An Azure Flaw Exposed a Platform-Wide Key & Russian Actors Survive Credential Rotation (07/30/2026)

July 30, 2026
An Azure Flaw Exposed a Platform-Wide Key & Russian Actors Survive Credential Rotation (07/30/2026)
Key Intel / TL;DR
  • Wiz disclosed CosmosEscape, a now-patched Azure Cosmos DB chain that escaped the Gremlin query sandbox and exposed a platform-wide key granting read and write access to databases across customer tenants.
  • Russian actors previously tied to the Zimbra campaign are exploiting a Microsoft Outlook Web Access flaw to retain mailbox access even after victims rotate credentials.
  • A state-sponsored campaign compromised trusted South Korean websites to abuse locally installed AnySign4PC financial-security software and install SIGNBT or COPPERHEDGE backdoors without user prompts.
  • Silver Fox used a three-driver bring-your-own-vulnerable-driver chain against a Japanese industrial manufacturer to deploy ValleyRAT.
  • Hidden instructions in a Word document can make Microsoft 365 Copilot alter figures in a report and copy those same instructions into the output file.

Two stories today undercut assumptions most security programs rely on. A cloud database flaw briefly put a key in reach that would have unlocked other customers’ data, which is the failure mode multi-tenancy is supposed to make impossible. And a Russian group found a way to stay in mailboxes after the victim did the one thing every playbook says to do first, which is change the passwords.

Top 5 Critical Security Alerts

1. An Azure Cosmos DB Flaw Exposed a Platform-Wide Key

Wiz disclosed CosmosEscape, a now-patched vulnerability chain in Azure Cosmos DB that let an attacker escape the service’s Gremlin query sandbox and obtain a platform-wide key granting full read and write access to databases across customer tenants (The Hacker News). Tenant isolation is the promise the entire managed-database model rests on, and a single key that crosses it means the boundary you are trusting was one bug away from not existing.

Operator Note: You cannot patch your provider’s platform, and you can limit what a cross-tenant compromise reaches. Encrypt sensitive fields with keys you hold, keep your most regulated data on the smallest possible footprint, and make sure your logging would show a read you did not initiate.

2. Russian Actors Keep Mailbox Access After Credential Rotation

The Russian actors recently tied to the Zimbra campaign are now exploiting a Microsoft Outlook Web Access flaw against government, telecommunications, and financial targets in the US and Europe, retaining mailbox access even after victims rotate credentials (The Hacker News, The Register). Password resets are the first move in nearly every response plan, so a persistence mechanism that outlives them means a team can complete its checklist and still be compromised.

Operator Note: After a mailbox compromise, rotating the password is step one and it is not eviction. Revoke active sessions and refresh tokens, audit mailbox rules and delegate permissions, and re-enroll multi-factor authentication, because the access that survives a reset is the access nobody looked for.

3. Compromised Korean Sites Abuse Security Software to Plant Backdoors

South Korean authorities and four security firms disclosed a state-sponsored campaign that compromised trusted domestic websites and used them to exploit locally installed AnySign4PC financial-security software, infecting targeted visitors with SIGNBT or COPPERHEDGE backdoors with no user prompt (The Hacker News). Security software runs with high privilege and is trusted by design, which makes it the ideal thing to turn against the user when an attacker can reach it from a site the user already trusts.

4. Silver Fox Runs a Three-Driver BYOVD Chain

The Chinese cybercrime group Silver Fox used a chain of three vulnerable drivers in a bring-your-own-vulnerable-driver attack against a Japanese industrial manufacturer, ultimately deploying ValleyRAT for persistent remote access (The Hacker News). BYOVD works because the attacker brings a legitimately signed driver with a known flaw, so the operating system loads it willingly and the resulting kernel access sits underneath most endpoint protection.

5. Copilot for Word Propagates Hidden Instructions

Håkon Måløy disclosed that hidden instructions inside a Word document can make Microsoft 365 Copilot rewrite figures in a report and copy those same instructions into the finished file, 144 days after reporting it to Microsoft (The Hacker News). A document that alters your numbers and carries its own instructions forward is a self-replicating problem, and the output looks like ordinary work product produced by a trusted assistant.

Additional Security Alerts

Threat Intelligence

  • Amazon Ties the debug and chalk npm Hijack to North Korea: Amazon linked the September 2025 compromise of the widely used npm packages debug and chalk to North Korea’s Sapphire Sleet, reframing an incident that sat in the record for ten months as crypto theft. The Hacker News, The Record
  • Lazarus Tooling Shows Up in Ransomware Attacks: South Korean agencies warn that tools and infrastructure used by North Korea’s Lazarus Group appear to be shared with ransomware crews targeting South Korean organizations. The Record

Security Breaches & Incidents

  • Extortionists Claim 600,000 Records From the UK Department for Education: Criminals are attempting to extort Britain’s Department for Education after claiming to take more than 600,000 pieces of data including names, email addresses, and phone numbers. The Record

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)