ChaosDB: How we hacked thousands of Azure customers’ databases
ID: f07c7ad4-cdac-5143-aedf-e048ab65b717
STIX ID: report--f07c7ad4-cdac-5143-aedf-e048ab65b717
Feed Name: Wiz Blog
Wiz security researchers disclosed “ChaosDB,” a critical flaw in Azure Cosmos DB’s Jupyter Notebook feature that allowed trivial exploitation to harvest customers' long-lived primary keys and gain full read/write/delete access to databases across thousands of Cosmos DB accounts (including large enterprises). Microsoft quickly disabled the vulnerable notebook capability and notified affected customers to rotate keys, but the issue may have been exploitable for months and could have exposed large-scale sensitive data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
