Security researcher Faav discovered a critical vulnerability in Microsoft's internal Titan analytics service that could have exposed 17.3 trillion stored records. The flaw allowed attackers to bypass JWT signature verification and claim administrator identity to submit unauthorized SQL queries, though Faav reported the bug responsibly without accessing customer data.
Security researcher Faav discovered a critical vulnerability in Microsoft's internal Titan analytics service that could have exposed 17.3 trillion stored records due to inadequate JWT signature validation, allowing unauthorized SQL queries without proper credentials. The flaw was responsibly disclosed through Microsoft's bug bounty program and has been remediated.