Google Cloud Platform Vulnerability Led to Stealthy Account Backdoors

A vulnerability in Google Cloud Platform (GCP) could have allowed attackers to maliciously change an OAuth application and hide it to create a stealthy backdoor to any Google account.

Exploitation of the bug, referred to as GhostToken, could have allowed attackers to completely hide the malicious application from the Google user and leverage it to retrieve account tokens to access the victim’s data.

The issue was related to the deletion of OAuth clients, which essentially are GCP projects, app-to-app security firm Astrix, which identified the flaw in June last year, explains.

When a GCP project is deleted – either by the owner or anyone that has the necessary management permissions – the project enters a ‘pending deletion’ state for 30 days, allowing the developer to restore it if necessary.

However, when they are deleted, they are no longer displayed in the Google account application management page, even if they continue to have access to the account.

The same applies to GCP projects that are OAuth clients. While the user receives an error informing them that the client had been deleted, the application continues to have access to the account until effectively deleted.

Astrix also discovered that, when such an OAuth client is restored from the ‘pending deletion’ state, the refresh token created when the user first authorized the application is re-enabled.

This refresh token, the security firm explains, can then be used to get an access token to the victim’s account, and then access their data.

To exploit this vulnerability, an attacker could create or take over an OAuth application, thus gaining access to the refresh token. The attacker could then delete the project associated with the app to prevent the victim from removing it from their account.

Whenever the attacker wanted to access the victim’s data, they would restore the project, use the refresh token to get an access token, and then delete the project again to hide the application and make it unremovable.

“By exploiting the GhostToken vulnerability, attackers can hide their malicious application from the victim’s Google account application management page. Since this is the only place Google users can see their applications and revoke their access, the exploit makes the malicious app unremovable from the Google account,” Astrix notes.

In this scenario, the access token would allow the attacker to read the victim’s emails, access their Google Drive and Photos files, view their calendar, track their location, and “grant access to the victim’s Google Cloud Platform services”, the security firm explains.

In April 2023, Google addressed the vulnerability by making applications that are in a ‘pending deletion’ state visible in the Google account, so that users can remove them.

Related:Google Wants Android Users to Have More Control Over Their Data

Related: Google Suspends Chinese Shopping App Amid Security Concerns

Related: Google Workspace Client-Side Encryption Now Generally Available in Gmail, Calendar

Google Cloud Platform Vulnerability Led to Stealthy Account Backdoors




VMware Patches Pre-Auth Code Execution Flaw in Logging Product

Virtualization technology powerhouse VMware continues to encounter major security problems in its enterprise-facing log analysis product.

The company shipped urgent patches on Thursday to cover critical security defects in the VMware Aria Operations for Logs (formerly vRealize Log Insight) product line and warned of the risk of pre-authentication remote root exploits.

A critical-level advisory from VMware documents two separate vulnerabilities — CVE-2023-20864 and CVE-2023-20865 — in the VMware Aria Operations for Logs suite and provides guidance to help businesses mitigate the issues.

“An unauthenticated, malicious actor with network access to VMware Aria Operations for Logs may be able to execute arbitrary code as root,” the company said in its documentation of the CVE-2023-20864 vulnerability. The flaw carries a CVSS severity score of 9.8 out of 10.

The second vulnerability is described as a command injection issue with a CVSS score of 7.2/10.

“A malicious actor with administrative privileges in VMware Aria Operations for Logs can execute arbitrary commands as root,” according to the advisory.

VMware’s security troubles with the vRealize Logging product line are well known. The company has patched several high-severity issues in the past and confirmed the release of exploit code targeting known software bugs.

The VMWare vRealize product has been featured in the CISA KEV (Known Exploited Vulnerabilities) must-patch catalog.

Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event

Related: VMware Confirms Exploit Code Released for Critical vRealize Logging Flaws

Related: VMware Patches High-Severity Vulnerabilities in vRealize Operations

https://www.securityweek.com/vmware-patches-pre-auth-code-execution-flaw-in-logging-product/




PaperCut Warns of Exploited Vulnerability in Print Management Solutions

Print management solutions provider PaperCut has warned organizations that exploitation of a recently patched critical-severity vulnerability has commenced.

Papercut offers a print management system called PaperCut MF/NG, which provides monitoring and control capabilities. With PaperCut NG organizations can manage and control printing, while PaperCut MF allows them to manage and track off-the-glass copier activity.

