Teenage Hacker Exposes 17 Trillion Records via Microsoft Analytics Flaw
A teenage security researcher discovered a significant vulnerability in Microsoft's analytics service, Titan. The flaw allowed him to access over 17 trillion records without proper authentication.
The researcher, Faav, used an AI-powered hacking tool he built, Antares, to bypass login errors and gain administrative rights on 17 connected databases. He exploited the fact that Titan did not verify login token signatures, allowing him to execute raw SQL queries.
According to Ensar Seker, CISO at SOCRadar, this case highlights the importance of combining automation with human security expertise. The AI system handled repetitive tasks, while Faav's intuition and contextual reasoning led to the breakthrough.