chiprook
← Security
SecurityOctober 1, 2026, 01:29

16-year-old researcher found Microsoft Titan auth flaw, got admin access to 17.3 trillion rows

A 16-year-old researcher known as Faav found that Microsoft's Titan analytics service never verified JWT signatures, letting him forge an admin token and reach analytics databases with an estimated 17.3 trillion rows. Microsoft locked down the API and paid him a $5,000 bug bounty.

16-year-old researcher found Microsoft Titan auth flaw, got admin access to 17.3 trillion rows
#Microsoft#Titan#Azure
Read next
Security

Teenager finds open Microsoft database with 17 trillion rows

Security

Three Artifactory flaws under active exploitation allow auth bypass and admin access

Software

Microsoft Azure CTO ports 20-year-old Windows tool to macOS with AI in two days

Security

Man spent two years hunting fake LinkedIn jobs, got 60,000 removed