Tracked as CVE-2023-27350 (CVSS score of 9.8), the exploited vulnerability is described as an improper access control issue in the SetupCompleted class of PaperCut MF/NG.

Successful exploitation of this security defect allows a remote, unauthenticated attacker to bypass authentication and execute arbitrary code with System privileges.

“We have confirmed that under certain circumstances this allows for an unauthenticated attacker to get remote code execution (RCE) on a PaperCut Application Server. This could be done remotely and without the need to log in,” PaperCut’s advisory reads.

The issue impacts PaperCut MF and NG versions 8.0 and later. The company patched the bug in March 2023 with the release of PaperCut MF and PaperCut NG versions 20.1.7, 21.2.11, and 22.0.9, and urges customers to update their installations as soon as possible, since exploitation has started.

“Please note that as of 18th April, 2023 we have evidence to suggest that unpatched servers are being exploited in the wild,” the company says. Both application servers and site servers are impacted.

PaperCut recommends reviewing server access logs and performing malware scans to identify any signs of suspicious activity resulting from the vulnerability’s exploitation.

“If you suspect that your server has been compromised, we recommend taking server backups, then wiping the Application Server, and rebuilding from a ‘safe’ backup point prior to when you discovered any suspicious behavior,” the company notes.

The vulnerability was reported to the vendor by an anonymous researcher through Trend Micro’s Zero Day Initiative (ZDI) in January. No information is available about the attacks exploiting CVE-2023-27350It’s currently unclear if the flaw was exploited with a zero-day status at some point. 

Along with CVE-2023-27350, PaperCut also patched CVE-2023–27351, a high-severity flaw in PaperCut MF or NG versions 15.0 and later, which could allow an attacker to access user information such as usernames, names, emails, office information, and card numbers.

“The attacker can also retrieve the hashed passwords for internal PaperCut-created users only. This could be done remotely and without the need to log in,” PaperCut explains.

The bug exists within the SecurityRequestFilter class and is the result of an improperly implemented authentication algorithm. This vulnerability, also reported through ZDI, does not appear to be exploited in malicious attacks.

Related:Veritas Vulnerabilities Exploited in Ransomware Attacks Added to CISA ‘Must Patch’ List

Related:CISA Adds Chrome, macOS Bugs to Known Exploited Vulnerabilities Catalog

Related:Zimbra Flaw Exploited by Russia Against NATO Countries Added to CISA ‘Must Patch’ List

https://www.securityweek.com/papercut-warns-of-exploited-vulnerability-in-print-management-solutions/




Fortra Completes Investigation Into GoAnywhere Zero-Day Incident

Fortra has completed the investigation into the recent zero-day incident involving its GoAnywhere managed file transfer (MFT) software and the company has shared a summary of its findings.

The investigation, conducted with the aid of cybersecurity firm Palo Alto Networks, revealed that malicious activity started on January 18, with cybercriminals exploiting a zero-day vulnerability against on-premises implementations running a specific configuration of GoAnywhere.

In the case of MFTaaS customers, the probe found that they were targeted with the zero-day vulnerability starting with January 28. 

Fortra became aware of the hack on January 30 and the unauthorized activity conducted in MFTaaS environments was completely neutralized the next day. The zero-day vulnerability, tracked as CVE-2023-0669, can be exploited for remote code execution. 

“Our initial investigation revealed the unauthorized party used CVE-2023-0669 to create unauthorized user accounts in some MFTaaS customer environments. For a subset of these customers, the unauthorized party leveraged these user accounts to download files from their hosted MFTaaS environments,” the company explained.

In addition, the attackers leveraged the zero-day to install up to two tools in compromised customer environments: Netcat and Errors.jsp.

Fortra said it immediately started working with customers to resolve the breach, but a patch for the zero-day was only released roughly one week after the incident was made public. 

“At this time, we can confirm this issue was isolated to our GoAnywhere MFT solution and does not involve any other aspects of the Fortra business, or its customers,” Fortra said.

The company has also described the actions it has taken to prevent future incidents and shared some recommendations for customers. 

The zero-day vulnerability appears to have been exploited by hackers associated with the Cl0p ransomware operation.

