Cloud security firm Wiz disclosed CosmosEscape, a critical vulnerability in Microsoft Azure Cosmos DB that chained multiple flaws to obtain the platform-wide Cosmos Master Key, enabling attackers to escape the Gremlin query sandbox, execute code on shared infrastructure, and access any customer database including datastores for Microsoft services such as Entra ID, Teams, and Copilot.
Topics #
Sources #
- Press
Go deeper #
This intelligence is sourced automatically from public sources across the web and synthesised by the Prefactor AI pipeline. Stories are reviewed before publication.