AI Weekly Malaysia

Back to items Summaries

Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts

ID
29260
Status
summarized
Published
28 Sep 2026, 7:00 PM
Fetched
28 Sep 2026, 8:32 PM
Provider
Tom's Hardware
Category
technology
Original URL
https://www.tomshardware.com/tech-industry/cyber-security/teenager-hacks-open-microsoft-database-with-17-trillion-total-rows-and-25-000-user-accounts-custom-ai-bot-and-lack-of-jwt-token-validation-yields-a-fruitful-trove-earns-usd5-000-bug-bounty
Source URL
https://www.tomshardware.com/feeds/all

Summary

Score
6.5
Created
28 Sep 2026, 8:32 PM
Tags
Audience
developersvibe_codersai_agent_users

What happened

Tom's Hardware reports that a teenager accessed an open Microsoft database containing 17 trillion total rows and 25,000 user accounts, reportedly by pairing a custom AI bot with a failure to validate JWT tokens, and earned a $5,000 bug bounty. The article body available here is almost entirely paywall and newsletter boilerplate, so the mechanics of the attack, the affected service, and Microsoft's response are not described in the text provided.

Why it matters

The one concrete technical claim is 'lack of JWT token validation' — if your app accepts a JWT without verifying its signature and claims, an attacker can mint their own token and read whatever the database returns, which is exactly the class of mistake that ships when auth is generated quickly and never tested. Before your next deploy, confirm your backend actually verifies the signing key and issuer rather than decoding the token payload, and check that any AI-generated auth code isn't doing `jwt.decode` where it should be doing `jwt.verify`.

Discussion angle

JWT verification is the single most common thing AI coding assistants get subtly wrong — walk through what `decode` vs `verify` looks like in the libraries your stack uses, and whether your own project would survive a hand-crafted token.

Top