Microsoft has closed access to the API of its internal analytics platform Titan and paid $5,000 to a 16-year-old researcher known as Faav, who used the AI bot Antares to discover a critical vulnerability in the authorization mechanism.
Unchecked JWT Signature Allowed Admin Access
For about 10 days, Antares analyzed Titan's login scheme and found that the system checked the data in the JWT token but not its cryptographic signature. This made it possible to forge tokens, impersonate an administrator, and execute SQL queries.
17 Databases With About 17.3 Trillion Rows Connected
Titan provided access to 17 databases containing approximately 17.3 trillion rows, including historical and duplicate records. The researcher did not download information in bulk and reported the vulnerability; a few days later, API access was closed. Details are available in the detailed vulnerability analysis.
