
Alphabet-owned cybersecurity firm Wiz has uncovered a critical vulnerability in Microsoft’s Azure Cosmos DB service that could have exposed thousands of cloud customers to remote cyberattacks before it was patched.
According to Wiz, the flaw affected Azure Cosmos DB, one of Microsoft’s core cloud database services used to store data for applications such as chatbots, web services, online retail platforms, and recommendation engines. The company said the vulnerability could have allowed attackers to remotely compromise customer databases if exploited.
Microsoft confirmed that the issue has been fully resolved in collaboration with Wiz and said its investigation found no evidence that customers were affected.
Although Microsoft did not disclose how many users could have been at risk, Azure Cosmos DB is widely used by thousands of organizations worldwide and also supports several Microsoft services, including Teams and Copilot.
Wiz Chief Technology Officer Ami Luttwak described Cosmos DB as a foundational component of Microsoft’s cloud ecosystem, noting that many cloud-based applications rely on the service.
Cybersecurity experts said the vulnerability highlights the growing risks associated with cloud infrastructure. Karl Fosaaen, Senior Vice President at cybersecurity firm NetSpi, said Cosmos DB is frequently used to store sensitive information, making the flaw particularly significant, although he noted that similar vulnerabilities are periodically discovered across major cloud platforms.
Vaisha Bernard, co-owner of Dutch cybersecurity company Eye Security, said researchers have recently identified an increasing number of high-severity vulnerabilities affecting cloud infrastructure providers. He warned that if malicious actors had discovered the Cosmos DB flaw before it was patched, it could have resulted in widespread damage.
The discovery follows a series of previous cloud security issues involving Microsoft. Wiz identified another major Azure Cosmos DB vulnerability in 2021, while a separate flaw discovered last year by independent researcher Dirk-jan Mollema also raised concerns over the potential compromise of Microsoft cloud accounts before it was fixed.-ERMD/TS
READ MORE
SK Hynix Considers Major Memory Chip Plant in Japan
South Korean chipmaker SK Hynix is considering building a large-scale memory chip manufacturing plant in…
Sindh, Zong Parent CMPak Agree to Develop AI-Ready Data Centre in Karachi
The Sindh government and CMPak, the parent company of Zong, have agreed to collaborate on…
New CoolClient Malware Variant Targets Organizations Across Asia and Russia
A new variant of malware capable of giving cyber attackers remote access to compromised systems…
PTA, Google Partner to Boost Child Online Safety in Pakistan
The Pakistan Telecommunication Authority (PTA) and Google LLC have signed a Memorandum of Understanding (MoU)…
Five Decades of Excellence: The Journey of Engr. Wasim Nazir
Engr. Wasim Nazir reflects on five decades of professional excellence, leadership, and lifelong learning, sharing…
China Showcases Next Generation of Robots at 2026 World Robot Conference
China opened the 2026 World Robot Conference in Beijing on Aug 19, showcasing a wide…
