Teen's AI-Powered Discovery Exposes Critical Flaw in Microsoft Analytics Service
A 16-year-old security researcher discovered a critical authentication flaw in Microsoft's Titan analytics service. The vulnerability allowed him to gain administrator access and submit unauthorized SQL queries, potentially exposing sensitive data from databases containing an estimated 17.3 trillion rows.
The researcher, who used a bot called Antares to aid his investigation, found that the Titan API didn't verify the signature on login tokens, allowing him to bypass authentication checks. He was able to access platform metadata and query application tables directly.
Microsoft awarded the researcher a $5,000 bug bounty for his findings and promptly locked down the affected endpoint. The company appreciated the teen's discovery and coordinated vulnerability disclosure, stating it helped them harden their services and protect customers.