Microsoft announces cloud database vulnerability

Microsoft has told thousands of its cloud computing customers about a database security flaw.

The statement, originally reported by Reuters, said that third parties could read, change, or even delete businesses’ main databases.

The vulnerability was discovered in Microsoft Azure’s Cosmos database product by Ami Luttwak, chief technology officer at Israeli cybersecurity group Wiz.

Luttwak was previously chief technology officer at Microsoft’s cloud security division.
Microsoft told users to change their security keys in the email, as Microsoft is unable to do this by themselves.

According to Microsoft, Cosmo is used by a significant number of large corporations worldwide, including Coca-Cola, Exxon Mobil, and Citrix.

The software giant is set to pay Wiz $40,000 for identifying and reporting the vulnerability.
Microsoft’s email as reported by Reuters said there was “no indication that external entities outside the researcher (Wiz) had access to the primary read-write key.”

Wiz said the vulnerability stemmed from a feature called Jupyter Notebook, added in 2019 to Cosmos DB, that allows customers visualise their data and create customised views.

Jupyter Notebook was automatically turned on for all Cosmos DBs in February 2021.

The news comes after a Microsoft vulnerability was exploited in the Solarwinds cyberattack in December 2020, which impacted over 200 organisations worldwide.

    Share Story:

Recent Stories


The future-ready CFO: Driving strategic growth and innovation
This National Technology News webinar sponsored by Sage will explore how CFOs can leverage their unique blend of financial acumen, technological savvy, and strategic mindset to foster cross-functional collaboration and shape overall company direction. Attendees will gain insights into breaking down operational silos, aligning goals across departments like IT, operations, HR, and marketing, and utilising technology to enable real-time data sharing and visibility.

The corporate roadmap to payment excellence: Keeping pace with emerging trends to maximise growth opportunities
In today's rapidly evolving finance and accounting landscape, one of the biggest challenges organisations face is attracting and retaining top talent. As automation and AI revolutionise the profession, finance teams require new skillsets centred on analysis, collaboration, and strategic thinking to drive sustainable competitive advantage.