Posted by EatonZ 1 day ago
At least with the second app (admittedly judging by that UI) this is a classic case of some team that has only every built apps that sit behind the firewall being made to “move to cloud,” without any understanding of what it means that their code is exposed to the internet.
I’ve seen a lot of orgs “solve” this not by fixing their code but by using Direct Connect to keep everything within the corporate network boundary; since after all compromised VPN credentials are another team’s problem!
I wonder what changed…