16-year-old's AI-assisted bug hunt exposed 17.3 trillion Microsoft records via unsigned token

rez0__ · x · 2026-09-26

16-year-old bug bounty researcher Faav disclosed that a Microsoft internal analytics service never validated login token signatures, leaving an estimated 17.3 trillion stored rows reachable by forging an admin identity and submitting unauthorized SQL queries. No customer data was touched; Microsoft fixed the flaw, thanked Faav, and held editorial control over the write-up. Notably, the lead originally came from Antares, his personal AI hackbot, with the human finishing verification ten days later.

Original post →

More from Safety

Safety channel →