How I Could've Accessed 17 Trillion Microsoft Records
blog.faav.net
A researcher reported that Microsoft’s Titan internal analytics service allowed unauthorized SQL access by accepting an unsigned login token that was not signature-checked, enabling an administrator identity to be claimed. The environment was estimated to be reachable at a scale of 17,333,335,124,315 stored rows across related databases. As a result, Microsoft said it hardended the service to prevent the unsigned-JWT access path and improved protections based on the coordinated disclosure.
Why it matters
An internal Microsoft analytics service accepted unsigned JWTs, allowing a forged admin identity to run SQL across an environment estimated at 17.3 trillion stored rows. The bounded investigation highlights the impact of skipping signature verification and how agent exploration plus human insight can uncover the flaw.
Related stories
Microsoft disrupts AI-assisted platform that compromised 12,000 accounts
Ars Technica · 2 weeks ago ·
40
Microsoft patches record number of security vulnerabilities, citing its use of AI
TechCrunch · 2 months ago ·
58
Microsoft Copilot reveals secret input that allowed it to be hacked
Ars Technica · 1 month ago ·
43