per acre bid

    2 hours ago
  • Farmer walks barefoot, carries paddy sacks in pushcart to protest procurement delays in Telangana

    3 hours ago
  • Narrow escape for TGOA leader as burnt tree falls on car

    3 hours ago
  • Malkajgiri police book over 3000 cases against footpath encroachments

    3 hours ago
  • BRS leader launches free e-classes app for job aspirants

    4 hours ago
  • Sumit Antil wins gold, stars at Indian Open Para Athletics 2026

    4 hours ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam