0
Deep & Emerging Tech·July 30, 2026·1 min read

Wiz’s AI bug-hunter helped find a master key to every database in Azure Cosmos DB

Share

AI-augmented security just found a single credential that could unlock every Azure Cosmos DB instance—offense at this scale means your cloud data blast radius is larger than you think. Treat AI-powered vuln discovery as the new baseline and recheck assumptions about key management, tenant isolation, and third-party access this week.

Deep & Emerging Tech

Amazon researchers link the compromises of four npm packages, including axios, over the past 18 months to the North Korea-linked group tracked as Sapphire Sleet

Four compromised npm packages over 18 months—via social engineering of maintainers—reinforces that your software supply chain risk now includes upstream humans, not just code. Lock down dependency policies, pin and mirror critical packages, and assume popular OSS components are active targets for state-linked actors.