Microsoft’s cloud services had recently been hit with a security flaw that had the potential to expose thousands of businesses before it was caught and fixed. Alphabet-owned cybersecurity company Wiz has revealed that it discovered a major vulnerability in Azure Cosmos DB, Microsoft’s cloud database service used by organisations around the world to store critical data and run digital services. According to the researchers, the flaw could have allowed hackers to remotely gain access to customer databases if it had been exploited. Microsoft says the issue has now been patched and that its investigation found no evidence of customer data being compromised. Even so, the discovery has once again raised fresh questions about the security of cloud infrastructure that powers everything from business applications to Microsoft’s own products.
The vulnerability was discovered by Wiz, the Alphabet-owned cybersecurity company known for identifying major cloud security issues. The company said the flaw existed in Azure Cosmos DB, a core Microsoft cloud database service that is widely used by businesses across industries.
Microsoft confirmed that it worked with Wiz to fix the issue and said the vulnerability has been fully addressed. The company added that it found no signs that the flaw had been exploited or that any customer had been affected before the patch was rolled out.
Although Microsoft did not disclose how many users could have been at risk, Azure Cosmos DB is considered one of the key building blocks of its cloud platform. Thousands of businesses depend on the service to store and process data for websites, mobile applications, chatbots and online recommendation systems. Microsoft also relies on Cosmos DB for services including Teams and Copilot.
Wiz Chief Technology Officer Ami Luttwak said developers building applications on Microsoft’s cloud platform often use Cosmos DB, making the vulnerability especially significant because of its wide reach.
The latest discovery is not the first time Wiz has flagged a major issue involving Cosmos DB. In 2021, the company uncovered another flaw that researchers warned could have led to large-scale exposure of customer data before it was fixed.
Also read: Google Pixel 10 price drops by over Rs 14,000 ahead of Pixel 11 launch: How to grab this deal
Security experts said the latest finding highlights the risks of weaknesses in widely used cloud platforms. Karl Fosaaen, Senior Vice President at NetSPI, noted that Cosmos DB frequently stores sensitive information, making any security flaw a major concern. Vaisha Bernard, co-owner of Eye Security, said similar high-severity vulnerabilities have recently been found across cloud infrastructure providers and warned that this flaw could have caused serious damage if attackers had discovered it before Wiz.