Microsoft Shares Guidance on Securing Azure Accounts

Share post:

Microsoft recently released some recommendations for securing Azure Cosmos DB accounts.

Microsoft presented several recommendations, including regenerating Cosmos DB keys, using a combination of firewall rules, vNet and/or Azure Private Link for all Azure Cosmos DB customers. They also recommended using Role-Based Access Control that allows per user and security principal access control to Azure Cosmos DB and, finally, implementing regularly scheduled key changes in case users cannot use Role-Based Access Control.

The warning became needed after a bug known as Chaos DB affected Microsoft Azure Cosmos DB.

The bug granted attackers full admin rights to user data without authorization and allowed users to steal their customers’ primary read-write keys, giving them the power to remotely take over their databases.

In addition to the various recommendations, Microsoft also added additional security measures to prevent future attempts to gain access to its customers’ Cosmos DB accounts without authorization.

For more information, read the original story in Bleeping Computer.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways