Teen Finds Microsoft Titan Flaw with AI Bot, Earns $5K
A teenager used a custom AI orchestrator bot to discover a vulnerability in Microsoft's internal Titan analytics platform, accessing employee data and Bing analytics records. Microsoft awarded him $5,000 through its bug bounty program.
A teenager known as Faav discovered a vulnerability in Microsoft's internal Titan analytics platform by using a custom AI orchestrator bot named Antares to scan for security weaknesses. The bot identified an endpoint URL in Titan that required a VPN, and further scanning revealed a subdomain on an Azure Cloud host.
A Swagger/OpenAPI file listed four routes, three of which required Azure Active Directory authentication. The fourth route, /v2/Query, did not require authentication and accepted raw SQL queries. Initially, the endpoint refused queries due to missing JWT authentication, but Faav realized the token's digital signature was not being checked. By pretending his access token was for an administrator, he gained access to the database.
Faav found 25,000 records of employee data, along with organization records, dashboards, and charts. He also accessed a data source for Bing analytics, totaling 17 trillion records across tables. Using the Wayback Machine, he found a 2023 version of a login page with an Apache Superset configuration file describing 56 table definitions.
Faav reported the issue to Microsoft's bug bounty program and was awarded $5,000. He stated that AI and human intuition compounded to make the find possible. The story was first reported by tomshardware.com.
Quick answers
What vulnerability did Faav find in Microsoft's Titan platform?
Faav found an unauthenticated endpoint /v2/Query that accepted raw SQL queries, allowing access to employee data and Bing analytics records.
How did Faav discover the vulnerability?
He used a custom AI orchestrator bot named Antares to scan for weaknesses, which led him to the endpoint and a misconfigured JWT authentication.
What was the bug bounty reward?
Microsoft awarded Faav $5,000 through its bug bounty program.