Wiz’s AI Bug-Hunter Uncovers Master Key to Azure Cosmos DB
Wiz researchers discovered a single credential, dubbed the Cosmos Master Key, that granted access to every database running on Microsoft’s Azure Cosmos DB. This vulnerability has since been patched.
The Discovery
On July 30, 2026, Wiz revealed that their AI vulnerability researcher, Atlas, assisted in finding this master key. The discovery highlighted the potential of AI in cybersecurity, as Atlas outperformed other models like Mythos Preview from Anthropic and GPT-5.5 Cyber from OpenAI.
Microsoft’s Response
Microsoft acknowledged the issue but assured customers that no exploitation had been found beyond Wiz’s testing. They emphasized that no action is required from users.
The Scope of the Vulnerability
The concern lay in the fact that Azure Cosmos DB is core Azure infrastructure, supporting services like Teams, Entra ID, and Copilot. A successful exploit could have compromised every account within a region, accessing primary keys for full read and write access.
The Future of AI in Cybersecurity
Wiz’s achievement showcases the potential of collaborative AI models, combining smaller models with larger ones to enhance performance. They plan to integrate Google’s Gemini Flash Cyber into their system next. Microsoft is also developing its own hybrid model, MDASH, which splits tasks between red and green teams for efficient vulnerability discovery and patching.
Considerations and Caveats
While these advancements are promising, several factors temper the excitement:
- Benchmarks vs. Reality: Benchmark scores are vendor-reported and may not accurately reflect real-world performance.
- Cost and Availability: Atlas is currently not available for sale; it operates within Wiz, and there’s a cost problem associated with deploying cutting-edge models in production.
- Continuous Evolution: The AI cybersecurity landscape is constantly evolving, with new scores and discoveries emerging regularly.