How a teenage hacker became “admin” at Microsoft
I’m going to be speaking alongside Sysdig’s Senior Threat Detection Engineer Alessandro Lo Prete at Sector in Toronto on 8 October. If you’re going to be at the conference, we’d love to see you there. Our talk is entitled, “Closed Loop: From Autonomous Exploit to Deployed Defense in Under Five Minutes” and includes a live demo of AI-driven mitigation solutions.
Our top story this week:
A 16-year-old researcher who goes by Faav found that an internal Microsoft analytics service called Titan checked nearly everything on a login token except the one thing that matters: the signature.
By submitting a forged token with the algorithm set to none and the user principal name changed to admin, he was executing SQL as Titan's administrator. Metadata showed the service connected to 17 analytics databases and an estimated 17.3 trillion stored rows, a figure that likely includes historical and duplicated data.
He also saw 17,990 employee email records and confirmed Bing analytics were reachable using two one-row samples. He says he never touched customer data or PII, and that the impact is hypothetical. Microsoft locked down the endpoint four days after his report and paid a $5,000 bounty.
Faav also notes that Microsoft had editorial control over the writeup and cut sections and figures. The find combined machine persistence and human intuition: his AI hackbot, Antares, spent 10 days grinding through JWT errors, and a hunch that upn was really a local username finished the job. Read all about it on Faav’s blog:
https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records
Did someone forward you this? Subscribe to this newsletter.
In other cybersecurity news:
Google says ShinyHunters is mass-exploiting an Oracle PeopleSoft flaw, using a trick that slips past the firewall rules companies relied on instead of patching, and has planted web shells on dozens of systems worldwide. The campaign has spread from universities to healthcare, government, tech and transportation, and some servers got a new backdoor called SIDEEYE, hidden inside a booby-trapped media player installer signed with a valid certificate. Google has published IOCs, file hashes and a fix-it guide for CVE-2026-35273, and warns victims to prepare for extortion.
https://cloud.google.com/blog/topics/threat-intelligence/shinyhunters-renewed-mass-exploitation-campaign-targeting-oracle-peoplesoft
OpenAI has notified "dozens" of organisations that its AI agents may have hacked them during training and evaluation, with governments and universities among them. The company's own summaries describe agents using exposed credentials and command injection. The agents also leaked 53 images from ChatGPT users. OpenAI won't say whether they show real people.
https://openai.com/hugging-face-incident-and-misalignment/#model-misalignment-2026-09-25
ShinyHunters, the data theft and extortion crew that has stolen sensitive information belonging to millions of cancer patients, university and K-12 students, and Carnival cruisers, wanted to preserve their reputation and keep their “business” afloat. So it hacked the FBI to make a statement, the group told The Register. “It’s a game and it’s the world we live in,” a ShinyHunters spokesperson told us. “We are just protecting our business as any other business would do. It’s about who does their job better.”
https://www.theregister.com/cyber-crime/2026/09/25/shinyhunters-tells-the-reg-we-hacked-the-fbi-to-protect-our-business/5299250
A critical perimeter emergency is unfolding across enterprise infrastructure worldwide as threat intelligence teams confirm the active, in-the-wild exploitation of two unpatched pre-authentication remote code execution (RCE) zero-day vulnerabilities in Citrix NetScaler ADC (formerly NetScaler Application Delivery Controller) and NetScaler Gateway appliances. Disclosed in an urgent advisory by offensive cybersecurity research firm watchTowr on September 26, 2026, the zero-day exploit chain allows unauthenticated adversaries with external HTTPS reachability to execute arbitrary code within the appliance’s packet processing kernel, harvest active VPN session tokens, and bypass network perimeter controls without credentials. With official vendor patches still pending release, cybersecurity agencies and incident response firms are urging organizations to implement emergency isolation protocols immediately.
https://sh3llc0d3.com/blog/inside-the-netscaler-zero-day-siege-chained-pre-auth-rces-weaponized-in-the-wild-watchtowr-disclosure/
When it comes to fixing security vulnerabilities, speed is crucial. Canonical is officially outlining a transition from its current 4-week regular and 2-week security kernel Stable Release Update (SRU) cycles to a unified, rapid 2-week SRU cycle, published weekly.
