Award Banner
Award Banner

Microsoft warns thousands of cloud customers of exposed databases

Microsoft warns thousands of cloud customers of exposed databases
This latest disclosure comes after months of bad security news for Microsoft.
PHOTO: Reuters file

SAN FRANCISCO - Microsoft on Thursday (Aug 26) warned thousands of its cloud computing customers, including some of the world's largest companies, that intruders could have the ability to read, change or even delete their main databases, according to a copy of the email and a cyber security researcher.

The vulnerability is in Microsoft Azure's flagship Cosmos DB database. A research team at security company Wiz discovered it was able to access keys that control access to databases held by thousands of companies. Wiz Chief Technology Officer Ami Luttwak is a former chief technology officer at Microsoft's Cloud Security Group.

Because Microsoft cannot change those keys by itself, it emailed the customers Thursday telling them to create new ones. Microsoft agreed to pay Wiz US$40,000 (S$54,000) for finding the flaw and reporting it, according to an email it sent to Wiz.

"We fixed this issue immediately to keep our customers safe and protected. We thank the security researchers for working under coordinated vulnerability disclosure," Microsoft told Reuters.

Microsoft's email to customers said there was no evidence the flaw had been exploited. "We have no indication that external entities outside the researcher (Wiz) had access to the primary read-write key," the email said.

“This is the worst cloud vulnerability you can imagine. It is a long-lasting secret,” Luttwak told Reuters. “This is the central database of Azure, and we were able to get access to any customer database that we wanted.”

Luttwak's team found the problem, dubbed ChaosDB, on Aug 9 and notified Microsoft on Aug 12, Luttwak said.

The flaw was in a visualisation tool called Jupyter Notebook, which has been available for years but was enabled by default in Cosmos beginning in Feb. After Reuters reported on the flaw, Wiz detailed the issue in a blog post.

Luttwak said even customers who have not been notified by Microsoft could have had their keys swiped by attackers, giving them access until those keys are changed. Microsoft only told customers whose keys were visible this month, when Wiz was working on the issue.

Microsoft told Reuters that "customers who may have been impacted received a notification from us", without elaborating.

The disclosure comes after months of bad security news for Microsoft. The company was breached by the same suspected Russian government hackers that infiltrated SolarWinds, who stole Microsoft source code. Then a wide number of hackers broke into Microsoft Exchange email servers while a patch was being developed.

Read Also
digicult
Microsoft uncovers new breach while investigating SolarWinds hackers

A recent fix for a printer flaw that allowed computer takeovers had to be redone repeatedly. Another Exchange flaw last week prompted an urgent US government warning that customers need to install patches issued months ago because ransomware gangs are now exploiting it.

Problems with Azure are especially troubling, because Microsoft and outside security experts have been pushing companies to abandon most of their own infrastructure and rely on the cloud for more security.

But though cloud attacks are more rare, they can be more devastating when they occur. What's more, some are never publicised.

A federally contracted research lab tracks all known security flaws in software and rates them by severity. But there is no equivalent system for holes in cloud architecture, so many critical vulnerabilities remain undisclosed to users, Luttwak said.

homepage

trending

trending
    Eleanor Lee's former assistant confesses to editing audio clip that landed actress in controversy
    'We apologise for the operational lapse': NUS responds to backlash over disposal of Yale-NUS books
    'Global problems require global solutions': PM Wong stresses world coordination to tackle future health challenges
    Lady Gaga visits Maxwell Food Centre, signs fan's vinyl record
    SCDF rescues trapped driver from car following accident involving lorry along CTE
    'I told him not to be too ruthless': Mark Lee responds to Addy Lee's fallout with Quan Yi Fong
    'One reckless moment can destroy a life': Pet owner appeals to cyclists after hit-and-run leaves dog injured
    No joke: Bangkok condo resident releases snakes in corridor to protest neighbour's noisy dog
    Ex-Mediacorp actress Le Yao condemns Ian Fang: 'You want the benefits from the limelight but don't set strict standards for yourself?'
    New theme park to open in Japan's Okinawa this July offering scenic treks, hot air balloon rides and more
    We head to China to check out how Singapore's top-selling car brand intends to transform the automotive industry
    We check out Hiap Joo Bakery's new vending machine selling its famous banana cake

Singapore

Singapore
    • SQ321 incident: One year on, passengers recall how extreme turbulence upended their lives
    • More than 3,000 new jobs in rail, bus sectors to be added to support expansion: Chee Hong Tat
    • Some monkeys trapped in Punggol last year euthanised due to 'aggressive' behaviour: NParks
    • Beach Road slashing: Man pleads guilty to attempted murder of wife in 2022
    • Daily roundup: Poultry supply in Singapore not affected by bird flu outbreak in Brazil, supermarkets say — and other top stories today
    • Singaporean Amos Yee's parole from US jail delayed after he violated terms of release
    • Singaporean Malone Lam charged in US for orchestrating $340m crypto theft
    • Poultry supply in Singapore not affected by bird flu outbreak in Brazil, supermarkets say
    • 'Thankful for the neighbourliness': MP Cai Yinzhou on resident who alerted others to Toa Payoh flat fire
    • 'I will serve with conviction and integrity': WP's Eileen Chong and Andre Low on being elected NCMPs

