UiPath Security Risks and Concerns - Attack Demo by Alon Dankner

Опубликовано: 02 Сентябрь 2026
на канале: Kanopy Security
24
2

UiPath sits at the heart of many business processes, which means even small gaps can open the door to serious trouble. In this session, Alon Dankner from Nokod Security shows real attack actions that can hit UiPath workflows, using simple inputs to trigger harmful results. This is a straight, practical walk-through built for CISOs and AppSec leaders who need a clear view into how business automations can expose the organization without anyone noticing.

You will see how common workflow steps such as reading user input, sending email, running database queries, and compressing files can be turned into strong attack actions when input handling is missing. For security teams dealing with fast-moving no-code and RPA platforms, this demo is an eye opener that shows how easy it is for attackers to reach internal systems without touching a single line of code.

This session covers key concerns in low-code no-code security, UiPath security best practices, and broader RPA security risks. It gives real proof of how blind spots in business automations can leak data, run harmful commands, or pull in unsafe packages through supply chain tricks. These are not theory points; every example is shown live so you can see the result on the victim machine.

What you will learn:
✅ HTML input used to trigger harmful code inside emails
✅ SQL input that exposes private tables from the database
✅ File-name tricks that run commands on the host using simple workflow steps
✅ How unsafe third-party packages can run code the moment they are added
✅ How loose versioning allows attackers to swap in harmful dependencies
✅ Why no-coders, business users, and automation builders create a large unseen attack area
✅ How these risks tie into shadow IT and no-code business apps across the enterprise

📌 Why this matters
Enterprises now run thousands of business apps, bots, and flows. Many live outside classic AppSec oversight. UiPath, Power Platform, Salesforce, ServiceNow, Copilot, and other platforms give non-developers strong building power. When inputs and packages are not checked, the risk grows fast. For AppSec managers, this is a chance to show quick wins at scale and protect an area that is often ignored until attackers find it.

🌐 Learn more about Nokod Security
Website: https://nokodsecurity.com
LinkedIn:   / nokodsecurity  

👍 Like the video if this helped
💬 Tell us: Are you checking the security of your UiPath flows today?
🔔 Subscribe for more research on low-code no-code security, RPA risks, Copilot security, Power Platform protection, and shadow IT exposure.

#UiPathSecurity
#RPAsecurity
#LowCodeSecurity
#NoCodeSecurity
#BusinessAppsSecurity
#ShadowIT
#ShadowITSecurity
#AppSec
#CISO
#AppSecLeaders
#PowerPlatformSecurity
#CopilotSecurity
#SalesforceSecurity
#ServiceNowSecurity
#AIGovernance
#EnterpriseSecurity