OWASPNoCode's profile picture. Security risks, hacking stories and ways to protect low-code/no-code apps
#infosec #appsec #lowcode #nocode

OWASP Low-Code/No-Code

@OWASPNoCode

Security risks, hacking stories and ways to protect low-code/no-code apps #infosec #appsec #lowcode #nocode

OWASP Low-Code/No-Code repostou

incredible vibes at openai's security conf last week I came out both humbled and excited and with a greater conviction -- you can just do things!

mbrg0's tweet image. incredible vibes at openai's security conf last week

I came out both humbled and excited
and with a greater conviction --

you can just do things!

OWASP Low-Code/No-Code repostou

Had great fun Wednesday with Michael Bargury (@mbrg0 ) at Microsoft's BlueHat (#Bluehat) security conference on Wednesday. Our talk focused on risk reduction in Low-Code/No-Code platforms (x.com/MSFTBlueHat/st…).

DonWiillitsV2's tweet image. Had great fun Wednesday with Michael Bargury (@mbrg0 ) at Microsoft's BlueHat (#Bluehat) security conference on Wednesday. Our talk focused on risk reduction in Low-Code/No-Code platforms (x.com/MSFTBlueHat/st…).

📣SPEAKER ANNOUNCEMENT📣 Our next #BlueHat speakers are Michael Bargury (@mbrg0), Co-Founder & CTO, Zenity and Project Leader at OWASP, and Don Willits, Senior Program Manager, Microsoft. They will be co-presenting a talk titled “Scaling AppSec with an SDL for Citizen…

MSFTBlueHat's tweet image. 📣SPEAKER ANNOUNCEMENT📣

Our next #BlueHat speakers are Michael Bargury (@mbrg0), Co-Founder & CTO, Zenity and Project Leader at OWASP, and Don Willits, Senior Program Manager, Microsoft. They will be co-presenting a talk titled “Scaling AppSec with an SDL for Citizen…
MSFTBlueHat's tweet image. 📣SPEAKER ANNOUNCEMENT📣

Our next #BlueHat speakers are Michael Bargury (@mbrg0), Co-Founder & CTO, Zenity and Project Leader at OWASP, and Don Willits, Senior Program Manager, Microsoft. They will be co-presenting a talk titled “Scaling AppSec with an SDL for Citizen…


OWASP Low-Code/No-Code repostou

really really excited to be sharing this insider today together with microsoft's @donwillits66 at #bluehat see you in 30m

mbrg0's tweet image. really really excited to be sharing this insider today together with microsoft's @donwillits66 at #bluehat
see you in 30m

OWASP Low-Code/No-Code repostou

modifying salesforce einstein is a privileged operation saved for admins unless einstein uses flows then flow makers can implicitly modify too


OWASP Low-Code/No-Code repostou

First Vulnerability in Salesforce AI Apparently you can edit edit EVERYONE’s Einstein Copilot without admin permissions? Here’s exactly how labs.zenity.io/p/over-permiss…


Join us in a couple of hours for awesome talks on attacking and defending low-code/no-code apps 🚀 by @wyattDaveDev @ZivDanielHagbi

🚨 Join Our Upcoming Webinar on Low-Code/No-Code Security! 🚨 I'm thrilled to invite you to our next OWASP Low-Code/No-Code security meetup! This is a must-attend event for anyone passionate about safeguarding their business apps. 👉 Register here: forms.gle/rot78zf6yKciNm…

ZivDanielHagbi's tweet image. 🚨 Join Our Upcoming Webinar on Low-Code/No-Code Security! 🚨

I'm thrilled to invite you to our next OWASP Low-Code/No-Code security meetup! 
This is a must-attend event for anyone passionate about safeguarding their business apps.

