มีรายงานว่า Microsoft ปิดช่องทางเชื่อมต่อที่ได้รับผลกระทบเมื่อ 9 กันยายน 2026 ส่วนเงินรางวัลและการถูกใช้ช่องโหว่ก่อนหน้านั้นยังไม่มีข้อยืนยันจากหลักฐานที่มี [7][10]
How did 16-year-old researcher Faav and his AI tool Antares discover and exploit the unsigned JWT flaw in Microsoft’s publicly reachable TitIllustration; not an image of Titan’s API or Faav’s investigation.
AI พรอมต์
Create a landscape editorial hero image for this Studio Global article: How did 16-year-old researcher Faav and his AI tool Antares discover and exploit the unsigned JWT flaw in Microsoft’s publicly reachable Tit. Article summary: Faav reported that Microsoft’s publicly reachable Titan analytics API accepted a forged, unsigned login token as an administrator, allowing unauthorized SQL queries. The estimated 17.3 trillion rows describe potential re. Topic tags: general, general web, user generated. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fa
openai.com
ประเด็นสำคัญของกรณี Microsoft Titan ไม่ใช่ว่า Faav อ่านข้อมูลไป 17.3 ล้านล้านแถว แต่คือระบบวิเคราะห์ข้อมูลของ Microsoft ยอมรับโทเค็นเข้าสู่ระบบที่ไม่ได้ตรวจสอบลายเซ็น จนเขาสามารถอ้างตัวเป็นผู้ดูแลระบบและส่งคำสั่ง SQL ได้โดยไม่ต้องมีบัญชี Microsoft ตัวเลขมหาศาลนั้นเป็นประมาณการขอบเขตข้อมูลที่ อาจเข้าถึงได้ ไม่ใช่ปริมาณที่เขาตรวจสอบหรือดาวน์โหลด 211