Wiz researchers found a single credential that could unlock every database running on Microsoft’s Azure Cosmos DB. They named it the Cosmos Master Key. And the vulnerability hunter that helped find it was not entirely human.
Microsoft has patched the flaw, disclosed on Thursday and dubbed CosmosEscape. It found no evidence anyone exploited it beyond Wiz’s own testing, and says customers need to do nothing, Reuters reported.
The scope was the alarming part. Cosmos DB is core Azure plumbing, and Microsoft services such as Teams, Entra ID and Copilot all store data in it. A working exploit could have listed every account in a region, then pulled the primary key for any of them. That grants full read and write access. The exposure reached Microsoft’s own internal databases, too.
Found with help from an AI
Buried in Wiz’s write-up is the detail that matters for where security is heading. The research “was assisted by an early version of Atlas,” the company’s AI vulnerability researcher. The same class of tool that broke into companies this month just helped find a master key to a flagship cloud.