Dozens have been impacted and several major organizations have confirmed being hit, including Community Health Systems (CHS), Rubrik, Hitachi Energy, Crown Resorts, the City of Toronto, Saks Fifth Avenue, Pluralsight, PPF, P&G, Atos, and Rio Tinto. The hackers claimed that they targeted 130 organizations in the GoAnywhere campaign. 

Several victims said that while the attackers did exploit the vulnerability against them, impact was limited. Files allegedly stolen from some of them have been published on Cl0p’s leak website.

Related: Data Breach at Independent Living Systems Impacts 4 Million Individuals

Related: Western Digital Shuts Down Services Due to Cybersecurity Breach

Related: Latitude Financial Services Data Breach Impacts 300,000 Customers

https://www.securityweek.com/fortra-completes-investigation-into-goanywhere-zero-day-incident/




Google Patches Second Chrome Zero-Day Vulnerability of 2023

Google on Tuesday announced patches for another zero-day vulnerability found in the Chrome browser.

Tracked as CVE-2023-2136, the security defect is described as a high-severity integer overflow issue in Skia. The bug was reported by Google Threat Analysis Group researcher Clement Lecigne and, per Google’s policy, no monetary reward was issued for it.

“Google is aware that an exploit for CVE-2023-2136 exists in the wild,” the internet giant notes in its advisory.

CVE-2023-2136 is the second zero-day vulnerability resolved in Chrome this year, after CVE-2023-2033, a type confusion issue in the V8 JavaScript engine, was addressed with an emergency patch last week.

The latest Chrome 112 update includes eight security fixes, five of which address vulnerabilities reported by external researchers, including four bugs rated ‘high’ severity.

Google says it handed out $20,000 in bug bounty rewards to the reporting researchers.

Based on the paid reward, the most severe of the externally reported security defects are CVE-2023-2133 and CVE-2023-2134, two out-of-bounds memory access issues in the Service Worker API.

Out-of-bounds access bugs occur when the area outside of array bounds is accessed, which could lead to unexpected behavior, such as crashes and data leaks.

Both vulnerabilities were reported by Rong Jian, who received a total of $16,000 for the findings.

The third externally reported high-severity issue addressed with this Chrome update is CVE-2023-2135, a use-after-free bug in DevTools. Security researcher Cassidy Kim received a $3,000 bug bounty reward for finding this flaw.

Google handed out a $1,000 reward for CVE-2023-2137, a medium-severity heap-buffer overflow in SQLite, which was reported by 360 Vulnerability Research Institute’s Nan Wang and Guang Gong.

The new Chrome iteration is rolling out as version 112.0.5615.137 for Mac and as versions 112.0.5615.137/138 for Windows. A new Chrome for Linux release will arrive soon.

Related: CISA Adds Chrome, macOS Bugs to Known Exploited Vulnerabilities Catalog

Related:Chrome 112 Patches 16 Security Flaws

Related:Chrome 111 Update Patches High-Severity Vulnerabilities

https://www.securityweek.com/google-patches-second-chrome-zero-day-vulnerability-of-2023/




Oracle Releases 433 New Security Patches With April 2023 CPU

Oracle on Tuesday announced the release of 433 new patches as part of its quarterly set of security updates, including more than 70 fixes for critical-severity vulnerabilities.

More than 250 of the addressed vulnerabilities can be exploited remotely and without authentication. Some of the resolved bugs impact multiple products.

For the third quarter in a row, Oracle Communications received the largest number of security patches, at 77. Of the addressed vulnerabilities, 65 can be exploited by remote, unauthenticated attackers. A total of 27 flaws have a ‘critical’ severity rating.

Financial Services Applications also received many security patches this month, at 76. According to Oracle’s advisory, 59 of the resolved bugs can be exploited by attackers over the network, with no user credentials needed.

Oracle also released 49 new patches for Fusion Middleware, including fixes for 44 issues that are remotely exploitable without authentication.

Other Oracle applications that received numerous patches include MySQL (34 patches – 11 remotely exploitable, unauthenticated vulnerabilities), Retail Applications (22 – 16), Analytics (20 – 12), Communications Applications (18 – 13), JD Edwards (14 – 8), Virtualization (11 – 1), HealthCare Applications (10 – 8), PeopleSoft (10 – 8), Health Sciences Applications (10 – 3), and Insurance Applications (9 – 9).

