Hot eventLive
微软Titan分析平台JWT签名未校验漏洞
1 reports1 sources4 hr ago updated
Get the story
AI overview
2026年10月,16岁漏洞猎人Faav报告微软内部Titan分析服务未校验JWT签名,可将字符串admin作为身份获得管理员权限,触及约17.3万亿行数据和约25000个账户元数据。微软已修复漏洞并支付5000美元赏金,称该数字为理论存储估计而非实际泄露的客户信息。
Generated from reports · updated 4 hr ago
LatestOct 5
微软修复Titan未校验JWT签名漏洞,支付5000美元赏金,称数据量为理论估计。Timeline
Follow the coverage from different angles.
Oct 6, 2026
- TechRadar · AI16岁漏洞猎人Faav借未校验签名获微软Titan管理员权限
16岁漏洞猎人Faav利用微软内部Titan分析服务未校验JWT签名,以字符串admin获得管理员权限,可触及约17.3万亿行数据和约25000个账户元数据。微软已修复漏洞并支付5000美元赏金,称该数字为理论存储估计而非实际泄露的客户信息。
Heat trend
Current heat 9·Comparable peak 10(Oct 6)·Comparable change over 24 hours –
The trend compares only the same participants observed continuously; its range may be smaller than the current heat count. Move or click on the chart to inspect hourly heat; use the left and right arrow keys to switch.