16-Year-Old Hacker Exposes Massive Microsoft Vulnerability Using AI Tool

A 16-year-old security researcher uncovered a critical authentication vulnerability in Microsoft's Titan service using an AI tool, accessing 17 trillion data rows.

Geektime•Author: Oshri Alkasslasi
Source •
16-Year-Old Hacker Exposes Massive Microsoft Vulnerability Using AI Tool
Photo: Geektime / © Simon Lehmann| Dreamstime.com

A 16-year-old security researcher using an AI-based tool has discovered a major vulnerability in Microsoft's internal analytics service, gaining unauthorized access to over 17 trillion rows of data.

The young researcher, known online as Faav, identified a flaw in the authentication mechanism of Microsoft's Titan analytics service. The weakness allowed him to obtain administrator privileges, run SQL queries, and access a massive database containing 17,333,335,124,315 rows of data. Although Microsoft provides employee access to the tool via a web interface, Faav utilized a custom AI-driven hacking tool to reach the Titan API through Azure Cloud Services by exploiting a missing token signature validation.

"It was 2 AM," the researcher wrote in a blog post. "I wanted to scream, or at least say something out loud, but my parents were sleeping."

Discovery and Responsible Disclosure

The vulnerability was investigated over an 11-day period from August 25 to September 5. Upon changing a vulnerable username to admin, Faav discovered he had been granted full management privileges due to the system's failure to verify connection tokens.

Instead of exploiting the flaw maliciously, Faav reported the issue to Microsoft. The tech giant promptly patched the vulnerability and awarded him a $5,000 bug bounty. Microsoft praised the responsible disclosure, stating it helped harden their services and protect customers.

Related News