← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 26, 2026 · 03:55via Cyber Security News

16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records

Brief

A 16-year-old security researcher known as Faav uncovered an authentication flaw in Microsoft’s internal Titan analytics service that potentially exposed an estimated 17.3 trillion database rows.

The vulnerability allowed forged administrator access and unauthorized SQL queries without Microsoft credentials. However, Faav emphasized that the potential impact was hypothetical.

The researcher relied on metadata, table descriptions, and limited samples, never accessing customer personally identifiable information (PII), and found no evidence that malicious actors exploited this weakness.

The investigation began on August 25, 2026, when Faav’s AI-powered hacking assistant, Antares, discovered Titan. Although the web interface displayed a “VPN REQUIRED” page, Antares identified a public API hosted through Azure Cloud Services .

Read more on Cyber Security News→