News · curated 30 Sep 2026

How I Could’ve Accessed 17 Trillion Microsoft Records | blog.faav.net

Coverage timeline

discovered faav.net primary 30 Sep 2026theregister.com

Single-source incident — first reported, latest, and curated coincide.

Why it matters

Antares, an autonomous AI hackbot that discovered and iterated on a real Microsoft vulnerability, shows how AI agents are increasingly weaponized for offensive vulnerability discovery, a trend defenders must track.

A 16-year-old researcher named Faav, using a self-built AI hackbot called Antares, found an authentication flaw in Microsoft's internal Titan analytics service that failed to verify JWT signatures, letting him claim admin identity and submit unauthorized SQL queries against datasets estimated at 17.3 trillion rows. Microsoft patched the API and paid a $5,000 bounty under coordinated disclosure; no customer data was accessed.