// Alert

Microsoft Azure threat report

Wiz Research disclosed CosmosEscape, a critical vulnerability chain in Azure Cosmos DB's Gremlin API that allowed attackers to bypass network isolation controls and access arbitrary customer databases across tenants. The flaw stemmed from insufficient security restrictions in the custom Gremlin query engine, permitting .NET reflection techniques to achieve code execution on the DB Gateway and recover the platform-wide Cosmos Master Key, granting full read/write access to all Cosmos DB accounts globally. Microsoft has remediated the vulnerability, found no evidence of external exploitation, and stated no customer action is required.

// Get alerts for Microsoft Azure