#powerpages — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #powerpages, aggregated by home.social.
-
Microsoft published a migration guide for removing wildcard dependencies on the Power Pages Web API: https://learn.microsoft.com/en-us/troubleshoot/power-platform/power-pages/migrate-web-api-wildcard
You've got 10 days to act before existing sites start failing unless the configuration is updated.
-
30 days after ExfilSquad published they harvested data from orgs using Power Pages, sites like ATL311 remain online. Showing PII data via publicly visible case detail records that contain customer names, email threads etc.
Built by Accenture, designed by no one.🙄
More thoughts posted here:
https://www.linkedin.com/feed/update/urn:li:share:7497977035005341697/ATL311 portal:
https://www.atl311.com/en-US/support/Reddit thread on CoA data breach:
https://www.reddit.com/r/Atlanta/comments/1vvbn6w/coa_website_data_breach/ -
I couldn't stand the mess of Power Platform product blog that Microsoft's marketing team had created. Navigating that WP site was just torture. So, I created a better page for it: https://ppnews.jukkan.com
Just a quick project in Lovable. Clear, chronological feed with proper search tools. No brand images and other "content" to distract you.
#PowerPlatform #PowerApps #PowerAutomate #PowerPages #Microsoft #Lovable
-
Now we have an official Power Pages deprecation announcement for the wildcard value in Web API field configuration: https://learn.microsoft.com/en-us/power-pages/important-changes-deprecations#wildcard-value--in-web-api-field-configuration
September 14, 2026. That's the deadline for all Microsoft customers with portals to change their configs.
"Why is this change necessary?" Hmm... Let me guess: the ExfilSquad campaign?
-
Already 4.6 million leaked records in the confirmed Power Pages sites targeted by ExfilSquad. Now, Microsoft is rolling out a Web API hotfix to make misconfiguration less likely to expose entire customer databases on the public internet. Tracking the story in my newsletter:
https://www.perspectives.plus/p/stupid-easy-power-pages-data-leak
-
Microsoft is previewing a Power Pages security agent that could warn MS customers / partners about misconfigured settings for their websites:
I tried running the preview agent. Unfortunately, at least here in the EU, it refused to work. Yes, data movement across regions was already enabled. No, this shouldn't push the data outside EU data boundary, according to MS.
Anyone had luck with this in their M365 tenant?
-
15 real Power Pages websites got targeted literally because kids wanted to build up online reputation for their new group. No expectation for revenue via ransom payment - just fame.🤳
UK police, dept for education, Newcastle University, Bonava. 4/15 victims confirmed by now.
Exfiltrating real customer data by the millions, for the lulz. The story of ExfilSquad + incompetent portal development. (paywall)
https://www.thetimes.com/uk/crime/article/who-are-exfilsquad-hackers-cyberattacks-dtzhvvzgj
-
Misconfigured Power Pages websites were targeted in the data breach carried out by ExfilSquad. 15 victims, at least 3 confirmed, with the big whale still waiting for confirmation: Microsoft itself.
Why does this keep happening? The pattern is similar to 2021, the Web API is just a modern replacement to the OData feeds leaking the data earlier.
Gift link to my full article, since I learned so much about this from folks on Mastodon.👋
https://www.perspectives.plus/p/stop-leaking-dataverse-data-via-portals?gift_content=503cc0d4-98ed-4692-86b8-03f4d3a35e3d -
🟪 Creating a Power Page with Claude — Session 2
Demo of Claude Code in VS Code to scaffold a county 311 SPA prototype and iterate it quickly before Power Pages deployment. The agent runs commands you approve and serves a local dev preview. Make UI edits with natural language and screenshots add a use my location button and run an accessibility pass. Claude pro license required. 🚀
💡 Local SPA scaffold in VS Code
🔍 Rapid UI iteration via Claude prompts
⚖️ Accessibility pass and deploy ready prototype -
Power Pages + Liquid. If you are building external facing sites, learn Liquid Template Language. The drag-and-drop editor is great for 80% of the site, but that last 20% of custom logic requires code. Liquid is the key to unlocking the portal.
