16-year-old's AI-assisted bug hunt exposed 17.3 trillion Microsoft records via unsigned token
rez0__ · x · 2026-09-26
16-year-old bug bounty researcher Faav disclosed that a Microsoft internal analytics service never validated login token signatures, leaving an estimated 17.3 trillion stored rows reachable by forging an admin identity and submitting unauthorized SQL queries. No customer data was touched; Microsoft fixed the flaw, thanked Faav, and held editorial control over the write-up. Notably, the lead originally came from Antares, his personal AI hackbot, with the human finishing verification ten days later.
More from Safety
- User accuses Superwhisper of silently switching local voice transcription to cloud after update — brandon_xyzw · 2026-09-26
- Tesla fans petition Norway to approve FSD now, bypassing EU committee vote — lasas · 2026-09-26
- Memory backups may resurrect revoked agent permissions across AIs — tallmetommy · 2026-09-26
- AI safety debate: the movement will never look respectable to average Americans, and that's fine — repligate · 2026-09-26
- Three OpenAI security stories break in one hour: user photos leaked online, HF agents hoarded 'LOOT' — EthanJPerez · 2026-09-26
- Someone received an AI deepfake ad of themselves — HN discusses what to do — pavel_lishin · 2026-09-26