Teen Researcher Uncovers Critical Flaw in Microsoft's Titan Analytics Service
A 16-year-old security researcher discovered a significant authentication vulnerability in Microsoft's internal Titan analytics service. The flaw allowed unauthorized access to sensitive data and administrative functions.
The researcher, known as Faav, identified a weakness in Titan's API that bypassed signature verification on login tokens. With the aid of an AI tool named Antares, Faav gained administrator privileges and submitted unauthorized SQL queries, potentially accessing 17.3 trillion rows of data stored in analytics databases.
The vulnerability stemmed from Titan's failure to validate the signature of JSON Web Tokens, despite checking other token components. Although the service is restricted to Microsoft employees, the exploit could have exposed employee records, organizational data, and Bing analytics information.