https://canonical.com/blog/accelerating-delivery-of-cve-fixes-with-a-new-kernel-release-strategy
The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media has found. The findings further highlight how sensitive the stolen data is, and how valuable it may be to criminals or to foreign intelligence agencies. There is very little public information about the FBI’s hacking unit, including the operations it conducts, the tools it uses, or which agents are part of it.
https://www.404media.co/fbi-hack-exposed-fbis-own-hacking-unit-remote-operations-shinyhunters/
It would seem that Asus recently suffered a security breach through its online store. In an email sent out to registered Asus eshop customers, the company confirms that it recently became aware of “unauthorised access” to customer order information, but no financial information was touched.
https://www.kitguru.net/tech-news/featured-tech-news/matthew-wilson/asus-warns-customers-of-eshop-data-breach/
Microsoft's Digital Crimes Unit obtained an order from a federal court in Virginia. Authorities seized 50 websites and disabled over 150 supporting domains. British police arrested two men (aged 32 and 38) in London in connection with running the service. Microsoft worked with tech and security partners including Cloudflare, Coinbase, and OpenAI.
https://www.microsoft.com/en-us/corporate-responsibility/customer-security-trust/digital-crimes-unit/notice-of-pleadings/eviltokens/
A vulnerable chat overlay, an unsandboxed Chromium renderer, and a V8 bug already exploited in the wild were enough to turn viewer-controlled text into native code execution, with OBS itself left at its default settings.
https://blog.scrt.ch/2026/09/22/how-one-twitch-chat-message-became-code-execution-on-a-streamers-pc/
HEIF Heist is Hacktron's name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images. By exploiting underlying native libraries, these vulnerabilities allow an attacker to bypass application-level defenses and trigger memory corruption, data exposure, or remote code execution (RCE).
https://heif-heist.com/
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/
The FBI is investigating a cyberattack targeting the Arizona court system that may have compromised personally identifiable information belonging to residents. Court IT staff discovered the intrusion, which occurred within the last 36 hours, and took immediate steps to stop criminal hackers from copying additional court records. Officials say there is currently no evidence that compromised names or addresses have been shared, and the court is cooperating fully with federal investigators.
https://www.fox10phoenix.com/news/arizona-court-system-targeted-cyberattack-compromising-personal-records
A brief history of export controls that didn’t stop anyone. Last Friday, citing unspecified national security concerns, the White House ordered Anthropic to restrict the export of its powerful AI models Fable and Mythos to anyone outside of the United States, as well as to foreign nationals inside the country. Shortly after, the AI giant hastily pulled the plug on both models, which have now been unavailable to anyone for a week.
https://techcrunch.com/2026/06/19/encryption-spyware-and-now-mythos-history-shows-why-cyber-export-control-doesnt-work/
Ransomware groups are exploiting a serious security flaw in JetBrains TeamCity, a platform used by more than 30.000 development teams worldwide. The US CISA agency confirmed on September 23, 2026, that the issue is linked to real-life ransomware attacks.
https://en.hacks.gr/omades-ekviasmoy-chtypoyn-to-teamcity-peripoy-160-egkatastaseis-paramenoyn-ektetheimenes/
Hackers took home a stolen Flock camera. What they found was massive. A stolen Flock Safety license-plate camera yielded roughly 1.6 million images after hackers physically removed and reverse-engineered the device, but a former Secret Service cybercrime expert says the incident does not appear to have compromised Flock's broader cloud network. Jason Brown, director of customer advisory and counter-fraud lead at threat intelligence firm iCOUNTER, spent 25 years with the U.S. Secret Service and specialized in cybercrime.
https://www.fox26houston.com/news/hackers-stolen-flock-camera
Hackers are leveraging overlooked machine accounts in Microsoft 365 (M365) to steal enterprise data from organizations in Chile. Within any organization's M365 environment, there are accounts that belong to humans, sure, but also shared functional identities and accounts for applications and automated processes. Individuals are responsible for their own identities, but who keeps track of, maintains, and secures those nonhuman ones? Without due diligence, those types can fall out of focus and become forgotten relics with default credentials and excessive permissions.
https://www.darkreading.com/cyberattacks-data-breaches/ghost-service-accounts-m365-data-theft-chile