👉 Register here: forms.gle/rot78zf6yKciNm…


OWASP Low-Code/No-Code repostou

@NoCodeOps is joining @Zapier, the leader in no-code automation! More here 👉 nocodeops.com/zapier


OWASP Low-Code/No-Code repostou

Pancakes have been had, now back to Power Automate. This tool is so powerful. As we all know, with great power comes .... This one will be a tough one to secure. Will need many layers of defense


OWASP Low-Code/No-Code repostou

tool drop time. enjoy! *powerpwn* v3 is out and its feature packed abusing m365 copilot collect full dumps of sensitive data across email, teams, sharepoint, calendar automated spear phishing scour the internet for copilot studio bots leaking sensitive data #DEFCON #BHUSA

mbrg0's tweet image. tool drop time. enjoy!
*powerpwn* v3 is out and its feature packed abusing m365 copilot

collect full dumps of sensitive data across email, teams, sharepoint, calendar

automated spear phishing

scour the internet for copilot studio bots leaking sensitive data

#DEFCON #BHUSA

OWASP Low-Code/No-Code repostou

Attacks on Microsoft’s Copilot AI allow for answers to be manipulated, data extracted, and security protections bypassed, new research shows. wired.com/story/microsof…


OWASP Low-Code/No-Code repostou

Attacks on Microsoft’s Copilot AI allow for answers to be manipulated, data extracted, and security protections bypassed, new research shows. wired.trib.al/vULHXIm


OWASP Low-Code/No-Code repostou

I found a publicly exposed confidential document belonging to a fortune 500 company using copilot studio 🤖 The first step in finding it was discovering over 1K unauthenticated copilot studio bots

avishai_efrat's tweet image. I found a publicly exposed confidential document belonging to a fortune 500 company using copilot studio 🤖

The first step in finding it was discovering over 1K unauthenticated copilot studio bots

OWASP Low-Code/No-Code repostou

When I ask Copilot about bank details it starts talking about Satya Nadella?? This is ~RCE - Remote Copilot Execution. Making YOUR Copilot obey to ME. Asked about: -Emails? here's a link to the summary 😈 -Bank info? Here are the wrong details -And more... DIY guide: #RCE #BH

tamirishaysh's tweet image. When I ask Copilot about bank details it starts talking about Satya Nadella??

This is ~RCE - Remote Copilot Execution. Making YOUR Copilot obey to ME.

Asked about:
-Emails? here's a link to the summary 😈
-Bank info? Here are the wrong details
-And more...

DIY guide:
#RCE #BH

OWASP Low-Code/No-Code repostou

Ever tried to navigate your way between the dozens of Microsoft admin portals? Just ask M365 Copilot, right? At your own risk. We got an ~RCE (Remote Copilot Execution) that can lead to phishing attacks just by sending a mail. #BHUSA #defcon32


OWASP Low-Code/No-Code repostou

we got an ~RCE on M365 Copilot by sending an email by ~RCE I mean full remote control over its actions - search for sensitive content (sharepoint, email, calendar, teams), execute plugins and outputs - bypass DLP controls, manipulate references, social engineer its users on our…


OWASP Low-Code/No-Code repostou

an attacker wants to get sensitive data you have access to here's how they get YOUR copilot to find and analyze that data, and lure you to a malicious site to exfiltrate it #DEFCON


OWASP Low-Code/No-Code repostou

while msft docs say this is not possible, copilot studio can leak High Restricted SharePoint files to any user on the Internet, no auth required #copilot #dataleak

mbrg0's tweet image. while msft docs say this is not possible, copilot studio can leak High Restricted SharePoint files to any user on the Internet, no auth required

#copilot #dataleak

OWASP Low-Code/No-Code repostou

The 2023 OWASP Global Board election has been finalized. First, congratulations to all the candidates. Directors elected in the 2023 Election are: Steve Springett Sam Stepanyan Kevin Johnson Avi Douglen The term for the Directors will begin on January 1, 2024.

owasp's tweet image. The 2023 OWASP Global Board election has been finalized.

First, congratulations to all the candidates.

Directors elected in the 2023 Election are:

Steve Springett
Sam Stepanyan
Kevin Johnson
Avi Douglen

The term for the Directors will begin on January 1, 2024.

Hi @OWASP folks at DC thank you for joining our project demo. Now join us at creating the next version of the Top 10!

OWASPNoCode's tweet image. Hi @OWASP folks at DC thank you for joining our project demo. Now join us at creating the next version of the Top 10!

Loading...

Something went wrong.


Something went wrong.