Seven things to know:
- The vulnerability is on Microsoft Azure’s Cosmos database. A security team at Wiz uncovered that a hacker could access keys that control access to the databases used by thousands of companies.
- Microsoft cannot change the keys itself and emailed its clients Aug. 26, telling them to create new keys. Microsoft paid Wiz $40,00 for finding the flaw and reporting it, according to an email Wiz shared with CNBC.
- Microsoft told its clients in an email that the vulnerability has been fixed, and there is no evidence indicating the flaw was exploited.
- Ami Luttwak is the chief technology officer at Wiz and the former chief technology officer at Microsoft’s Cloud Security Group.
- “This is the worst cloud vulnerability you can imagine. It is a long-lasting secret,” Mr. Luttwak said. “This is the central database of Azure, and we were able to get access to any customer database that we wanted.”
- Wiz uncovered the flaws Aug. 9 and notified Microsoft on Aug. 12.
- Microsoft has been connected to several cybersecurity flaws in the last few months. More than a thousand web apps that use Microsoft’s Power Apps portal service exposed 38 million records. A Windows print service flaw gave remote users access to execute code on client’s computer systems. Microsoft told its customers to refrain from printing until the vulnerability was fixed.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.