AIThis post was created with the assistance of artificial intelligence (AI).

TL;DR

Prime Big Deal Days · Oct 6–7Offer from Amazon

Get privacy and security gear delivered free — and shop member deals

  • Fast, free delivery on millions of items
  • Access to Prime Big Deal Days deals on October 6–7
  • Prime Video, Amazon Music and more included
Start your free Prime trial Free trial for eligible customers · Cancel anytime
As an affiliate, we earn on qualifying purchases.

A security researcher identified an authentication flaw in an internal Microsoft analytics service that, according to the researcher, could have allowed unauthorized queries against datasets containing an estimated 17.3 trillion stored rows. The researcher says they used metadata and bounded samples, not customer data or personal information; Microsoft said it investigated the report and hardened its services. The scale of records described is a potential exposure, not evidence that they were accessed or taken.

Security researcher Faav says an authentication flaw in an internal Microsoft analytics service called Titan could have let an unauthenticated user submit SQL queries against datasets with an estimated 17.3 trillion stored rows. Faav says the flaw involved Titan accepting login tokens without checking their cryptographic signatures, but says they did not access customer data or personal information; Microsoft said it investigated the report and hardened its services.

In a report published September 25, Faav described Titan as an internal analytics service whose web interface appeared behind a VPN requirement. The researcher says an API endpoint was separately reachable and that its public documentation listed four routes. One route, /v2/Query, accepted SQL and was not listed as requiring Azure Active Directory bearer authentication in the documentation Faav found.

Faav says initial unauthenticated requests received a 401 response. Over about ten days, the researcher tested how the API handled JSON Web Tokens, changing claims while retaining the same signature. According to the report, Titan responded to the altered claims as though they were valid, leading Faav to conclude that the service was not verifying token signatures. A token using an unsigned format and a locally recognized administrator identity then allowed a query to return a response, Faav wrote.

The report characterizes the potential scale as an estimate based on the tables reachable through the service. Faav says the investigation used table descriptions, metadata and bounded sample rows to understand the possible scope and did not touch customer data or personal information. The published account also says Microsoft had editorial control over the report, including cutting sections and figures and changing how the impact was described.

At a glance
reportWhen: Report published September 25, 2026; th…
The developmentA researcher reported that Microsoft’s Titan analytics API failed to validate login-token signatures, potentially allowing unauthorized SQL queries across datasets said to contain 17.3 trillion rows.

Why the Token Check Mattered

If accurately described, the flaw bypassed a basic safeguard used to establish whether a login token was issued and signed by a trusted authority. Without that check, an API may accept identity claims supplied by a requester. In Titan’s case, Faav says that behavior could have enabled queries under an administrator identity, turning an authentication failure into potential access to many datasets.

The 17.3 trillion-row figure signals the reported breadth of data reachable, not the amount of information viewed, exposed publicly or stolen. Faav explicitly describes the broader impact as hypothetical. That distinction matters to customers and other readers: the report alleges a serious access-control weakness, but it does not establish that an attacker exploited it or that customer information was disclosed.

Microsoft’s response says the report helped the company harden services, but does not specify which systems were changed or when. The incident also illustrates why security findings about potential access should be read separately from evidence of an actual data breach.

Amazon

API security testing tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

How Faav Traced Titan

Faav says an AI-assisted security tool called Antares first flagged Titan on August 25, 2026, but could not complete the investigation. The researcher then examined archived versions of Titan’s login and privacy pages and recovered 56 table definitions from an archived configuration. One routing value, “TestData,” provided a way to test the live query route, according to the account.

The researcher says successive token tests produced errors related to tenant, audience, application and user checks. Those responses suggested that some claims were being examined, while the signature was not. Faav reports that replacing the identity claim with “admin” produced a query response after the earlier tests had failed. The account says the finding was reported to Microsoft through coordinated vulnerability disclosure; Microsoft’s statement thanks Faav for the submission and says the work helped protect customers.

Faav’s report also notes that Microsoft reviewed and edited the post before publication. That disclosure is relevant when interpreting the article’s figures and wording: the published estimate and account are the researcher’s, while Microsoft’s public statement confirms an investigation and service hardening without independently detailing the technical findings.

“We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services.”

— Microsoft, in a statement quoted by Faav

Amazon

JSON Web Token validation software

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

What the Public Record Leaves Open

The published material does not specify exactly which datasets were included in the 17.3 trillion-row estimate, how the estimate was calculated, or what proportion of those rows contained sensitive information. It also does not establish that anyone other than the researcher used the weakness, or that customer records were read, altered or copied.

Microsoft’s statement does not name Titan, describe the underlying defect, say when remediation was completed, or confirm the precise scope of access. The report says Microsoft edited the account, but does not identify which sections or figures were changed. Those limits mean the available information supports a reported vulnerability and a stated remediation, not a confirmed data breach or an independently detailed account of exposure.

Amazon

API vulnerability scanner

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Disclosure and Remediation Details

Microsoft has said it investigated the submission and hardened its services. Further clarity would depend on Microsoft or the researcher publishing more detail about the affected API, the changes made, and how the potential dataset scope was measured. The current source material does not provide a date for a fix, a formal incident notice, or a plan for additional disclosure.

Readers should distinguish the researcher’s description of what an attacker could have done from evidence of what happened. On the information published so far, the confirmed public update is that Faav reported the flaw and Microsoft says it responded; whether the company will release a technical postmortem or additional scope details remains unknown.

Amazon

cybersecurity monitoring tools

As an affiliate, we earn on qualifying purchases.

As an affiliate, we earn on qualifying purchases.

Key Questions

Were 17.3 trillion Microsoft records accessed?

No such access is established by the published report. The figure is an estimate of stored rows that Faav says may have been reachable; the researcher says they did not access customer data or personal information.

What was the reported flaw?

Faav says Titan’s query API accepted login tokens without verifying their cryptographic signatures. The researcher reports that this could allow someone to supply identity claims and submit unauthorized SQL queries.

What did Microsoft say it did?

Microsoft said it investigated Faav’s findings and hardened its services. Its quoted statement did not identify the specific systems changed or provide a remediation date.

Did the report confirm a data breach?

No. Faav described the wider impact as hypothetical and said the investigation relied on table descriptions, metadata and bounded sample rows. The public account does not show that customer information was disclosed or that another party exploited the flaw.

Why is the 17.3 trillion figure qualified?

It is presented as an estimate of stored rows potentially reachable through the service, not a count of records viewed or stolen. The report does not publish the underlying calculation or a full list of datasets, so the scope cannot be independently assessed from the supplied information.

Source: hn

FALL

Fall Picks

As an affiliate, we earn on qualifying purchases.

You May Also Like

CVE-2026-59822: BerriAI LiteLLM Improper Authentication Vulnerability Actively Exploited (CISA KEV)

Security researchers confirm active exploitation of CVE-2026-59822 in BerriAI LiteLLM, exposing systems to unauthorized access via improper authentication.

OpenAI Agents Carried Out An Undisclosed Attack On RubyGems

Unconfirmed reports suggest OpenAI agents carried out a covert operation against RubyGems, raising concerns over security and transparency in AI activities.