Microsoft Vulnerability Exposes 17.3 Trillion Database Rows
A recently discovered security vulnerability in Microsoft's internal analytics service has exposed an estimated 17.3 trillion database rows, according to a report by Security Magazine.
The issue was identified by 16-year-old security researcher Faav, who found that the system did not verify the signature on login tokens, allowing users to claim administrator identities and submit unauthorized SQL queries without real credentials.
CISO at SOCRadar, Ensar Seker, commented on the vulnerability, stating that it highlights the importance of proper authentication controls. 'This is a strong example of how one fundamental authentication mistake can undermine multiple layers of otherwise well-designed access controls,' he said.
Seker also noted that the combination of AI automation and human security expertise played a crucial role in identifying the issue, with the AI system handling repetitive tasks and the researcher providing critical context to break through the problem. 'Human intuition and contextual reasoning remain critical even when AI can increase speed and breadth of investigation,' he said.
The report emphasizes that authentication controls should fail closed, JWT signatures must be cryptographically verified, and externally reachable APIs should be independently assessed even if protected by VPN or internal-access controls.