Wiz researchers have uncovered a critical flaw in Microsoft's Azure Cosmos DB that could have allowed a single credential to unlock every database running in the service. They named that credential the Cosmos Master Key. The vulnerability, dubbed CosmosEscape, was discovered with help from an artificial intelligence agent. Microsoft has patched the issue and said it found no evidence of exploitation beyond Wiz's own testing.
Key facts
- Wiz researchers found a single credential, named the Cosmos Master Key, that could list every account in a region and pull the primary key for any of them.
- The vulnerability is called CosmosEscape and was disclosed on Thursday.
- Microsoft has patched the flaw and says customers need to take no action.
- Wiz's research was assisted by Atlas, the company's AI vulnerability researcher.
Source: TNW | Anthropic News