Sunday, July 13, 2025
News
  • Home
  • Politics
  • Business
  • Culture
  • Opinion
  • Health
  • Sports
  • Technology
No Result
View All Result
News
Home Technology

EXCLUSIVE Microsoft warns thousands of cloud customers of exposed databases

vwdhfgeyug by vwdhfgeyug
August 28, 2021
in Technology
0
EXCLUSIVE Microsoft warns thousands of cloud customers of exposed databases
0
SHARES
3
VIEWS
Share on FacebookShare on Twitter


SAN FRANCISCO, Aug 26 (Reuters) – Microsoft (MSFT.O) on Thursday warned hundreds of its cloud computing clients, together with a few of the world’s largest corporations, that intruders may have the flexibility to learn, change and even delete their essential databases, in line with a duplicate of the e-mail and a cyber safety researcher.

The vulnerability is in Microsoft Azure’s flagship Cosmos DB database. A analysis group at safety firm Wiz found it was in a position to entry keys that management entry to databases held by hundreds of corporations. Wiz Chief Expertise Officer Ami Luttwak is a former chief expertise officer at Microsoft’s Cloud Safety Group.

Related posts

New technology to track the spread of water contaminants in the blink of an eye

New technology to track the spread of water contaminants in the blink of an eye

October 21, 2022
DOD describes need for IT-rich facility management support – Washington Technology

DOD describes need for IT-rich facility management support – Washington Technology

October 21, 2022

As a result of Microsoft can’t change these keys by itself, it emailed the purchasers Thursday telling them to create new ones. Microsoft agreed to pay Wiz $40,000 for locating the flaw and reporting it, in line with an e-mail it despatched to Wiz.

“We fastened this concern instantly to maintain our clients secure and guarded. We thank the safety researchers for working below coordinated vulnerability disclosure,” Microsoft instructed Reuters.

Microsoft’s e-mail to clients mentioned there was no proof the flaw had been exploited. “We’ve got no indication that exterior entities outdoors the researcher (Wiz) had entry to the first read-write key,” the e-mail mentioned.

“That is the worst cloud vulnerability you’ll be able to think about. It’s a long-lasting secret,” Luttwak instructed Reuters. “That is the central database of Azure, and we had been in a position to get entry to any buyer database that we needed.”

Luttwak’s group discovered the issue, dubbed ChaosDB, on Aug. 9 and notified Microsoft Aug. 12, Luttwak mentioned.

A Microsoft brand is pictured on a retailer within the Manhattan borough of New York Metropolis, New York, U.S., January 25, 2021. REUTERS/Carlo Allegri

The flaw was in a visualization device referred to as Jupyter Pocket book, which has been obtainable for years however was enabled by default in Cosmos starting in February. After Reuters reported on the flaw, Wiz detailed the issue in a weblog put up.

Luttwak mentioned even clients who haven’t been notified by Microsoft may have had their keys swiped by attackers, giving them entry till these keys are modified. Microsoft solely instructed clients whose keys had been seen this month, when Wiz was engaged on the problem.

Microsoft instructed Reuters that “clients who might have been impacted acquired a notification from us,” with out elaborating.

The disclosure comes after months of dangerous safety information for Microsoft. The corporate was breached by the identical suspected Russian authorities hackers that infiltrated SolarWinds, who stole Microsoft source code. Then a large variety of hackers broke into Trade e-mail servers whereas a patch was being developed.

A current repair for a printer flaw that allowed pc takeovers needed to be redone repeatedly. One other Trade flaw final week prompted an urgent U.S. government warning that clients want to put in patches issued months in the past as a result of ransomware gangs at the moment are exploiting it.

Issues with Azure are particularly troubling, as a result of Microsoft and out of doors safety specialists have been pushing corporations to desert most of their very own infrastructure and depend on the cloud for extra safety.

However although cloud assaults are extra uncommon, they are often extra devastating once they happen. What’s extra, some are by no means publicized.

A federally contracted analysis lab tracks all recognized safety flaws in software program and charges them by severity. However there isn’t a equal system for holes in cloud structure, so many important vulnerabilities stay undisclosed to customers, Luttwak mentioned.

Reporting by Joseph Menn; Enhancing by William Mallard

Our Requirements: The Thomson Reuters Trust Principles.



Source link

Previous Post

Big-play Knights leave Timberwolves behind | Sports – Huntington Herald Dispatch

Next Post

Intelligence Review Yields No Firm Conclusion on Origins of Coronavirus

Next Post
Intelligence Review Yields No Firm Conclusion on Origins of Coronavirus

Intelligence Review Yields No Firm Conclusion on Origins of Coronavirus

RECOMMENDED NEWS

BLCK Press starts St. Paul newsroom, works to change media culture – Twin Cities

BLCK Press starts St. Paul newsroom, works to change media culture – Twin Cities

3 years ago

technology innovation dimension – Bits&Chips

3 years ago
Marshall Memo: Teaching Technology, Resources for Families and a Parade | News, Sports, Jobs

Influence and Politics | News, Sports, Jobs – Wheeling Intelligencer

3 years ago
New Lawsuit alleges NC sheriff made arrest for political reasons

New Lawsuit alleges NC sheriff made arrest for political reasons

3 years ago

FOLLOW US

  • 139 Followers
  • 87.1k Followers
  • 196k Subscribers

BROWSE BY CATEGORIES

  • Business
  • Culture
  • Health
  • Opinion
  • Politics
  • Sports
  • Technology

POPULAR NEWS

Plugin Install : Popular Post Widget need JNews - View Counter to be installed

Recent News

  • Craft Beer Week celebrates the culture of a growing industry
  • Banks to pay as Hungary extends scheme to cap loan rates
  • Stephen A. Smith ripping Knicks’ culture is back
  • Business as usual in BVA blowout – The Mon Valley Independent
  • How To Escape From Hustle Culture And Regain Work-Life Balance

Category

  • Business
  • Culture
  • Health
  • Opinion
  • Politics
  • Sports
  • Technology

Follow us on social media:

Contact Us

Loading
  • About Us
  • Contact Us
  • Privacy & Policy

© 2021 Copyright N The News

No Result
View All Result
  • Home
  • Politics
  • Business
  • Culture
  • Opinion
  • Health
  • Sports
  • Technology

© 2021 Copyright N The News