Entertainment

Entertainment
    • Babymonster, Gigi Leung, Elva Hsiao and other stars spotted at Lady Gaga's Singapore concerts
    • 'Sorry for bad drawing': Yim Si-wan plays games with Singapore fans, shares South Korea travel tips
    • 'Gaslighted the victim': Judge sentences actor Ian Fang to 40 months' jail for sex with 15-year-old
    • Gossip mill: Wife of veteran Hong Kong actor Ai Wai dies of liver disease, Kwon Yul announces wedding, Shinee's new single has same name as late Jonghyun's final album
    • Scandal-ridden Mickey Huang and actress wife Summer Meng said to have divorced
    • David Beckham says receiving a knighthood would be an 'unbelievable honour'
    • Violet Affleck was stuck in a hotel room arguing with her mother Jennifer Garner during the California wildfires
    • Stolen memorial bust of Jim Morrison found
    • Gordon Ramsay annoyed daughter is 'getting taught to cook' by someone else
    • Dropout Kings lead singer Adam Ramey dies aged 32

Lifestyle

Lifestyle
    • Back with a bang: Burgs ends 2-year hiatus with new standalone restaurant at Arab Street
    • 'You asked, we listened': Don Don Donki brings back plastic bags
    • Furry capabara EVs, self-driving mini bar, and more - here are the wackiest cars we saw at Auto Shanghai 2025
    • Heiress Kim Lim 'disappointed' after finding Chanel bag she sold for charity listed on Carousell
    • Cat A COE premiums remain above $100k despite slight dip in second bidding for May 2025
    • Singapore's beef kway teow ranks 18th in best stir-fried dishes list, Indonesia's sambal goreng takes crown
    • 7 toilet door ideas for all types of spaces
    • Things to do in Nagoya, Japan: A cultural guide to arts, music and markets
    • Inside Balmoral Park: Rare freehold landed homes with 1.6 plot ratio in District 10
    • Why we chose a walk-up apartment (yes, with no lift) for our first home

Digicult

Digicult
    • World's best Dota 2 teams to compete for $1m prize pool in Singapore in November
    • A $500 wake-up call: How the Samsung Galaxy Ring made me realise my stress
    • Monster Hunter Wilds producer explains how game has remained unique and fresh over 20 years
    • Google Pixel 9a: The best AI-centric phone under $800 in 2025?
    • Western intelligence agencies warn spyware threat targeting Taiwan, Tibetan rights advocates
    • Taiwan says China using generative AI to ramp up disinformation and 'divide' the island
    • Russian court fines Telegram app for refusal to remove anti-government content, TASS reports
    • One Beijing man's quest to keep cooking — and connecting with Americans — on camera
    • Nintendo Switch 2 to launch in June with US$449.99 price tag
    • Games in April: RPGs, racing and Ronaldo in a fighting game

Money

Money
    • Wall Street equity indexes close higher after US-China tariff truce
    • Giant deal: Malaysian company to acquire Cold Storage and Giant supermarket chains in Singapore
    • HDB BTO July 2025 review: Locations, resale, values, amenities and more
    • Selling your condo? This overlooked factor could quietly undercut your selling price
    • Using a personal loan for a used car purchase: What you need to know
    • 6 prime HDB shophouses for sale at $73m in Singapore: A look inside the rare portfolio
    • Croatia's Game of Thrones filming sites face threat from Trump tariffs
    • A new high in Choa Chu Kang: $690k for a 4-room flat
    • SIA rewards staff with over 7 months' bonus after record $2.8b full-year profit
    • Apec warns of tariff impact on trade as members seek deals with US

Latest

Latest
  • 'Our children are dying slowly', says father searching for food in Gaza 
  • Ukraine to ask EU to lead on Russia sanctions as US wavers
  • Iran parliament approves strategic pact with Russia
  • EU agrees to lift economic sanctions on Syria, Kallas says
  • Trump Organisation to break ground on golf club in Vietnam amid trade talks 
  • Philippines, US hold joint maritime drills in South China Sea
  • Cheers actor George Wendt dies aged 76
  • US Justice Department investigating former New York governor Cuomo, sources say
  • Iran faces US without Plan B as nuclear red lines collide 

In Case You Missed It

In Case You Missed It
  • 'Only one chance at life': Chinese student, 18, misses exam to save classmate suffering heart attack
  • Baby suspected to have been eaten by monitor lizard in Thailand, only head found
  • 'Dog will return soon': GE2025 independent candidate Jeremy Tan wants to contest again
  • Ong Ye Kung leads PAP team to victory while elder brother Howard Ong loses in Australia's election on the same day
  • Tan Kiat How weighs in on viral video of Gan Kim Yong being ignored by passers-by in Punggol
  • PSP's Tan Cheng Bock turns 85; SDP's Paul Tambyah joins celebration at Teban Gardens
  • PM Wong urges voters to 'choose leaders of good character' in PAP's first party political broadcast
  • It is 'important for Singapore's democracy' that WP wins more seats, says Pritam in election broadcast
  • GE2025: PSP, RDU, SDP, PPP, PAR, NSP promise to push for policy changes if elected to Parliament in first political broadcast
This website is best viewed using the latest versions of web browsers.