Urgent.News

What's breaking now, across thousands of outlets.

Tech

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service's Gremlin query sandbox and obtain full read and write access to databases across customer tenants, according to Wiz. Wiz, which codenamed the chain CosmosEscape, said the exploit chain began with a crafted query against a Gremlin database controlled by the attacker. From there, code execution on a

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

Read the original at thehackernews.com →

More in Tech

Security updates for Thursday

Security updates have been issued by AlmaLinux (gstreamer1-plugins-bad-free, libtiff, libXfont2, nodejs:22, nodejs:24, and rest), Debian (expat and nss), Fedora (libssh, nginx, nginx-mod-brotli…

  • Multiple Linux distributions released security updates on Thursday
  • Updates addressed vulnerabilities in packages like gstreamer1-plugins-bad-free and libtiff
  • Aimed at improving security and stability of affected software

[$] Reconsidering O_CREAT|O_DIRECTORY

Linux provides a system call ( mkdir() ) to create a directory, and a few variants of open() that can open a directory. There is, however, no system call in Linux that can create and open a directory…

More from Thursday 30 July →