Oracle also released patches for Java SE, Blockchain Platform, Commerce, Siebel CRM, Systems, Database, Essbase, Construction and Engineering, Utilities Applications, Enterprise Manager, E-Business Suite, iLearning, Supply Chain, GoldenGate, SQL Developer, Hyperion, Graph Server and Client, NoSQL Database, REST Data Services, and Hospitality Applications.

For many of these applications, the tech giant’s patches also address vulnerabilities in third-party dependencies.

Customers are advised to apply the available patches as soon as possible. Unpatched Oracle applications are known to have been exploited in malicious attacks.

“Due to the threat posed by a successful attack, Oracle strongly recommends that customers apply Critical Patch Update security patches as soon as possible,” the tech giant notes.

Related: Exploitation of Oracle E-Business Suite Vulnerability Starts After PoC Publication

Related: Oracle’s First Security Update for 2023 Includes 327 New Patches

Related: Oracle Fusion Middleware Vulnerability Exploited in the Wild

https://www.securityweek.com/oracle-releases-433-new-security-patches-with-april-2023-cpu/




US, UK: Russia Exploiting Old Vulnerability to Hack Cisco Routers

Government agencies in the United States and United Kingdom have issued a joint cybersecurity advisory to warn organizations about attacks in which a Russian threat group has exploited an old vulnerability to hack Cisco routers.

The threat actor in question is APT28 (aka Fancy Bear, Strontium, Pawn Storm, Sednit Gang and Sofacy), which has officially been linked by the US and UK to a Russian military intelligence unit. 

The APT28 attacks detailed this week targeted Cisco routers in the United States, Ukraine and other European countries in 2021. However, the exploited vulnerabilities still pose a significant risk, with Cisco saying that it’s “deeply concerned by an increase in the rate of high-sophistication attacks on network infrastructure”.

An advisory released on Tuesday by the UK’s National Cyber Security Centre (NCSC), the US Cybersecurity and Infrastructure Security Agency (CISA), the FBI and the NSA focuses on exploitation of CVE-2017-6742. Cisco informed customers about this and other similar vulnerabilities in 2017, when it made available patches and mitigations.

Cisco has warned customers about in-the-wild exploitation since 2018, but the company updated its original advisory this week to clarify that CVE-2017-6742 and seven other vulnerabilities patched in 2017 have been exploited. 

The flaws impact the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE software, and they allow a remote, authenticated attacker to execute arbitrary code on the targeted device by sending specially crafted SNMP packets. 

SNMP allows network administrators to remotely monitor and configure devices, but it can also be abused by hackers, particularly if default or easy-to-guess SNMP community strings are used. 

According to the US and UK agencies, in some of the attacks aimed at unpatched Cisco routers, APT28 used SNMP exploits to deploy malware that allowed the attackers to obtain additional device information and enable backdoor access to the system.

One piece of malware used to target Cisco routers via CVE-2017-6742 has been named Jaguar Tooth, and a report detailing the threat has been published by the NCSC. The malware is non-persistent, which means it cannot survive a reboot of the compromised device.

In a blog post published on Tuesday, Cisco reported seeing various activities conducted by threat actors on hacked infrastructure devices. The list includes installing malware, hijacking DNS traffic, modifying device configurations to gain further access, modifying memory to reintroduce patched vulnerabilities, capturing traffic, and using devices for attack delivery or command and control (C&C) purposes. 

The installation of malware on a device, Cisco said, allows an attacker to make changes that prevent malicious traffic from being blocked, provides backdoor access, can cause disruption by disabling the device, and enables traffic redirection.  

According to Cisco, even if a device is unpatched, applying best practices such as using a well-selected SNMP community string can prevent attacks. 

In addition, the networking giant pointed out that recently leaked files describing Russia’s cyber capabilities suggest that attacks are not limited to its own products, with hackers being able to target switches and routers made by nearly 20 manufacturers. 

Cisco also noted that network equipment is not targeted only by Russian hackers, but by Chinese state-sponsored threat actors as well. 

“Route/switch devices are stable, infrequently examined from a security perspective, are often poorly patched and provide deep network visibility. They are the perfect target for an adversary looking to be both quiet and have access to important intelligence capability as well as a foothold in a preferred network,” Cisco said.

Cisco has also published a separate blog post providing resources for hardening devices, detecting attacks, and performing forensic investigations. 

