PaymentsJournal
No Result
View All Result
SIGN UP
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
PaymentsJournal
  • Commercial
  • Credit
  • Debit
  • Digital Assets & Crypto
  • Digital Banking
  • Emerging Payments
  • Fraud & Security
  • Merchant
  • Prepaid
No Result
View All Result
PaymentsJournal
No Result
View All Result

Are Your Neighbors Sneaking Into Your Database on Azure?

By Tim Sloane
June 2, 2022
in Analysts Coverage, Fraud & Security, Security
0
0
SHARES
0
VIEWS
Share on LinkedIn
Are Your Neighbors Sneaking Into Your Database on Azure?

Are Your Neighbors Sneaking Into Your Database on Azure?

Cross-tenant cloud security vulnerabilities demonstrate the potential risks created when multiple organizations share infrastructure from the same cloud service provider. A flaw that allows one tenant to access another tenant’s data or resources can dramatically increase the potential impact of a security breach, turning a single vulnerability into a threat to many organizations simultaneously.

The discovery of vulnerabilities affecting Microsoft Azure services, including Cosmos DB, raised important questions about cloud architecture and the security controls needed to maintain isolation between customers. As organizations increasingly move sensitive data and critical applications to public cloud environments, preventing cross-tenant access is essential to maintaining confidence in cloud computing.

In 2021, a security company found it could access all the data held by other companies that used the Microsoft Cosmos DB service. This cross-tenant hack enables one tenant on the shared Azure service to access resources used by other tenants, sort of like drilling a hole in your wall to spy on your neighbors. But once discovered, it got worse:

“But the stunning finding made researchers at Wiz and several other vendors curious to find out how prevalent this new class of cross-tenant vulnerability actually is. That led to the discovery of another scary bug in an Azure service a month later. Then another. Then three more — for a total of six critical Azure vulnerabilities in as many months.

Including ChaosDB, five of the critical vulnerabilities demonstrated the possibility of breaching large numbers of different cloud environments, or tenants, in one fell swoop. A cross-tenant flaw like ChaosDB is “the most severe vulnerability that could be found in a cloud service provider,” said Shir Tamari, head of Research at Wiz.

The Wiz research team was not out looking for this type of vulnerability, and only found ChaosDB by accident, Tamari said. The finding was a revelation to researchers that this type of issue is even possible in the public cloud, he said.

Security researchers would go on to discover a pair of critical vulnerabilities in AWS too. But the lion’s share of the most severe vulnerabilities over the past year have been found in Azure, researchers say. To some security researchers and industry analysts, this series of issues raises questions about Microsoft’s approach to securing its Azure services.”

Perhaps building a cloud service platform out of servers designed for single companies made the security issues harder for Microsoft to wrangle versus the multiple server structure preferred by AWS? 

The potential scale of cross-tenant cloud security vulnerabilities makes them particularly concerning for businesses relying on public cloud infrastructure. Strong tenant isolation is fundamental to the cloud model, and vulnerabilities capable of bypassing those boundaries can potentially expose multiple customers through a single security flaw.

The discoveries involving Azure also highlight the importance of continued security research as cloud platforms become more complex. Organizations adopting cloud services must consider not only their own cybersecurity controls but also how effectively providers protect the underlying shared infrastructure and isolate customer environments from one another.

Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group

0
SHARES
0
VIEWS
Share on LinkedIn
Tags: AmazonAWSCloudData BreachMicrosoftMicrosoft AzureSecurity

    Get the Latest News and Insights Delivered Daily

    Subscribe to the PaymentsJournal Newsletter for exclusive insight and data from Javelin Strategy & Research analysts and industry professionals.

    Must Reads

    upi biometric

    Beyond Authentication: Rethinking Digital Identity Security

    September 11, 2026
    Fraud Monitoring, Nacha ACH Rules

    Nacha’s Upcoming Rules Refresh Is All About Improving Clarity

    September 10, 2026
    instant payments for financial institutions

    Why Haven’t More Financial Institutions Adopted Instant Payments?

    September 9, 2026
    complex debit

    Regulation, Economics, and Technology: The Complex World of Debit

    September 8, 2026
    agentic commerce

    Biometrics Are Here. Agentic Payments Aren’t—Yet.

    September 4, 2026
    swift cross-border

    P2P Payments Have Changed How Consumers Move Money. What’s Next?

    September 3, 2026
    holiday prepaid

    The Holiday Gift Card Outlook: Why Repeat Buyers Matter Most

    September 2, 2026
    co-branded debit cards

    A New Generation of Consumers Is Changing the Role of Debit Cards

    September 1, 2026

    Linkedin-in X-twitter
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Commercial
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Digital Banking
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter
    • About Us
    • Advertise With Us
    • Sign Up for Our Newsletter

    ©2026 PaymentsJournal.com |  Terms of Use | Privacy Policy

    • Commercial Payments
    • Credit
    • Debit
    • Digital Assets & Crypto
    • Emerging Payments
    • Fraud & Security
    • Merchant
    • Prepaid
    No Result
    View All Result