-
You can now check how much #Dataverse storage capacity different Power Platform and Dynamics 365 licenses give you, using this Dataverse Capacity Calculator I created:
https://www.youtube.com/watch?v=zMbbKDQRqd8
Direct link: https://dataverse.licensing.guide/
#PowerApps #PowerAutomate #PowerPages #CopilotStudio #Dynamics365
-
Power Apps are meant for you internal user audience. What can we do to expose Dataverse data to external users like customers?
#PowerPages isn't the only option that customers should explore. In fact, even portals/websites aren't alwaysthe best tool.
In my Perspectives on #PowerPlatform newsletter, I present both traditional and creative ways to allow external users to interact with data in your #Dataverse environment: https://www.perspectives.plus/p/external-access-to-power-platform-data
-
Microsoft Patches Exploited Power Pages Vulnerability – Source: www.securityweek.com https://ciso2ciso.com/microsoft-patches-exploited-power-pages-vulnerability-source-www-securityweek-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #vulnerabilities #securityweekcom #securityweek #PowerPages #Exploited #Microsoft #FEATURED
-
Microsoft Patches Exploited Power Pages Vulnerability https://www.securityweek.com/microsoft-patches-exploited-power-pages-vulnerability/ #Vulnerabilities #PowerPages #exploited #Microsoft #Featured
-
Microsoft Patches Exploited Power Pages Vulnerability https://www.securityweek.com/microsoft-patches-exploited-power-pages-vulnerability/ #Vulnerabilities #PowerPages #exploited #Microsoft #Featured
-
Data leaks from websites built on Microsoft Power Pages, including 1.1 million NHS records – Source: www.bitdefender.com https://ciso2ciso.com/data-leaks-from-websites-built-on-microsoft-power-pages-including-1-1-million-nhs-records-source-www-bitdefender-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #operatingsystems #grahamcluleycom #Grahamcluley #DataBreach #PowerPages #Guestblog #Microsoft #Dataloss #privacy #NHS
-
Data leaks from websites built on Microsoft Power Pages, including 1.1 million NHS records https://www.bitdefender.com/en-us/blog/hotforsecurity/data-leaks-microsoft-power-pages-nhs-records #OperatingSystems #databreach #PowerPages #Guestblog #Microsoft #Dataloss #Privacy #NHS
-
"Private businesses and public-sector organizations are unwittingly exposing millions of people's sensitive information to the public internet because they misconfigure #Microsoft #PowerPages website creation program."
https://www.theregister.com/2024/11/15/microsoft_power_pages_misconfigurations/
-
Hmm, where have I seen that headline before? Oh, yeah, it was 3 years ago.
Different brand name (#PowerApps Portals vs. #PowerPages), lots of new security related features developed by MS. And still, developers misconfigure their sites to leak PII data.😐
More thoughts over on LI: https://www.linkedin.com/feed/update/urn:li:share:7263991635212951552/
The new report from 2024: https://appomni.com/ao-labs/microsoft-power-pages-data-exposure-reviewed/
-
Microsoft Power Pages misconfigurations have exposed sensitive user data, with incidents like an NHS contractor leak impacting millions of records. #cybersecurity #microsoft #powerpages
-
Microsoft Power Pages Misconfigurations Expose Millions of Records Globally – Source:hackread.com https://ciso2ciso.com/microsoft-power-pages-misconfigurations-expose-millions-of-records-globally-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #Misconfiguration #cybersecurity #DataBreach #PowerPages #Microsoft #Hackread #security #privacy #Leaks #NHS
-
Microsoft Power Pages Misconfigurations Expose Millions of Records Globally https://hackread.com/microsoft-power-pages-misconfigurations-data-leak/ #Misconfiguration #Cybersecurity #databreach #PowerPages #Microsoft #Security #Privacy #Leaks #NHS