16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
It's 2 am. Do you know what your teen is doing?
A 16-year-old researcher named Faav discovered a critical authentication flaw in Microsoft's Titan analytics service, which allowed him to gain admin access and potentially access databases containing approximately 17.3 trillion rows of data. Titan is an internal analytics platform, and Redmond only grants access via its web interface to its employees.
Utilizing an AI hackbot called Antares, Faav found that he could access Titan's API through an Azure Cloud Services host, bypassing Titan's authentication checks that did not validate the signature of login tokens. Microsoft promptly addressed the issue by securing the API and compensated Faav with a $5,000 bug bounty for his findings.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.