Related: CISA Says Recent Cisco Router Vulnerabilities Exploited in Attacks

Related: Flaw in Cisco Industrial Appliances Allows Malicious Code to Persist Across Reboots

https://www.securityweek.com/us-uk-russia-exploiting-old-vulnerability-to-hack-cisco-routers/




NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022: Citizen Lab

Israeli spyware vendor NSO Group used at least three previously unknown iOS zero-click exploits in 2022, according to a new report from Citizen Lab.

NSO Group’s Pegasus spyware has often been delivered to targeted iPhones using zero-click and/or zero-day exploits, and while Apple has taken steps to prevent attacks against its customers, NSO’s exploit developers continue to find ways to bypass mitigations.

Citizen Lab, a group at the University of Toronto that focuses on human rights and security research, came across the new iOS exploits while investigating malware infections on the iPhones of human rights defenders in Mexico.

One of the new zero-click exploits discovered by Citizen Lab has been named PwnYourHome. This two-step exploit targets HomeKit and iMessage and it was used against iOS 15 and 16 devices starting with October 2022. 

Another two-step exploit, which targets the Find My feature and iMessage, has been dubbed FindMyPwn. This zero-click exploit has been used against iPhones running iOS 15 since at least June 2022. 

The third, named LatentImage, was seen on only one device and it seems to be the first new exploit used by NSO in 2022. 

The FindMyPwn and PwnYourHome exploits were used as zero-days.

Apple was informed about the findings in October 2022 and January 2023. One of the vulnerabilities involved in these attacks is CVE-2023-23529, which Apple fixed in February. It’s unclear what other CVE identifiers have been assigned to the flaws associated with these exploits. The tech giant has patched roughly a dozen iOS zero-days over the past year. 

Apple sent out notifications to targeted users in November and December 2022, as well as in March 2023. 

NSO Group may have since improved its exploits, but Citizen Lab has not seen the PwnYourHome exploit work against devices that had Apple’s Lockdown Mode feature enabled. 

Citizen Lab discovered the new exploits after finding indicators of compromise known to be associated with Pegasus attacks, but the organization has decided not to disclose those indicators as NSO Group might leverage the information to ensure that future attacks are not detected. 

Citizen Lab and Microsoft recently detailed the iOS malware developed by an Israel-based spyware vendor named QuaDream. The company, described as a competitor of NSO, is reportedly shutting down, partly due to the latest revelations. 

Related: Google, CISA Warn of Android Flaw After Reports of Chinese App Zero-Day Exploitation 

Related: ​​Apple Patches Exploited iOS Vulnerability in Old iPhones

Related: Citizen Lab Documents Israeli Surveillance Spyware Infections in Spain

https://www.securityweek.com/nso-group-used-at-least-3-ios-zero-click-exploits-in-2022-citizen-lab/




CISA Adds Chrome, macOS Bugs to Known Exploited Vulnerabilities Catalog

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two flaws to its known exploited vulnerabilities (KEV) catalog: a Chrome bug patched last week and a macOS bug exploited by the DazzleSpy malware.

The Chrome vulnerability, tracked as CVE-2023-2033, was patched by Google on Friday with a Chrome 112 update. The flaw has been described as a type confusion issue affecting the V8 JavaScript engine. 

Google has not shared any information about the attacks exploiting CVE-2023-2033. However, the issue was reported by a member of the company’s Threat Analysis Group, which often finds vulnerabilities exploited by commercial spyware vendors. 

The second vulnerability, CVE-2019-8526, is a privilege escalation issue affecting Apple’s macOS operating system. A patch was released in March 2019 and the details of the flaw were made public a few months later by the researcher who reported it to the tech giant. 

CVE-2019-8526, also known as KeySteal, affects macOS versions prior to 10.14.4 and it can be exploited to access passwords inside the Keychain without any warning to the user. 

Cybersecurity firm ESET warned about exploitation of CVE-2019-8526 in January 2022, when it released a report on a piece of macOS malware dubbed DazzleSpy. The malware, described as a full-featured backdoor that allows attackers to control the compromised device and steal data, was discovered during the analysis of an attack launched by a state-sponsored threat group against pro-democracy individuals in Hong Kong. 

It’s worth noting that Apple’s advisory does not say anything about CVE-2019-8526 being exploited in attacks. 

It’s unclear if CISA has become aware of additional attacks exploiting CVE-2019-8526 or if it added the vulnerability to the KEV catalog due to the DazzleSpy attacks. Considering that the KeySteal exploit has been publicly available for years, it’s possible that other threat actors have added it to their arsenal. 

