Threat reporting says the ExfilSquad group has been targeting misconfigured Microsoft Power Pages portals to access data exposed through the platform’s built-in Web API. Power Pages uses the /_api route to perform create, read, update, and delete operations against Microsoft Dataverse tables, and Microsoft documents that access is governed by per-table enablement, field-level controls, table permissions, column permissions, web roles, and CSRF protections. If those controls are improperly configured, portal data can become accessible in ways administrators did not intend.
Microsoft’s documentation shows that the API is designed for portal user experiences and requires explicit configuration for each table and field, including use of the correct EntitySetName in requests. The guidance also notes that unsupported tables are blocked and that missing mandatory field settings can produce the error "No fields defined for this entity", underscoring how heavily security depends on correct setup. The reported activity highlights a familiar cloud risk: attackers are abusing exposed functionality rather than a newly disclosed software flaw, making Power Pages permission reviews and API exposure checks a priority for defenders.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.