By Deeba Ahmed
Publication Date: 2026-09-29 11:22:00
A teen hacker found an authentication flaw in Microsoft’s Titan analytics service, where metadata indicated an estimated 17.3 trillion stored rows.
A 16-year-old using the alias Faav, who describes himself as a hacker and developer, found an authentication flaw in an internal Microsoft analytics service that could have allowed unauthorized SQL queries against an environment whose metadata indicated an estimated 17.3 trillion stored rows.
The flaw affected Titan, an internal analytics service whose web interface was restricted to Microsoft employees. However, its API remained reachable through an Azure Cloud Services host. The problem was that Titan checked several claims in authentication tokens but did not verify the tokens’ signatures, allowing an attacker to claim another user’s identity when accessing the service.
Unsigned Token Led to Administrator Access
Faav discovered the API on August 25, 2026, while participating in Microsoft’s bug bounty…