CISA has instructed federal agencies to patch CVE-2019-8526 and CVE-2023-2033 until May 8. Other organizations should also ensure that the vulnerabilities included in the KEV catalog are patched. 

Related: Google, CISA Warn of Android Flaw After Reports of Chinese App Zero-Day Exploitation 

Related: CISA Warns of Plex Vulnerability Linked to LastPass Hack

Related: Veritas Vulnerabilities Exploited in Ransomware Attacks Added to CISA ‘Must Patch’ List

https://www.securityweek.com/cisa-adds-chrome-macos-bugs-to-known-exploited-vulnerabilities-catalog/




The Security and Productivity Implications of Low Code/No Code Development

The low code/no code movement provides simplified app generation – but it needs to be understood to be safe.

We are struggling to satisfy the demand for new software – the laborious effort of writing code has become a bottleneck to innovation in general, and being first to market in particular. 

In other areas of business, such problems are being solved through automation. Automation applied to code generation leads to the concept of ‘low code/no code’; that is, the automatic generation of software requiring little or even no direct human coding. The question is whether this concept will be a genuine boon to secure app development, or just a promise full of hidden landmines and booby traps – like open source software has proved to be.

We’re going to examine the concept, use, advantages and disadvantages, and the security implications of this evolution. 

“The concept of low-code/no-code isn’t new,” explains Steve Wilson, CPO at Contrast Security; “but the definition isn’t very specific either. For decades, most computer programs have been written with text-based programming languages – aka code. The resulting ‘source code’ is then ‘compiled’ into the code a computer can execute. This is true for most apps that run on back-end servers, desktops, and even mobile phones today.”

Low code/no code environments are introducing a higher level of abstraction, often using concepts like drag-and-drop icons and data flow diagrams. “In other words, visual programming rather than textual. Alternatively, low-code environments may mix visual programming with small bits of textual code, often referred to as ‘scripts’ or ‘functions’ to allow the developer or user to mix the benefits of visual and textual concepts.”

Ryan Cunningham, VP of Power Apps at Microsoft described the Microsoft product. “Low code/no code platforms like the Microsoft Power Platform,” he said, “use AI, automation, and ‘what you see is what you get’ tooling to make it easier to create applications, data visualizations, workflows, chatbots, and websites more efficiently than traditional ‘code-first’ software development.”

The application of low code/no code is expanding, and there is no single sentence nor use case that can categorize its potential. Broadly speaking, it falls into apps or workflows, or apps with workflows.

Eoin Hinchy, CEO and co-founder at Tines, has a low code/no code platform designed for security personnel. “Security teams face a major problem: there’s too much work and not enough staff,” he says. “More specifically, overworked staff are doing repetitive and mundane tasks, which not only leads to burnout [more likely, ‘rust out’, see Burnout in Cybersecurity – Can It Be Prevented?] but to human error that could cost a company millions.”

This can be solved by allowing the teams to develop their own scripts to automate workflows. But “Security analysts don’t necessarily have coding skills,” continued Hinchy, “so, they’re forced to call in developers, which can take weeks or months to create integrations and deploy automations. Then, if an update or addition is needed, the analyst needs to get developers involved all over again.”

Eoin Hinchy

His argument is that no-code automation allows frontline security analysts to independently automate time-consuming, mission-critical workflows: “like phishing attack responses, suspicious logins, and even employee onboarding and offboarding. Using a drag-and-drop interface, users place actions into a workflow, connect them together, enter parameters, test it, and set it loose.”

Automating workflows is just one of the uses for low code/no code concepts. Richard Rabins, CEO and co-founder of Alpha Software, sees the core technology of his platform frequently being used to develop mobile and web apps that combine with data collection workflows.

“The most common use case,” he said, “is replacing paper forms with a mobile app for collecting data. For example, you may have an inspector who examines bridges. That inspector used to enter details of the inspection on paper, but now the inspector uses an app on a tablet.” Rabins’ product can build that app from common building blocks since the requirements of data collection are often similar.

“In some cases,” he continued, “the bridge will be fine and all that is necessary is to set the date of the next inspection and file the report. Often, however, further action will be required. Repair work may be necessary, so the process needs to kick off a further workflow.” This workflow can also be generated by his app, demonstrating a low code/no code use case combining a stand-alone app and workflow.

