17-year-old hacker creates AI assistant to penetrate Microsoft's platform

Faav said he often spends time outside of class looking for cybersecurity vulnerabilities on the systems of large technology corporations such as Microsoft, Amazon, Google, and Adobe. To optimize the detection process, he developed an AI assistant called Antares to automate network scanning.
During a review of Titan's internal data analytics platform in late August, Antares discovered an API link belonging to the Azure cloud service. While the primary path requires a VPN internal network connection, a /v2/Query secondary path completely bypasses the Azure Active Directory login step.
According to Tom's Hardware, it's worth noting that this pipeline accepts SQL queries directly. Although the server initially refused due to the lack of a JSON Web Token authentication code, Faav found that Microsoft's control system had a serious loophole, the server only checked the existence of the JWT code string without verifying the digital signature of that code.

By creating a fake authentication code with administrator rights, Faav easily bypassed the security barrier to penetrate and access a list containing data of 25,000 Microsoft employees, along with internal organizational charts and reports.
Continuing to dig deeper into the analytical data storage section of the Bing search engine, the hacker discovered that he had access to a total of 17,000 billion lines of data.
"The persistence of assistant Antares for 10 days combined with an intuitive human judgment helped discover the vulnerability," Faav shared on his personal blog.
He informed the entire process for Microsoft's bug bounty program. At the end of September, the young hacker received a $5,000 reward from the world's largest software corporation.
Huy Duc