Insurance
Home›Insurance›Industry & Deals›Wiz finds Azure CosmosDB vulnerability that could have…
Wiz finds Azure CosmosDB vulnerability that could have compromised customers
Wiz said the now-patched flaw could have let hackers remotely compromise users across CosmosDB, which supports Microsoft services such as Teams and Copilot.
Alphabet-owned cybersecurity firm Wiz said it identified a sweeping vulnerability in Microsoft’s Azure CosmosDB that could have allowed a hacker to remotely compromise CosmosDB users, according to a post on its website.
Wiz said the issue has been patched, but it noted that CosmosDB is a core pillar of Microsoft’s cloud offering and is used by companies to store data powering services including chatbots, web applications, and online retail recommendation engines.
The company also said Microsoft relies on CosmosDB for its own services, including Microsoft Teams and Copilot. Microsoft did not disclose how many customers could have been affected, and Wiz said it could have exposed thousands of customers.
Wiz described the finding as the latest in a series of Azure CosmosDB vulnerabilities, including a similar CosmosDB issue it found in 2021, and it said researchers had previously warned that comparable flaws could enable mass compromise before patching. A NetSpi executive said CosmosDB has heavy usage and can contain sensitive data, while cautioning that findings like this occur periodically across cloud services, the Insurance Journal reported.