A security researcher who goes by the name Faav accessed a Microsoft database containing roughly 17 trillion total rows and 25,000 user accounts, according to his own account of the find. The database also held employee records along with organization records, dashboards, and charts. Faav reported the issue through Microsoft's bug bounty program and was awarded $5,000 for his findings.
Faav said he spent the year hacking Microsoft off and on around school, and that he also looks for bugs in products from Amazon, Google, and Adobe. His primary tool was Antares, an AI orchestrator bot he built to scan and automate routine security work. Antares located an endpoint URL in Titan that returned an error stating a VPN was required, which drew his attention.
Antares searched for subdomains around that endpoint and found one belonging to an Azure Cloud host, along with a Swagger/OpenAPI file listing four routes. Three of the routes required Azure Active Directory authentication, but one did not. That route, named /v2/Query, accepted raw SQL queries.
Faav used the Wayback Machine to find a 2023 version of a login page that included an Apache Superset configuration file describing the database schema, which listed 56 table definitions. The endpoint rejected his queries because no JWT authentication was supplied, so he set Antares on the problem for 10 days without success. He then realized from the server's responses that the token's digital signature was not being checked, so he presented an access token as if it belonged to an administrator and was allowed in.
A SHOW DATABASES command revealed 25,000 employee records plus organization records, dashboards, and charts. Exploring further, Faav found a data source for Bing analytics. After tallying rows across tables there, he determined he had access to 17 trillion records in total and had to double-check the figure, stopping himself from yelling and waking his parents at 2 am.
In a blog post, Faav wrote that AI and human intuition compounded in this case, saying Antares did ten days of work he did not have to do. He credited the bot's persistence plus one human hunch as what made the find possible. The 17 trillion figure covers records he could reach through the exposed endpoint, not files he downloaded.
More cybersecurity news from TechManNews.






