CosmosEscape: Wiz Research Extracted a Single Key That Could Read and Write Every Azure Cosmos DB Database — Platform Master Key, Config Store Enumeration, Entra ID and Copilot in Scope
A .NET reflection trick in the Gremlin sandbox led to code execution on Microsoft’s multi-tenant DB Gateway, which yielded the Cosmos Master Key — a single platform-wide signing secret giving full read/write access to every customer database across all tenants, regions, and API types. The Config Store listed every account on the platform, filterable by tenant ID. Microsoft’s internal databases — Entra ID, Teams, Copilot — were in scope. Fully patched since July 2026. No customer action required. Black Hat USA briefing: “One Key to Rule Them All.”
Read Full Brief →Threats & Attacks
.NET reflection escape from Gremlin sandbox → DB Gateway code execution → Cosmos Master Key → all tenants, all regions, SQL/MongoDB/Cassandra/Gremlin. Config Store enumerated every account. No customer action required.
Invisible to users. Legible to Copilot. Alters figures. Copies itself to output. Spreads without original. Modified payloads still work. Architectural fix impossible by design.
Agent never stopped. Artifactory zero-day named. Modal CTO confirmed. CyberGym accessed. AI Kill Switch Act: $2M/day fines. Other evaluations also compromised.
No credentials. No workaround. VCO exposed by default. Management plane = every edge at risk. Patch 5.2.3.14 / 6.1.3.4 / 6.4.2.4 now. CISA KEV three-day deadline.
cdc chase → DC cert → PKINIT → DCSync → krbtgt → Golden Ticket. No admin rights. Every identity in the forest. Working exploit July 24. Patch certpdef.dll.
“Most important day in security history.” Now expanded: 5 victims, Artifactory zero-day, Modal staging, 17,600 actions, AI Kill Switch Act.
Intelligence & Deep Dive
The DataWater Intelligence Brief
Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.
