A single crafted query was all it took. Security researchers at Wiz found a chain of bugs in Azure Cosmos DB, nicknamed CosmosEscape, that let an attacker break out of a sandboxed Gremlin query and reach a platform-wide key with full read and write access to databases belonging to other customers. Not their own tenant. Everyone’s. That’s the kind of finding that should make anyone responsible for cybersecurity in a multi-tenant cloud environment sit up straight, because the failure mode here wasn’t exotic. It was a shared credential sitting one privilege boundary away from a query engine that was supposed to be locked down.
Microsoft patched it before anyone (that we know of) exploited it in the wild. But the pattern behind CosmosEscape, a shared resource that turns one tenant’s bug into every tenant’s incident, showed up twice more this week in very different contexts. North Korea’s Lazarus Group is apparently handing its tooling and infrastructure to ransomware crews hitting South Korean targets. And a Chinese-speaking threat actor is running AI models to scan and exploit seven vulnerabilities at once, autonomously, with a human stepping in only for the manual finishing touches. Three stories, one thread: when infrastructure, tools, or access get shared, the blast radius of a single mistake stops being contained to a single victim.
One Gremlin Query Away From Every Tenant’s Data
The mechanics of CosmosEscape matter because they’re not unusual. Cosmos DB’s Gremlin API runs graph queries inside a sandbox meant to keep customer-supplied code from touching anything it shouldn’t. Wiz found a way to escape that sandbox and get code execution on the backend. From there, the researchers reached a platform-wide access key, a credential the service itself uses internally, that could read and write to databases across customer tenants, not just the one that submitted the malicious query.
Wiz described the exploit chain as beginning with nothing more than “a crafted query against a Gremlin database controlled by the attacker,” escalating from there to code execution and, ultimately, cross-tenant database access.
This is the recurring failure of multi-tenant cloud architecture: isolation that holds right up until one internal credential turns out to be broader than it needed to be. It echoes the confused-deputy patterns that have shown up repeatedly in Google Cloud and Azure this year, and it’s the same root cause behind plenty of on-prem breaches too, a service account or API key with more reach than the task in front of it requires. The specific product changes. The mistake doesn’t.

When Threat Actors Share Tools, Your Incident Isn’t Isolated Either
South Korean government agencies are now warning that Lazarus Group, the North Korean state hacking outfit best known for cryptocurrency heists and the Sony Pictures breach, appears to be sharing its tools and infrastructure with ransomware criminals. That’s a meaningful shift. State-backed operators historically guarded their tradecraft. Handing it off, whether for cash, leverage, or plausible deniability, means techniques built for espionage-grade patience and stealth are now showing up in crews optimized for speed and extortion.
Layer the AI angle on top and the picture gets worse before it gets better. Researchers at Unit 42 documented a Chinese-speaking threat actor using AI models to run autonomous scanning across seven separate vulnerabilities simultaneously, with a human operator picking up manual exploitation once the AI flags something promising. That’s not a novel exploit. It’s novel throughput. The same reconnaissance work that used to take a small team days now runs in parallel, unattended, around the clock.
Put those two stories next to CosmosEscape and the connective tissue is obvious: shared infrastructure, whether it’s a cloud platform’s internal key or a nation-state’s malware kit, multiplies consequences. A flaw that would have hit one target now potentially hits thousands. A toolkit built by one operator with deep resources now arms crews with none of that sophistication but all of that reach. Defense in depth stops being optional in that world; it’s the only thing standing between one bad actor’s access and your entire environment.
What Actually Reduces Your Exposure Here
None of this is unique to nation-states or hyperscale cloud vendors. The same principles apply whether you’re running a five-person shop or a regional hospital network, and most of them cost nothing but discipline.
- Audit every credential your services use internally, not just the ones your users touch. Look specifically for keys or accounts that have broader scope than the task in front of them.
- Rotate high-privilege keys on a schedule, not just after an incident. If a platform-wide credential exists anywhere in your stack, treat its rotation cadence as a first-class security control.
- Treat your firewall and edge controls as the first layer, not the only one. Brute-force protection and threat-protection tooling at the perimeter still matter, but they won’t catch a sandbox escape happening inside a service you trust.
- Build threat detection around behavior, not signatures. Autonomous AI-driven scanning doesn’t look like a single suspicious login; it looks like sudden, parallel probing across multiple weaknesses at once.
- Keep incident response playbooks current for third-party and vendor-hosted infrastructure, not just your own servers. If your cloud provider patches a CosmosEscape-style bug, you still need to know whether you were exposed before the fix landed.
- For internet-facing services handling authentication attempts, lightweight tools like IPBan Pro can help catch and block brute-force patterns automatically, freeing your team to focus on the harder problem of scoping internal credentials correctly.
Security hardening isn’t a one-time project you finish and move past. CosmosEscape got patched. The next platform-wide key sitting one bug away from every tenant’s data is already out there somewhere, in some service, waiting for someone to find it before the vendor does.
Sources
- Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
- North Korea’s Lazarus Group sharing tools with ransomware hackers, South Korean agencies warn
- Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
