16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
It's 2 am. Do you know what your teen is doing?
A 16-year-old named Faav uncovered a critical security flaw in Microsoft's Titan analytics service. This flaw enabled him to bypass authentication and gain administrator access to databases containing approximately 17.3 trillion rows of data. Titan is an internal analytics platform, typically restricted to Microsoft employees. Faav utilized an AI-powered tool called Antares to locate an unsigned token that could access Titan's API via Azure Cloud Services.
He then changed the token's user principal name to "admin" and successfully executed SQL commands as an admin. Microsoft acknowledged the find, stating it led to enhanced security measures. Faav received a $5,000 reward for his discovery, which he made after 10 days of persistence and assistance from his AI bot.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.