DHS urges Microsoft customers to update Azure to avoid security flaw
The Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency is urging Microsoft cloud customers to reset their security keys in light of a recent vulnerability that may have exposed customer data. The flaw, discovered by researchers at Wiz, would have allowed any customer using Microsoft’s Azure Cosmos database to read, write and delete another user’s information without authorization. Cosmos DB is used by thousands of organizations, including Coca-Cola, Exxon Mobil and a number of other Fortune 500 companies. “Although the misconfiguration appears to have been fixed within the Azure cloud, CISA strongly encourages Azure Cosmos DB customers to roll and regenerate their certificate keys and to review Microsoft’s guidance on how to secure access to data in Azure Cosmos DB,” CISA wrote in an alert Friday. Microsoft reported in a blog Friday that it contacted customers who had the Azur Cosmos feature that contained the vulnerability activated during the […]
The post DHS urges Microsoft customers to update Azure to avoid security flaw appeared first on CyberScoop.
Continue reading DHS urges Microsoft customers to update Azure to avoid security flaw