Low Code High Risk: Enterprise Domination via Low Code Abuse
Michael Bargury
BSides NYC 2023 (0x04) · Day 1 · Talk - Red
In an era where digital transformation is paramount, low-code and no-code platforms have emerged as powerful tools, empowering business users—often termed **citizen developers**—to rapidly build applications and automate workflows without extensive programming knowledge. This talk by Michael Bargury, a leading expert in low-code/no-code security and head of the OWASP Low-Code/No-Code group, critically examines the profound security implications of this burgeoning trend. Bargury argues that while these platforms offer undeniable productivity benefits, their rapid proliferation, inherent design choices, and lack of traditional security oversight create significant, often unseen, risks that attackers are already exploiting.
AI review
Bargury brings genuine original research to a widely deployed but criminally underexamined attack surface — the credential-sharing-as-a-service model alone is a conceptually clean framing of a real, exploitable design failure. The APT-in-the-wild case study with six months of undetected exfiltration via Power Automate, combined with the ephemeral backdoor PoC that creates-executes-deletes automations and their logs, elevates this well above the typical 'here are misconfigs' survey talk.