All Microsoft users need to change access keys
Researchers and cybersecurity authorities urge users of the cloud database to take action

Researchers discovered on Saturday a massive error in the key databases of Microsoft Corp.'s Azure cloud platform. (NASDAQ: MSFT) urged all users to change their digital access keys, not just the 3,300 notified this week. As first reported by Reuters, researchers for a cloud security company called Wiz discovered this month that they may have gained access to the primary digital keys of most users of the Cosmos DB database system, allowing them to steal millions of records, modify them or delete. Alerted by Wiz, Microsoft quickly fixed the configuration bug that would have made it easy for any Cosmos user to break into other customers' databases, and notified some users on Thursday to change their keys. In a blog post on Friday, Microsoft said it had warned customers who set up Cosmos access during the week-long investigation. No evidence was found that attackers used the same vulnerability to break into customer data, it said. "Our investigation found that there was no unauthorized access other than the researcher's activity," Microsoft wrote. "Notifications were sent to all customers who could potentially be affected due to the researcher's activities," it said, perhaps alluding to the possibility that Wiz's technology had leaked. "Although no customer data was accessed, it is recommended that the primary read / write keys be regenerated," it said. The US Department of Homeland Security's agency for cybersecurity and infrastructure security chose a sharper language in a bulletin on Friday and made it clear that it was not only addressing those affected. "The CISA strongly recommends the customers of Azure Cosmos DB to renew their certificate key", so the authority. Experts at Wiz, founded by four veterans of Azure's in-house security team, agreed. "I think it's really hard, if not impossible, for them to completely rule out anyone having used this before," said one of the four, Wiz chief technology officer Ami Luttwak. At Microsoft, he developed tools for logging security incidents in the cloud. Microsoft did not provide a direct answer to the question of whether it had comprehensive logs for the two years that the Jupyter Notebook feature was misconfigured or whether it had used any other method to rule out misuse of the access. "We have expanded our search beyond the researcher's activities to look for all possible activities for current and similar events in the past," said spokesman Ross Richendrfer and declined to answer any further questions. Wiz said Microsoft worked closely with him on the investigation but didn't want to say how it could be sure that previous customers would be safe. "It's terrifying. I really hope nobody but us found this bug," said Sagi Tzadik, one of the lead researchers on the project at Wiz.





