Skip to main content
News Directory 3
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Menu
  • Business
  • Entertainment
  • Health
  • News
  • Sports
  • Tech
  • World
Microsoft Security Breach: 16-Year-Old Exploits JWT Flaw, GameStar Reports

Microsoft Security Breach: 16-Year-Old Exploits JWT Flaw, GameStar Reports

October 6, 2026 Lisa Park Tech
News Context
At a glance
  • A 16-year-old security researcher named Faav bypassed token signature verification to access approximately 25,000 internal accounts, 17,990 employee email addresses, and 24,569 dashboards within Microsoft’s Titan internal analytics...
  • The vulnerability allowed arbitrary SQL queries to execute with administrator privileges on Azure infrastructure without requiring any sophisticated exploit.
  • On August 25, Faav used an artificial intelligence tool named Antares to locate the application programming interface for Titan.
Original source: gamestar.de

A 16-year-old security researcher named Faav bypassed token signature verification to access approximately 25,000 internal accounts, 17,990 employee email addresses, and 24,569 dashboards within Microsoft’s Titan internal analytics service, GameStar reported.

The vulnerability allowed arbitrary SQL queries to execute with administrator privileges on Azure infrastructure without requiring any sophisticated exploit. Titan checked the content parameters of the token including tenant, target audience, application, and user, but completely ignored its signature, which bypassed all security checks. Paradoxically, the official documentation of the Azure Application Gateway mandates that a token’s signature, issuer, recipient, and validity period must be validated. Microsoft patched the flaw within days of its disclosure and subsequently paid the researcher a 5,000 US-dollar bug bounty.

How the Titan API Exposed 17 Trillion Rows

On August 25, Faav used an artificial intelligence tool named Antares to locate the application programming interface for Titan. While the service’s web frontend was restricted to internal personnel, the underlying API remained exposed on an Azure host without public protection.

Antares tested token variations over a ten-day period before determining that the server accepted authentication tokens completely without a digital signature. To complete the unauthorized access, the system only required a valid username recognized by Titan. The case provides a clear example of AI-supported security research where the artificial intelligence acts as a diligent assistant to human judgment rather than a strategic mastermind; Antares worked repeatedly on the problem for ten days, but the decisive idea of using the username came from the researcher himself.

Faav entered the username admin into the token field. Titan accepted the input as a local user with administrative rights, executing SQL queries against internal databases without validating the token’s cryptographic integrity, and the researcher also discovered that the service was linked to 17 analytical databases.

Disclosure and Patch Timeline at Microsoft

Faav reported the security flaw to the Microsoft Security Response Center on September 5, the same day the tests concluded. Microsoft closed the vulnerability on September 9 and awarded a 5,000 US-dollar bounty on September 17, as detailed in the researcher’s personal blog.

The security breach relied on a class of vulnerability documented since 2015, when researcher Tim McLean demonstrated that various software libraries accepted authentication tokens without verifying specified algorithms. The Internet Engineering Task Force published official best practices for JSON Web Token handling in 2020.

Microsoft reviewed the research report prior to publication and removed specific sections and figures, while leaving the core technical details intact.

Share this:

  • Share on Facebook (Opens in new window) Facebook
  • Share on X (Opens in new window) X

Worth a look

  • Giant Light Studios releases expanded Mr. Magpie’s Harmless Card Game demo
  • Foldable Phones Require Care to Avoid Screen Punctures and Damage
  • Why the Social Security COLA Is Announced in October (daybreakwire.com)
  • Spanish Security Forces Clear Migrant Camp on Ceuta’s El Trampolín Beach (time.news)

Related

Search:

News Directory 3

News Directory 3 catalogs US newspapers, news services, newsstands and digital news outlets across all 50 states. Browse local publishers by city, state, or topic, and follow current headlines linked back to their original sources.

Quick Links

  • Disclaimer
  • Terms and Conditions
  • About Us
  • Advertising Policy
  • Contact Us
  • Cookie Policy
  • Editorial Guidelines
  • Privacy Policy

Browse by State

  • Alabama
  • Alaska
  • Arizona
  • Arkansas
  • California
  • Colorado

© 2026 News Directory 3. All rights reserved.
For contact, advertising, copyright, issues email: office@newsdirectory3.com