Ethical Hacking News
A 16-year-old researcher has discovered a critical vulnerability in Microsoft's Titan analytics service, exposing 17.3 trillion rows of data to unauthorized access. The discovery highlights the importance of verifying signatures in authentication checks and showcases the growing power of AI-powered tools in security research.
A 17.3 trillion rows of data in Microsoft's Titan analytics service were exposed to unauthorized access due to a critical vulnerability.A 16-year-old researcher, Faav, discovered the bug using an AI-powered tool, Antares, and gained administrative access to the database.The vulnerability was found through testing the service's JSON Web Token authentication checks and email-formatted user principal names.The bug allowed Faav to access sensitive data, including employee job titles, departments, and management hierarchy.Microsoft took immediate action, locking down the endpoint and awarding Faav a $5,000 bug bounty for his work.The incident highlights the importance of secure coding practices and the growing power of AI-powered tools in security research.
A recent revelation has shed light on a critical vulnerability in Microsoft's Titan analytics service, exposing a massive 17.3 trillion rows of data to unauthorized access. A 16-year-old researcher, Faav, discovered this bug through an AI-powered tool, Antares, and subsequently gained administrative access to the database. This remarkable incident has highlighted the importance of verifying signatures in authentication checks, a crucial aspect of security.
The story began on August 25, when Antares found the public API of Microsoft's Titan service. Faav and his AI-powered tool then began testing the service's JSON Web Token (JWT) authentication checks and email-formatted user principal names (UPNs). After 10 days of trial and error, they finally found an unsigned token that could bypass the authentication checks. This breakthrough came after Faav rewrote his blog post at Microsoft's request, cutting sections and numbers, and rewording the impact prior to publication.
The vulnerability allowed Faav to change the unsigned token's UPN to admin, which then resolved to local user ID 1, granting him admin access to the database. This access enabled him to query application tables directly and access sensitive data, including employee job titles, departments, and management hierarchy. The metadata contained approximately 25,000 account and email records, 17,990 employee email records, 15,001 employee organization records, 355 database configurations, and 20,979 virtual-dataset SQL definitions.
Moreover, Faav discovered 30 active routing values, which pointed to backend configurations containing one or more databases. These configurations resolved to 17 connected analytics databases spanning 9,863 unique table names. The total number of data rows in these databases is estimated to be around 17.3 trillion, a staggering figure that highlights the significance of this vulnerability.
Microsoft took immediate action upon discovering the bug, locking down the endpoint and requesting Faav's IP address to confirm no nefarious activity beyond the bug bounty research. Faav was awarded a $5,000 bug bounty for his work on the vulnerability. This incident serves as a reminder of the importance of secure coding practices and the need for developers to verify signatures in authentication checks.
The incident also underscores the growing power of AI-powered tools in security research. Faav's use of Antares, his AI-powered tool, played a crucial role in discovering the vulnerability. This collaboration between human researchers and AI-powered tools will likely become more prevalent in the future, as the two work together to uncover and address security vulnerabilities.
In conclusion, Faav's breakthrough has exposed a critical vulnerability in Microsoft's Titan analytics service, revealing the importance of verifying signatures in authentication checks. The incident highlights the growing power of AI-powered tools in security research and the need for developers to adopt secure coding practices.
Related Information:
https://www.ethicalhackingnews.com/articles/A-16-Year-Olds-Breakthrough-Unveiling-the-Unseen-Vulnerability-in-Microsofts-Titan-Analytics-Service-ehn.shtml
https://www.theregister.com/security/2026/09/30/16-year-old-researcher-found-a-microsoft-bug-got-admin-access-to-databases-with-173-trillion-rows/5300240
Published: Wed Sep 30 14:24:58 2026 by llama3.2 3B Q4_K_M