21.1 C
Dubai
Wednesday, November 27, 2024
spot_img

Microsoft warns of thousands of cloud customer databases exposed-News

[ad_1]

According to email copies and network security researchers, Microsoft warned thousands of its cloud computing customers on Thursday, including some of the world’s largest companies, that intruders may have the ability to read, change or even delete their main databases.

The vulnerability exists in Microsoft Azure’s flagship Cosmos DB database. A research team from the security company Wiz discovered that it can access the keys that control access to databases held by thousands of companies. Wiz CTO Ami Luttwak is the former CTO of Microsoft Cloud Security Group.

Since Microsoft cannot change these keys on its own, it sent an email to customers on Thursday telling them to create a new key. According to an email sent by Microsoft to Wiz, Microsoft agreed to pay Wiz $40,000 to discover the vulnerability and report it.

“We immediately fixed this issue to ensure our customers are safe and protected. We thank security researchers for their work in coordinating vulnerability disclosure,” Microsoft told Reuters.

Microsoft’s email to customers stated that there is no evidence that the vulnerability has been exploited. “We have no indication that external entities other than the researcher (Wiz) can access the master read and write keys,” the email said.

“This is the worst cloud vulnerability you can imagine. This is a long-standing secret,” Luttwak told Reuters. “This is Azure’s central database, and we can access any customer database we want.”

Luttwak said that Luttwak’s team discovered the problem called ChaosDB on August 9 and notified Microsoft on August 12.

The flaw exists in a visualization tool called Jupyter Notebook, which has been available for many years, but has been enabled by default in Cosmos since February. After Reuters reported the vulnerability, Wiz detailed the issue in a blog post.

Luttwak said that even customers who have not received Microsoft notice may have their keys stolen by attackers, allowing them to access them before they are changed. While Wiz was working on this issue, Microsoft this month only told customers that their keys were visible.

Microsoft told Reuters that “customers who may be affected have received our notice,” but did not elaborate.

This disclosure was made after months of bad security news from Microsoft. The company was attacked by the same group of suspected Russian government hackers that hacked SolarWinds and stole Microsoft source code. Then, while developing the patch, a large number of hackers broke into the Exchange email server.

A printer defect that allowed the computer to take over was recently fixed and must be repeated over and over again. Another Exchange vulnerability last week prompted the US government to urgently warn customers of the need to install a patch released a few months ago because ransomware gangs are now using it.

The Azure problem is particularly disturbing, because Microsoft and external security experts have been pushing companies to abandon most of their own infrastructure and rely on the cloud to improve security.

However, although cloud attacks are more rare, once they occur, they can be more destructive. More importantly, some have never been made public.

A research laboratory contracted by the federal government tracks all known security vulnerabilities in the software and ranks them by severity. Luttwak said, but there is no equivalent system for vulnerabilities in the cloud architecture, so many critical vulnerabilities have not yet been disclosed to users.




[ad_2]

Source link

Related Articles

Hatta Unveils World’s Largest Mosaic Artwork: The Majestic Zayed and Rashid Mural

Hatta Zayed and Rashid Mural Becomes the World’s Largest Mosaic Artwork In a remarkable celebration of art, history, and culture, Hatta, a picturesque mountain town...

UAE AI Awards: Sheikh Mohammed Celebrates Innovators Leading the Nation’s AI Transformation

UAE AI Award Winners: Paving the Way for Transformative Innovation in Business and Public Service Sheikh Mohammed bin Rashid Al Maktoum, the Vice President and...

UAE Operation ‘Chivalrous Knight 3’: Over 121 Aid Shipments Delivered to Gaza Amid Humanitarian Efforts

UAE has reinforced its dedication to humanitarian relief through the ongoing effort known as Operation ‘Chivalrous Knight 3.’   This initiative has seen the UAE dispatch...

With an eye towards its IPO on Nasdaq and Euronext, AAD Invest Group finalizes a EUR 75 million funding agreement with Global Emerging Markets...

AAD Invest Group finalizes a EUR 75 million funding agreement with Global Emerging Markets (GEM) About AAD Invest Group – Nov 2024 Founded in January 2024...

UAE Strengthens Global Ties: President Welcomes Qatari Prime Minister, While Crown Prince Leads at G20 in Brazil

UAE is making significant strides in strengthening its international relations, with recent diplomatic activities highlighting the country's growing influence on the global stage. In a...

Latest Articles