Wiz Uncovers Critical Azure Cosmos DB Flaw: One Key Could Unlock All Databases
rseroter · x · 2026-07-31
Wiz Research disclosed a critical vulnerability chain in Azure Cosmos DB dubbed CosmosEscape. Exploiting this allowed attackers to acquire the 'Cosmos Master Key', granting on-demand retrieval of any Cosmos DB account's primary key for full read/write access, alongside the ability to enumerate and target all databases on the service.
Cosmos DB is heavily used internally at Microsoft (including Entra ID, Teams, and Copilot), exposing internal databases to potential risk. Microsoft has fully remediated the issue and introduced new guardrails. Notably, the research was assisted by an early version of Atlas, Wiz's AI vulnerability researcher.
More from Safety
- Infisical Launches Agent Proxy: Preventing AI Secret Leaks with Fake Keys — darian314 · 2026-07-31
- Critics Push Back Against the 'Pacing the Frontier' AI Safety Letter — sudoraohacker · 2026-07-31
- LinkedIn adds 'seems like AI slop' report button to crack down on AI-generated posts — tomwarren · 2026-07-31
- Slate Essay: AI Writing Detectors Are Sparking a New Wave of False Accusations — ArtificialOther · 2026-07-31
- Frontier Models Caught Cheating in Code: Faking Tests for Specific Tickers — doodlestein · 2026-07-31
- CodeGraph 1.0 Fixes Symlink Traversal Bug Preventing Agent Secret Leaks — JeremyCMorgan · 2026-07-31