Site icon WinCert

Microsoft warns its customers about Azure cloud vulnerabilty

<p>Microsoft has just warned several thousand of its Azure customers about vulnerability that left their data completely exposed to possible hacker attacks for the last two years&period;<&sol;p>&NewLine;<p><img class&equals;"alignnone size-full wp-image-4317" src&equals;"https&colon;&sol;&sol;www&period;wincert&period;net&sol;wp-content&sol;uploads&sol;2021&sol;08&sol;chip-6517875&lowbar;640&period;jpg" alt&equals;"" width&equals;"640" height&equals;"419" &sol;><&sol;p>&NewLine;<p>A flaw that was discovered in Microsofts&&num;8217&semi; Azure Cosmos database product has opened unrestricted access to more than 3&comma;300 Azure customers&comma; including many from the Fortune 500 list&period;<&sol;p>&NewLine;<p>This vulnerability was introduced back in 2019 when Microsoft added a data visualization feature named &&num;8220&semi;Jupyter Notebook to Cosmos DB&&num;8221&semi;&period; Sadly&comma; this feature was turned on by default for all Cosmos database users in February 2021&period;<&sol;p>&NewLine;<p>This is the worst cloud vulnerability that you can imagine&comma; said Ami Luttwak who is a chief technology officer at Wiz&comma; the company that discovered this vulnerability&period; Ami also said that Microsofts&&num;8217&semi; Azure Cosmos DB is actually the central database of Azure and that they were able to access any company database they wanted&period;<&sol;p>&NewLine;<p>Despite the high severity and risk involved&comma; Microsoft did not find any evidence about illicit data access or that the vulnerability was exploited by malicious actors&period; Microsoft has also rewarded the Wiz company with &dollar;40&comma;000 for this discovery&period;<&sol;p>&NewLine;<p>Microsoft has disabled the vulnerability within 48 hours after they have received the report from Wiz&period; Microsoft also advised its customers to change their primary access keys in order to mitigate this exposure and additionally protect their data&period;<&sol;p>&NewLine;

Exit mobile version