16-Year-Old's Bug Report: 17 Trillion Microsoft Records Exposed, $5k Bounty

rez0__ · x · 2026-10-10

Researcher Faav (16) disclosed that a Microsoft internal analytics service never validated login token signatures, letting an attacker claim admin identity and run unauthorized SQL queries across an estimated 17.3 trillion stored rows. Faav only used table descriptions, metadata, and bounded samples — no customer data touched. Microsoft had editorial control over the write-up and praised the coordinated disclosure; the reported $5k bounty drew criticism. Faav built 'Antares', a personal AI hackbot that surfaced the original lead.

Original post →

More from Safety

Safety channel →