News · curated 30 Sep 2026
How I Could’ve Accessed 17 Trillion Microsoft Records | blog.faav.net
First reported faav.net
Coverage timeline
Single-source incident — first reported, latest, and curated coincide.
Why it matters
Antares, an autonomous AI hackbot that discovered and iterated on a real Microsoft vulnerability, shows how AI agents are increasingly weaponized for offensive vulnerability discovery, a trend defenders must track.
A 16-year-old researcher named Faav, using a self-built AI hackbot called Antares, found an authentication flaw in Microsoft's internal Titan analytics service that failed to verify JWT signatures, letting him claim admin identity and submit unauthorized SQL queries against datasets estimated at 17.3 trillion rows. Microsoft patched the API and paid a $5,000 bounty under coordinated disclosure; no customer data was accessed.