Ryan Cunningham sees a much wider capability. “More than 7.4 million monthly active developers are using Power Platform to build standalone low-code apps, automations, websites, and dashboards. These developers range from audiologists and former bricklayers to dedicated software professionals who have found a new way to work faster and more efficiently.”

The point to note from his comment is that you don’t need to be a developer to produce new apps – you could be a sole trader or small business with no IT staff, and yet still generate you own proprietary apps. But if you are a professional developer in a larger organization, you can work faster and more efficiently. In short, low code/no code brings skills to the unskilled, and efficiency to the professionals.

“The top two benefits of low code/no code are speed of delivery and opening it up for ‘business users’ to self-service and develop workflows that meet their needs without needing to engage with IT. However, this is also the biggest potential pitfall,” comments Mark Lambert, VP of products at ArmorCode.

Reed Loden, VP of security at Teleport agrees. “I’m personally a big fan of low code/no code,” he says. “These types of products have made code integrations really easy, making certain actions possible that would have taken a typical developer a lot of time to complete.”

Reed Loden

But there are both pros and cons, he continued. “The pros are that developers can quickly make integrations that are super useful for cybersecurity. For example, it can create an interaction that detects an alert and automatically remediates a problem, without any human intervention required. The con is that these types of tools require a lot of access, so if they are compromised, it can be really bad for the customer.”

Cunningham, describes the movement as a democratic force: “This technology changes the traditional development landscape by making existing professionals more productive and at the same time democratizing software development for a wider range of users.”

Allowing professionals in a professional environment to be more productive is good. “It decreases the risks associated with either one-off software projects or the ‘shadow IT’ alternatives that many business users will turn to without any other viable solution,” he adds.

But the same democratizing process could increase shadow IT. In one area it could help a small business develop personal apps to improve internal operations and workflow. This could be good or bad depending on the security of the app’s usage.

But it could also persuade an employee in a large organization to by-pass the IT department and produce his or her own personal automation tools. “Giving the power of development to non-developers,” comments Nick Rago, Field CTO at Salt Security, “also presents another security risk in regard to shadow IT, even if the endpoints are intended to be ‘internal only’. We have seen far too many breaches where attackers gain inside or privileged access to internal applications and APIs.”

Lambert adds, “Simply put, we need a defined process for deploying low-code, no-code into production environments; and have guardrails to ensure that, if any issues are present, the potential damage is limited.”

In fairness to Cunningham, extensive guardrails are present in the Microsoft product. “The Power Platform is built upon all the security and governance capabilities Microsoft is known for,” he comments, “and makes it possible for IT departments to require standard guardrails around app development and data access. Administrators can build guardrails around data, applications, and environments.”

The problem is that once a new technology is in process, it cannot be contained. We are seeing this with AI and generative pre-trained transformers (GPTs) such as ChatGPT – democratizing the use of AI leads to its personal use outside the built-in guardrails of the developer. With low code/no code, individuals not wishing to be constrained by the IT department will likely turn to third-party platforms to produce their own shadow IT apps, outside the purview of the IT department’s official guardrails.

Just as the web created the citizen journalist, so is low code/no code creating the citizen developer — with similar concerns. The output and the connection between subject and output both increase, but the accuracy and quality of the output needs scrutiny. It may be that the democratization of app development — at least for corporations — should be considered more as a potentially worrying side-effect than an advantage of low code/no code.

“One of the advantages of low code is that it allows non-developers to build their own applications,” says Jeff Williams, CTO and co-founder at Contrast Security. But he adds, “There is also a con in this as citizen developers are more likely to make inadvertent mistakes that could lead to security issues. I would expect citizen developers will make a lot of the basic mistakes such as hardcoded and exposed credentials, missing authentication and authorization checks, disclosure of PII, and exposure of implementation details.”

That said, if the process can be constrained to the professional IT department, more and potentially more secure code can be produced faster – and that alone will drive increasing adoption.

Ernest Lefner, CPO at Gluware – a firm that offers no-code process automation for networks – sees six primary advantages in the low code/no code movement. These are faster innovation, lower costs and improved efficiency, customer-focused delivery, less risk, greater control over intellectual property, and standardization.

