News from IT on September 28: 16-year-old security researcher Faav posted a blog on his homepage on September 25 local time, revealing how he discovered a vulnerability within Microsoft and received a bounty of $5,000 (Note from IT: The current exchange rate is approximately 33,597 RMB).
He discovered that there was an authentication vulnerability in Microsoft's internal analysis platform Titan. Hackers could exploit this vulnerability to access an internal database containing approximately 25,000 employee data records and were able to query a total of 17.3 trillion data records.

According to Faav, he has been participating in vulnerability bounty programs since the age of 15 and developed the AI robot as well as Antares. On August 25, 2026, Antares discovered the publicly available API interface of Titan. This interface indicated a need to connect to VPN. Subsequently, Faav had Antares enumerate related subdomains, identifying a host located in a Azure cloud environment, and found the corresponding Swagger / OpenAPI files.
This document lists 4 API routes. Three of them require Azure Active Directory authentication, but the last interface, named “/ v2 / Query”, does not have this requirement and supports direct submission of SQL queries.
Faav still needs to understand the database structure. He used Wayback Machine to find a snapshot of the login page from 2023, Titan, and obtained from it the Apache Superset configuration file (which describes the database structure and contains definitions for 56 data tables in total).
Antares then spent 10 days probing the JWT verification process. Subsequently, Faav discovered that although the "/ v2 / Query" interface required JWT authentication, the server did not appear to be verifying the digital signature of the token. Subsequently, based on the server's response, he forged a login token with alg as none and an empty signature field. After changing upn to admin, he successfully executed SQL as an administrator.
In the early hours of September 5th, he confirmed that he had access to the database of the Titan platform. Queries revealed that its metadata contained approximately 25,000 account and email records, 17,990 employee email records, 15,001 employee organization records, as well as 355 database configurations, 20,979 virtual datasets defined by SQL, 24,569 dashboards, and 425,891 charts.
After further inspection, he also discovered a set of data sources related to the analysis of Bing in the database. By summarizing the number of records from multiple data tables, Faav estimated that the scale of data he could access amounted to 17,333,335,124,315 entries.
Faav indicates that when he discovered this number at 2 a.m., in order not to wake his parents, he had to restrain the urge to shout it out loud. Subsequently, he began to draft a report and submitted it to Microsoft MSRC.
From September 6th to 8th, Microsoft requested him to stop testing and provide the address IP to confirm that there were no activities beyond the scope of security research. On September 9th, that interface API was immediately locked down.
On September 17th, Microsoft awarded a bounty of $5,000 (approximately 33,597 RMB at the current exchange rate) to Faav. On September 22nd, the two parties met to discuss the vulnerability and coordinate its disclosure. Faav stated that Microsoft had edited the article before posting it on their blog, removing some content and adjusting the description of the impact.
Microsoft stated in a statement, "We appreciate the opportunity to investigate the findings reported in Faav. The submission and coordination of vulnerability disclosures have helped us better protect our customers and enhance our services." Microsoft emphasized that the company will continue to place importance on security research under its vulnerability bounty program.












