0
Deep & Emerging Tech·July 30, 2026·1 min read

Wiz says a now-patched flaw in Azure CosmosDB would have let a hacker remotely compromise any of its users; Microsoft has seen "no evidence of customer impact"

Share

A single Cosmos DB flaw that could have exposed any tenant is a reminder that cloud concentration creates correlated security risk, even when patches land quickly. If you’re on managed databases, revisit blast-radius assumptions and make sure your own detection and backup plans don’t assume the provider is infallible.

Deep & Emerging Tech

Amazon researchers link the compromises of four npm packages, including axios, over the past 18 months to the North Korea-linked group tracked as Sapphire Sleet

Four compromised npm packages over 18 months—via social engineering of maintainers—reinforces that your software supply chain risk now includes upstream humans, not just code. Lock down dependency policies, pin and mirror critical packages, and assume popular OSS components are active targets for state-linked actors.