Critical Vulnerability in Cosmos DB Affects Microsoft Azure Customers

Critical Vulnerability in Cosmos DB Affects Microsoft Azure Customers

Microsoft Azure customers have been informed of a newly found critical bug in Cosmos DB that enables intruders to remotely take control over databases by giving them complete admin access with no authorization requested. Anyone can read, change, or delete databases as they please, according to Microsoft. What Happened? This month, cybersecurity researchers at the…

Microsoft warns Azure customers of critical Cosmos DB vulnerability

Microsoft warns Azure customers of critical Cosmos DB vulnerability

Microsoft has warned thousands of Azure customers that a now-fixed critical vulnerability found in Cosmos DB allowed any user to remotely take over other users’ databases by giving them full admin access without requiring authorization. Azure Cosmos DB is a globally distributed and fully managed NoSQL database service used by high-profile customers, including Mercedes Benz, Symantec,…

Microsoft Issues Security Advisory on ProxyShell Flaws

Microsoft Issues Security Advisory on ProxyShell Flaws

Governance & Risk Management , Patch Management Alert Urges Organizations to Patch as Vulnerabilities Are Exploited Doug Olenick (DougOlenick) • August 27, 2021     Four months after Microsoft released the first security update for three vulnerabilities in several versions of its on-premises Exchange Server software – collectively called ProxyShell – the company has issued…

Failing to Meet Cybersecurity Standards Can Have Legal Consequences

Failing to Meet Cybersecurity Standards Can Have Legal Consequences

Cybercrime is one of the most significant threats facing companies today. With the average cost of a data breach reaching an all-time high of $4.24 million, the business case for cybersecurity has never been stronger. Still, some businesses seem to misunderstand the urgency of meeting current cybersecurity standards. It may help to consider the legal…

Boston Public Library discloses cyberattack, system-wide technical outage

Boston Public Library discloses cyberattack, system-wide technical outage

The Boston Public Library (BPL) has disclosed today that its network was hit by a cyberattack on Wednesday, leading to a system-wide technical outage. BPL serves almost 4 million visitors per year through its central library and twenty-five neighborhood branches, as well as millions more online.  It is the third-largest public library in the United States behind the…

179th AW selected as location for ANG’s first Cyber Warfare Wing > Air National Guard > Article Display

179th AW selected as location for ANG’s first Cyber Warfare Wing > Air National Guard > Article Display

MANSFIELD, Ohio – The Department of the Air Force announced yesterday it has identified Ohio’s Mansfield-Lahm Air National Guard Base as the preferred location for a new Cyber Warfare Wing mission. The transformation will support Air Combat Command’s future requirements and result in operational mission changes, including an increase of approximately 175 Airmen and associated…

Researchers, cyber security agency urge action by Microsoft cloud database users – Cloud – Security

Researchers, cyber security agency urge action by Microsoft cloud database users – Cloud – Security

Researchers who discovered a massive flaw in the main databases stored in Microsoft’s Azure cloud platform have now urged all users to change their digital access keys, not just the 3300 it notified this week. Researchers at a cloud security company called Wiz discovered this month they could have gained access to the primary digital…

Mansfield selected as U.S. Air Force’s preferred site for new cyber warfare wing

Mansfield selected as U.S. Air Force’s preferred site for new cyber warfare wing

The following article was originally published in the Ohio Capital Journal and published on News5Cleveland.com under a content-sharing agreement. The U.S. Air Force announced Wednesday the Mansfield Air National Guard Base, home of the 179th Airlift Wing, has been selected as the preferred site for the Air National Guard’s first Cyber Warfare Wing. “This selection…

Azure Cosmos DB remote takeover bug affects thousands of organisations – Security

Azure Cosmos DB remote takeover bug affects thousands of organisations – Security

Security researchers have found a long-standing vulnerability in the Azure Cosmos DB fully managed non-structured query language database, which allows attackers to remotely take over the information store with a trivial exploit. Named ChaosDB, the vulnerability gives any Azure user full administrative access to other customers’ Cosmos DB instances, security vendor Wiz Research Team said….