A teenager, known as Faav, gained unauthorized access to Microsoft's internal Titan analytics platform. This platform contained a vast amount of data, including 17 trillion data rows and records for 25,000 Microsoft employees. The access was achieved by exploiting several security weaknesses within the system.
Faav identified an endpoint URL in Titan that initially indicated a VPN requirement. Further investigation revealed an Azure Cloud host subdomain with a Swagger/OpenAPI file. This file exposed a /v2/Query route that did not require Azure Active Directory authentication and accepted raw SQL queries. Additionally, Faav discovered that the server was not properly validating the digital signature of JSON Web Tokens (JWTs), allowing him to bypass authentication by forging an administrator token.
Faav utilized an AI orchestrator bot named Antares to automate the scanning and identification of security vulnerabilities. After finding the vulnerable endpoint, he used the Wayback Machine to locate a 2023 version of a login page, which included an Apache Superset configuration file detailing the database schema with 56 table definitions. This information was crucial in formulating the SQL queries to access the data.
Upon gaining access, Faav was able to view 25,000 employee records, organizational data, dashboards, and charts. He also found a data source for Bing analytics, where he tallied up rows across tables to confirm access to 17 trillion records. This incident demonstrates a significant lapse in security for an internal Microsoft system, exposing sensitive company and user data.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A teenager named Faav discovered a vulnerability in Microsoft's internal Titan analytics platform, allowing access to 17 trillion data rows and 25,000 employee records. The vulnerability stemmed from an unauthenticated API endpoint that accepted raw SQL queries and a flaw in JWT signature validation. This incident highlights significant security oversights in internal Microsoft systems.