CriticalSecurity & Privacy
16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows
A 16-year-old researcher found a critical authentication flaw in Microsoft’s Titan internal analytics service that let him gain admin access and query metadata tied to a platform spanning an estimated 17.3 trillion rows. For CIOs and technology leaders, the key takeaway is that a single missing control—JWT signature verification—can expose internal data at massive scale, underscoring the need for defense-in-depth, rigorous identity validation, and continuous security testing even for non-customer-facing systems.
The Register3 min read