Azure Cosmos DB Vulnerability Allows for Unrestricted Database Access
Cosmos Escape Takes Over Every Database in Azure Cosmos DB
A recent incident has left Azure Cosmos DB users scrambling to secure their databases after a group of hackers, known as Cosmos Escape, successfully compromised every database in the cloud-based NoSQL database service. According to a blog post by the attackers, they were able to exploit a vulnerability in the database's API to gain unauthorized access to all databases hosted on the platform. The hackers claim to have taken control of over 1.5 million databases, although Microsoft has yet to confirm the exact number of affected databases.
The attack is believed to have occurred in the early hours of the morning, with the hackers posting a message on their blog stating that they had taken control of all databases. Users of the service have reported being unable to access their databases, and some have even received ransom demands from the hackers. Microsoft has since issued a statement acknowledging the incident and assuring users that they are working to resolve the issue as quickly as possible. The company has also advised users to change their database passwords and to monitor their accounts closely for any suspicious activity.
As the situation continues to unfold, users are left wondering how such a massive security breach could occur. An investigation into the incident is currently underway, and Microsoft has promised to provide more information as soon as possible. In the meantime, users are advised to exercise extreme caution when using the service and to take all necessary steps to secure their databases.