16-year-old schoolboy breaks Microsoft using his own AI bot

16-year-old schoolboy breaks Microsoft using his own AI bot
16-year-old schoolboy breaks Microsoft using his own AI bot

16-year-old schoolboy finds vulnerability in Microsoft using his own AI bot

A 16-year-old schoolboy discovered a vulnerability in Microsoft's infrastructure using an AI agent he developed himself.

The teenager launched his bot to analyse the company's systems and, during the inspection, came across the Microsoft Titan platform. The AI agent identified a flaw in the authentication logic that potentially allowed bypassing access token verification.

The discovered vulnerability could have provided access to approximately 25,000 user accounts, as well as Bing's analytical databases.

Estimates suggest that through this error, a malicious actor could potentially have been able to extract or modify up to 17 trillion rows of internal data.

Thus, the schoolboy's own AI agent did not merely help analyse Microsoft's infrastructure but also uncovered a critical issue in the access control mechanism.

Comments

No comments yet. Be the first!

Leave a comment

Links are not allowed in comments. The editors may remove comments without explanation.
Back to top ↑