“The biggest pitfalls of a low code/no code strategy,” he says, “revolve around adoption and culture. Large scale organizations have a myriad of processes that were created specifically to avoid well known problems. Many of those problems no longer exist when you are employing automation for 90+% of your delivery. In many cases organizations try to retrofit low/no code solutions with all checks and balances of an over bloated delivery process and significantly increase the complexity of how you automate.”

Nevertheless, insists Mark Lambert, VP of products at ArmorCode, “Just because anyone ‘can’ create something, shouldn’t mean they should. Programming is inherently difficult. This is why it’s a profession. It’s why people have degrees in computer science. And why we’ve developed processes to ensure software is delivered that is both reliable and secure.”

“If the platform is well designed and is generating code that’s secure, that’s a Good Thing,” says Mike Parkin, senior technical engineer at Vulcan Cyber, “but it may also potentially introduce idiosyncrasies or vulnerabilities that a threat actor could leverage. Overall, though, the low/no code platforms offer more advantages than not.”

“Low code solutions are often considered more of a black box where developers may not have full control over how the underlying system is used, making it difficult to ensure the security of the application,” warns Jason Davis, VP of product and applications at Sauce Labs. “This can have implications as engineers don’t have control over network security, server configurations, security policies, and use of third-party services.”

Cunningham is a firm believer in the potential security of low code/no code. “A well-managed low code practice significantly decreases security concerns by standardizing application delivery on a robust platform with secure best practices built in… Companies can set granular data loss prevention policies to apply across low code environments.”

But Davis adds, “Vulnerabilities such as those achieved through inadequate input validation, insecure user input handling, or backdoors allowing unauthenticated access are always a concern.”

Rabins believes the security concerns are more in the use of the finished app, than the building blocks of its generator. Firstly, the generator is developed by experts with a security first approach. Secondly, it is under constant overview of security experts. And thirdly, since it is a cloud-based platform, any concerns can be immediately addressed and corrected for all future customers.

But he adds, “Any software that gets written has massive security implications. An app could be sending nurses to take care of patients in their own homes, and it collects sensitive medical information.” Here, it is not so much the security of the app’s code, but the security of the app’s usage that needs to be considered.

This is the primary security issue: the democratization of app production puts the ability into the hands of individuals who may have little understanding of cybersecurity and compliance regulations.

To complicate matters, those individuals or sole traders could be a component of your supply chain. Williams, however, doesn’t feel we should over-stress security concerns. “The risks are essentially the same [for all software]. Authentication, authorization, injection, encryption, logging, libraries, etc. There are slight differences with every application framework. And low/no code is no different.”

Wilson points out, “As with many things in IT, security is a shared responsibility model. What is the user/developer responsible for and what is the development environment responsible for. In a low-code environment, classic ‘vulnerabilities’ such as SQL Injection may not be a worry, and many user-authentication issues may be automatically handled. However, the user/developer may still make logic errors where they pass inappropriate data back to users or store data in insecure manners. In essence, the problems are all still there, but they move around in terms of who is responsible for what. At a minimum, you should thoroughly investigate the security characteristics, tools and practices that are recommended by the provider of your low-code tooling.”

“There are still trust issues in putting the fate of the network specifically into the hands of automation. Many network shops still want to keep one hand on the wheel. As we gain trust in the capabilities of low code/no code platforms we should see a lift in adoption,” says Lefner. “Ultimately no one wants to be working on Saturday at 2:00 am anymore. With the automation capabilities we have today, no one should have to.”

He believes this is just the beginning. “I expect to see the proliferation of low code/no code solutions grow in the next to 12-18 months. With the skills in short supply, and the absolute complexity and large failure rates in large scale automation programs, companies are going to need a flexible, less risky way to build efficiencies.”

Like all new technologies, there are concerns in the early days. Cloud-based platforms reduce some of the concerns of low code/no code. Greater understanding of the governance and guardrails necessary to manage the results will come. The advantages without the disadvantages will increase over time. 

This is clearly an evolutionary step in the generation of application code. Trying to stop evolution is like standing in front of a bulldozer rolling down the Hill of Inevitability.

Related: Security Automation Firm Tines Raises $26 Million at $300 Million Valuation

Related: Low Code/No Code App Security Firm Zenity Emerges From Stealth

Related: No-Code Security Automation Company ContraForce Emerges From Stealth

Related: Misconfigured Microsoft Power Apps Portals Exposed Millions of Records

https://www.securityweek.com/the-security-and-productivity-implications-of-low-code-no-code-development/