Antares, an Azure host, and a public Titan API
On August 25, Faav — a 16-year-old security researcher — began work after his AI hackbot, Antares, discovered a public API endpoint for Titan, Microsoft’s internal analytics service. Titan’s web interface is restricted to Microsoft employees, but Antares found the service's API reachable through an Azure Cloud Services host. Over the following ten days, the researcher and his bot tested Titan’s JSON Web Token (JWT) authentication checks and its handling of email-formatted user principal names (UPNs).
How a missing JWT signature turned a platform into an admin console
Faav’s breakthrough came early on September 5 when he modified an unsigned JWT’s UPN from an email-formatted identity to "admin." Titan validated the token’s contents — tenant, audience, app ID, and user — but never verified the signature, the researcher found. The modified UPN resolved to local user ID 1, which held an admin role, and Titan allowed him to run SQL against its systems. Faav summarized the flaw with an analogy: the authentication checks felt like a hotel where every door had a working keycard reader, but any keycard unlocked any room.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadWhat the access revealed: metadata, search samples, and a large-row estimate
With admin SQL access to Titan’s platform metadata database, Faav was able to query application tables directly and enumerate a set of records and configurations that Microsoft later reviewed. The metadata he listed included:
- About 25,000 account and email records
- 17,990 employee email records
- 15,001 employee organization records
- 355 database configurations
- 20,979 virtual-dataset SQL definitions
- 24,569 dashboards, 425,891 charts, and 27,347 dataset definitions
Faav also located a Bing analytics sample and tested two rows that contained search information, identifiers, and high-level location data such as country- or state-level details; he noted the location values did not contain precise user locations. He observed that Titan’s user and usage directory exposed employee job titles, departments, and management hierarchy, which "could be useful for social-engineering attacks — though I never tested or demonstrated that."
How the 17.3 trillion-row figure was derived
Working from an archived configuration, Faav tested 56 routing values and found 30 still active. "Each routing value pointed to a backend configuration, and each configuration contained one or more databases," he wrote, and the 30 live values resolved through 24 configurations to 17 connected analytics databases spanning 9,863 unique table names. From that metadata he derived a storage estimate of about 17.3 trillion rows — a number he cautioned likely includes historical, duplicated, and derived data.
Microsoft’s response, coordinated disclosure, and the bounty
Between September 6 and September 8, Microsoft asked Faav to stop testing and requested his IP address to confirm there had been no nefarious activity beyond his research. A day after that interaction, Microsoft locked down the endpoint and told Faav the "report prompted immediate investigation and remediation to address the remaining exposure." Microsoft provided a statement for Faav’s blog: "We appreciate the opportunity to investigate the findings reported by Faav," the company said. "Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future." Microsoft awarded the researcher a $5,000 bug bounty on September 17.
Faav also said he rewrote his blog post at Microsoft’s request, cutting sections and numbers and rewording the impact prior to publication.
How developers, security teams, and social engineers are implicated
- Developers: Faav’s central technical takeaway is clear and specific to engineers who build authentication systems — Titan validated token fields but failed to verify signatures. "If you’re a developer (or coding agent) reading this, the most important takeaway from this post is to make sure you verify signatures above all else when building auth," he wrote.
- Security teams and incident responders: The sequence of discovery, coordinated disclosure, Microsoft’s lock-down of the endpoint, and the subsequent bounty illustrate an operational path from vulnerability discovery to remediation in this case, including a request to cease testing and to provide an IP address for validation.
- Social engineers: The exported metadata included employee job titles, departments, and management hierarchy; Faav noted such information "could be useful for social-engineering attacks," even though he did not test or demonstrate that capability.
A 16-year-old researcher, an AI tool named Antares, and a missing token signature combined to turn a tightly configured analytics application into a remote SQL console. Microsoft moved to lock down the endpoint and issued a $5,000 bounty after coordinated disclosure; the estimated 17.3 trillion rows remain a metadata-derived figure that, by Faav’s account, likely includes history and duplicates. The episode is a compact case study in how a single missing cryptographic check can undo otherwise elaborate access controls — and how coordinated disclosure can close the gap.




