41 min listen
Discovering ChaosDB, a critical vulnerability in the CosmosDB. [Research Saturday]
FromCyberWire Daily
Discovering ChaosDB, a critical vulnerability in the CosmosDB. [Research Saturday]
FromCyberWire Daily
ratings:
Length:
16 minutes
Released:
Dec 18, 2021
Format:
Podcast episode
Description
Guests Sagi Tzadik and Nir Ohfeld of cloud security company Wiz join Dave to discuss their research "ChaosDB: How we hacked thousands of Azure customers’ databases." Nearly everything we do online these days runs through applications and databases in the cloud. While leaky storage buckets get a lot of attention, database exposure is the bigger risk for most companies because each one can contain millions or even billions of sensitive records. Every CISO’s nightmare is someone getting their access keys and exfiltrating gigabytes of data in one fell swoop.
Database exposures have become alarmingly common in recent years as more companies move to the cloud, and the culprit is usually a misconfiguration in the customer’s environment. In this case, customers were not at fault.
The research can be found here:
ChaosDB: How we hacked thousands of Azure customers’ databases
ChaosDB: How to discover your vulnerable Azure Cosmos DBs and protect them
Database exposures have become alarmingly common in recent years as more companies move to the cloud, and the culprit is usually a misconfiguration in the customer’s environment. In this case, customers were not at fault.
The research can be found here:
ChaosDB: How we hacked thousands of Azure customers’ databases
ChaosDB: How to discover your vulnerable Azure Cosmos DBs and protect them
Released:
Dec 18, 2021
Format:
Podcast episode
More Episodes from CyberWire Daily
Dropbox sign breach exposes secrets. by CyberWire Daily