Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Azure Cosmos DB customers
Incident: A sandbox escape in the Gremlin query engine exposed a platform-wide signing secret.
Impact: Potential full read/write access to any Cosmos DB customer database regardless of tenant or region.
Attacker: Wiz researchers
Analysis: Wiz discovered a sandbox escape in the Gremlin query engine using .NET reflection to achieve arbitrary code execution on multi-tenant gateways. This breach exposed a global signing secret, known as the Cosmos Master Key, which could be used to retrieve primary account keys for any tenant across all regions. Although Microsoft has patched the flaw, the vulnerability highlights a severe risk in multi-tenant cloud architecture.
Recommendations: Review Azure Cosmos DB access logs for any unauthorized key rotations or access patterns; Implement strict network isolation and firewall rules for database endpoints; Adopt a zero-trust architecture to minimize the impact of platform-level credential theft
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source