Microsoft Exposed Cloud Database: Researchers, Cybersecurity Agency Urge Users to Change Digital Access Keys

Microsoft rapidly fixed the configuration mistake that would have made it easy for any Cosmos user to get into other customers' databases.

Advertisement
By Reuters | Updated: 30 August 2021 11:53 IST
Highlights
  • Wiz said Microsoft had worked closely with it on the research
  • Wiz declined to say how it could be sure earlier customers were safe
  • Wiz is founded by four veterans of Azure's in-house security team

Microsoft said it warned customers which had set up Cosmos access during the weeklong research period

Researchers who discovered a massive flaw in the main databases stored in Microsoft's Azure cloud platform on Saturday urged all users to change their digital access keys, not just the 3,300 it notified this week.

As first reported by Reuters, researchers at a cloud security company called Wiz discovered this month they could have gained access to the primary digital keys for most users of the Cosmos DB database system, allowing them to steal, change or delete millions of records.

Alerted by Wiz, Microsoft rapidly fixed the configuration mistake that would have made it easy for any Cosmos user to get into other customers' databases, then notified some users Thursday to change their keys.

Advertisement

In a blog post Friday, Microsoft said it warned customers which had set up Cosmos access during the weeklong research period. It found no evidence that any attackers had used the same flaw to get into customer data, it noted.

Advertisement

"Our investigation shows no unauthorized access other than the researcher activity," Microsoft wrote. "Notifications have been sent to all customers that could be potentially affected due to researcher activity," it said, perhaps referring to the chance that the technique had leaked from Wiz.

"Though no customer data was accessed, it is recommended you regenerate your primary read-write keys," it said.

Advertisement

The US Department of Homeland Security's Cybersecurity and Infrastructure Security Agency used stronger language in a bulletin Friday, making clear it was speaking not just to those notified.

"CISA strongly encourages Azure Cosmos DB customers to roll and regenerate their certificate key," the agency said.

Advertisement

Experts at Wiz, founded by four veterans of Azure's in-house security team, agreed.

"In my estimation, it's really hard for them, if not impossible, to completely rule out that someone used this before," said one of the four, Wiz Chief Technology Officer Ami Luttwak. At Microsoft he developed tools for logging cloud security incidents.

Microsoft did not give a direct answer when asked if it had comprehensive logs for the two years when the Jupyter Notebook feature was misconfigured, or had used another way to rule out access abuse.

"We expanded our search beyond the researcher's activities to look for all possible activity for current and similar events in the past," said spokesman Ross Richendrfer, declining to address other questions.

Wiz said Microsoft had worked closely with it on the research but had declined to say how it could be sure earlier customers were safe.

"It's terrifying. I really hope than no one besides us found this bug," said one of the lead researchers on the project at Wiz, Sagi Tzadik.

© Thomson Reuters 2021


Realme is retiring its “X” series. We discussed the new Realme GT 5G and GT Master Edition on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: Microsoft, Microsoft Azure
Advertisement

Related Stories

Popular Mobile Brands
  1. Cloudflare Is Down Again For the Second Time in Weeks: See Affected Sites
  2. ACT Fibernet Launches New Broadband Plans With Free OTT Subscriptions
  3. OnePlus 15R Surfaces on Benchmarking Site Ahead of India Launch
  4. Airtel Discontinues These Prepaid Recharge Packs in India
  5. Realme Says It Will Launch Two New Narzo Smartphones in India Soon
  6. Realme P4x 5G Review
  7. Motorola Edge 70 With Pantone's 2026 Colour, Swarovski Crystals Launched
  8. Motorola Edge 70 Will Launch in India Soon via This E-Commerce Platform
  9. HMD 101, HMD 100 With Built-In Radio Launched in India at These Prices
  10. Vivo S50 Colour Options, Key Features Surface Online Ahead of Launch
  1. Google's Year in Search 2025 Reveals Gemini 3, Nano Banana Pro and Other AI Search Features Launched in India 2025
  2. Motorola Edge 70 India Launch Teased; Flipkart Availability Confirmed: Expected Specifications, Features
  3. Google’s Year in Search 2025: Top Trending Topics in India—From Gemini to Squid Games
  4. Vivo S50 Colour Options, Key Features Surface Online; Could Launch in India as Vivo V70
  5. CFTC Clears Path for Spot Crypto Trading on Regulated Platforms for the First Time
  6. Realme 16 Pro+ 5G Colour Options, Memory Configurations Leaked Again; Tipped to Launch With 7,000mAh Battery
  7. Cloudflare Outage Blocks Access to Several Websites Including BookMyShow, SpaceX, Coinbase
  8. Samsung Galaxy S26 Series to Offer Built-In Support for Company's 25W Magnetic Qi2 Charger: Report
  9. Airtel Discontinues Two Prepaid Recharge Packs in India With Data Benefits, Free Airtel Xtreme Play Subscription
  10. Samsung Galaxy Phones, Devices Are Now Available via Instamart With 10-Minute Instant Delivery
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.