16-year-old teenager discovers a vulnerability within Microsoft using AI involving over 17 trillion rows of data; awarded a $5,000 bounty
The Block
47m ago
Ai Focus
16-year-old security researcher Faav discovered a vulnerability in Microsoft's internal analysis platform Titan using a self-developed AI robot, claiming to be able to access approximately 17.3 trillion data records, and ultimately received a $5,000 bounty from Microsoft for the vulnerability. Microsoft expressed its gratitude for his coordinated disclosure and stated that it will continue to place emphasis on security research under the vulnerability bounty program.
Helpful
No.Help

News from IT on September 28: 16-year-old security researcher Faav posted a blog on his homepage on September 25 local time, revealing how he discovered a vulnerability within Microsoft and received a bounty of $5,000 (Note from IT: The current exchange rate is approximately 33,597 RMB).

He discovered that there was an authentication vulnerability in Microsoft's internal analysis platform Titan. Hackers could exploit this vulnerability to access an internal database containing approximately 25,000 employee data records and were able to query a total of 17.3 trillion data records.

According to Faav, he has been participating in vulnerability bounty programs since the age of 15 and developed the AI robot as well as Antares. On August 25, 2026, Antares discovered the publicly available API interface of Titan. This interface indicated a need to connect to VPN. Subsequently, Faav had Antares enumerate related subdomains, identifying a host located in a Azure cloud environment, and found the corresponding Swagger / OpenAPI files.

This document lists 4 API routes. Three of them require Azure Active Directory authentication, but the last interface, named “/ v2 / Query”, does not have this requirement and supports direct submission of SQL queries.

Faav still needs to understand the database structure. He used Wayback Machine to find a snapshot of the login page from 2023, Titan, and obtained from it the Apache Superset configuration file (which describes the database structure and contains definitions for 56 data tables in total).

Antares then spent 10 days probing the JWT verification process. Subsequently, Faav discovered that although the "/ v2 / Query" interface required JWT authentication, the server did not appear to be verifying the digital signature of the token. Subsequently, based on the server's response, he forged a login token with alg as none and an empty signature field. After changing upn to admin, he successfully executed SQL as an administrator.

In the early hours of September 5th, he confirmed that he had access to the database of the Titan platform. Queries revealed that its metadata contained approximately 25,000 account and email records, 17,990 employee email records, 15,001 employee organization records, as well as 355 database configurations, 20,979 virtual datasets defined by SQL, 24,569 dashboards, and 425,891 charts.

After further inspection, he also discovered a set of data sources related to the analysis of Bing in the database. By summarizing the number of records from multiple data tables, Faav estimated that the scale of data he could access amounted to 17,333,335,124,315 entries.

Faav indicates that when he discovered this number at 2 a.m., in order not to wake his parents, he had to restrain the urge to shout it out loud. Subsequently, he began to draft a report and submitted it to Microsoft MSRC.

From September 6th to 8th, Microsoft requested him to stop testing and provide the address IP to confirm that there were no activities beyond the scope of security research. On September 9th, that interface API was immediately locked down.

On September 17th, Microsoft awarded a bounty of $5,000 (approximately 33,597 RMB at the current exchange rate) to Faav. On September 22nd, the two parties met to discuss the vulnerability and coordinate its disclosure. Faav stated that Microsoft had edited the article before posting it on their blog, removing some content and adjusting the description of the impact.

Microsoft stated in a statement, "We appreciate the opportunity to investigate the findings reported in Faav. The submission and coordination of vulnerability disclosures have helped us better protect our customers and enhance our services." Microsoft emphasized that the company will continue to place importance on security research under its vulnerability bounty program.

Tip
$0
Like
0
Save
0
Views 12
WalletJYS reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Strategy Invests $142.7 Million in Bitcoin, Setting a New High for Holdings at BTC
Strategy purchased 1,665 bitcoins between September 21 and September 27, spending $142.7 million, which raised its total bitcoin holdings to a record 847,666. The company also repurchased $151.7 million worth of STRC preferred stocks and disclosed holding assets of $6.02 billion as of September 27.
Decrypt
·2026-09-28 21:23:16
4
US Stock Outlook | Trump Rejects Cease-Fire Proposal, Oil Prices Rise and Stock Index Futures Fall; NVIDIA Launches AI Security System and Announces $150 Billion in Share Repurchases
Before the market opened on Monday, due to Trump's rejection of Iran's ceasefire proposal, oil prices rose and geopolitical risk premiums soared, causing weakness in the three major U.S. stock index futures. NVIDIA announced the AI security platform and increased its repurchase authorization by $150 billion; Microsoft upgraded its Copilot; Oracle's "force majeure" notice triggered fluctuations in the bond market. The market also focused on PCE, non-farm payroll data, and the Federal Reserve's policy path for October.
The Block
·2026-09-28 21:23:11
3
HelloNation: Retirement Planning Experts Katy Ridge Discuss Whether Life Insurance is Still Needed After Retirement
An article from HelloNation states that Cornerstone Insurance's retirement planning expert, Katy Ridge, believes that the role of life insurance changes after the age of 65, but it is still meaningful for many retirees. It can be used to cover expenses after death, support estate planning, or leave a gift for family members.
PR Newswire
·2026-09-28 21:23:09
5
MongoDB Announces the Handover of CEO
MongoDB announced that Chirantan, who held the position of CJ, has immediately resigned from his role as President and Chief Executive Officer to join Meta Platforms in a senior position. The Board of Directors appointed CEO Dev Ittycheria as the interim President and Chief Executive Officer, and reaffirmed the company's confidence in the guidance for the third quarter and the full year of fiscal year 2027.
PR Newswire
·2026-09-28 21:13:21
9
Newmark Appoints Mike Whitaker as the Group Chief Information Officer
Newmark Group, Inc. Announces the appointment of Mike Whitaker as the Group Chief Information Officer, who will report to the Chief Operating Officer Luis Alvarado and work closely with the Chief Strategy Officer Kyle Lutnick to advance the company's technology, data, and information strategies. Whitaker will also join the company's Executive Committee.
PR Newswire
·2026-09-28 21:13:19
11
View More