Urgent.News

What's breaking now, across thousands of outlets.

Tech

The Most Expensive Code You Ship Is the Admin Panel Nobody Reviews

Every product has a second application hiding behind it. It has no designer, no load tests and no on-call rotation, and its security model often amounts to a boolean called is_admin . Support agents use it to look up customers, reset passwords and issue refunds, a few service accounts talk to it overnight, and nobody has read its pull requests with real curiosity since the sprint it was built in.…

Every product possesses an internally focused application that goes unnoticed. This hidden code typically lacks design, testing, and monitoring, and relies on a simple "is_admin" boolean for security. Support agents frequently utilize this code to access customer information, reset passwords, and process refunds. Service accounts also connect to it, often without proper review or scrutiny.

This type of software has been linked to numerous costly incidents over the past few years, with the breaches' impact extending beyond IT to affect the company's financial health.

The most notable example comes from Coinbase in May 2025, where criminals bribed support staff and employees outside the United States to obtain customer data through legitimate access. The company later incurred a $307 million expense in a single quarter due to the incident. Coinbase's monitoring system had flagged unsupported data access months before the extortion email, highlighting the potential for abuse when no reason is required to open a record.

Another case is the MGM Resorts breach in 2023, where attackers impersonated IT service desk personnel to gain access to customer information, leading to an estimated $100 million loss for MGM. Clorox experienced a similar incident, where help desk agents unknowingly facilitated an attacker's entry by resetting passwords and MFA without verifying the caller's identity.

In 2023, Okta suffered from an attacker who gained access to their support system using a service account that had stored credentials on an employee's personal device, resulting in the hijacking of customer sessions and a 11.5% drop in the company's stock value.

Lastly, Salesloft's integration with Drift in 2025 saw attackers exploiting OAuth tokens, accessing customer data from support tickets. This threat is particularly concerning as many organizations rely on these integrations for customer support, inadvertently exposing sensitive information through support communications. The attackers targeted support workflows, which usually involve privileged operations, and are often managed by outsourced teams, making them prime targets for exploitation.

To mitigate these risks, organizations should treat their back-office tools as production systems, implementing access controls, logging, and monitoring to reduce abuse and potential breaches.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Your Podcast Habit Is Read-Only. Here's How to Give It a Write Path

Plenty of developers keep a podcast queue longer than their sprint backlog, and they burn through it the same way: earbuds in, playback at 1.5x, one eye on Slack.

  • Podcasts treated as read-only, no writing to disk.
  • Active engagement improves comprehension, contrary to ease.
  • Ten-minute post-episode protocol boosts learning retention.

I built a rotation checker for product photos, then a whole campaign tool on top of it

Two products came out of one problem. Sellers kept uploading product photos that looked fine on their phone and came out sideways on the marketplace, because the camera's rotation tag and the pixels…

  • UprightAI tool corrects photo rotation for marketplace listings.
  • BlueVeta campaign tool offers pay-per-pack photo solutions.
  • Verification process ensures image accuracy for sellers.

Stoplight Studio is gone: five OpenAPI editors compared for 2026

If you maintained OpenAPI documents between 2018 and 2023, Stoplight Studio was probably on your machine: a desktop editor that combined a form-based operation view with raw YAML, no account required…

  • Stoplight Studio discontinued in 2023, leaving teams to seek alternatives
  • Five OpenAPI editors compared for performance against real workload
  • Key features: two-way editing, multi-file support, raw YAML alongside form fields

More from Saturday 3 October →