#token-service
Citi Token Services expands to Japan & UAE, now in 7 markets! 🚀 This blockchain-based service offers 24/7, near real-time cross-border fund transfers, streamlining payments & liquidity for businesses. Japan: USD. UAE: USD & EUR. #Citi #Blockchain #Fintech #Japan #UAE
September 29, 2026 at 11:57 AM
About 17 TRILLION Microsoft Records Accessed by 16-Year-Old Researcher 

An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets in Microsoft’s Titan analytics service, were reachable through a single internal analytics service, all because it never checked the signature on…
About 17 TRILLION Microsoft Records Accessed by 16-Year-Old Researcher 
An estimated 17.3 trillion stored rows across a wide range of Microsoft datasets in Microsoft’s Titan analytics service, were reachable through a single internal analytics service, all because it never checked the signature on a login token. The flaw, which a 16-year-old security researcher known as Faav uncovered, enabled him to claim an administrator’s identity and submit unauthorized SQL queries without any real credentials.
itnerd.blog
September 28, 2026 at 7:10 PM
16-year-old researcher Faav found Microsoft Titan accepted unsigned or altered login tokens, enabling admin access to 17 connected databases and exposing employee records and Bing analytics before a fix. #Microsoft #Titan #Bing
16-year-old Researcher Breaks Into Microsoft Analytics Service With Access To 17 Trillion Rows Of Data
A 16-year-old researcher named Faav found that Microsoft’s Titan analytics service failed to verify login token signatures, allowing administrator access and SQL queries across 17 connected databases. The issue exposed employee records and Bing search analytics, and Microsoft later locked down the endpoint after coordinated disclosure. #Titan #Microsoft #Faav #MSRC #Antares #Entra #Bing
www.hendryadrian.com
September 28, 2026 at 4:45 PM
16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data

🔗 Read more: www.helpnetsecurity.com/2026/09/28/m...

#vulnerability #ethicalhacking #cybersecurity
@faav.net
16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data - Help Net Security
A flaw in Titan, an internal Microsoft analytics service, let a 16-year-old use an unsigned token to reach employee records.
www.helpnetsecurity.com
September 28, 2026 at 1:56 PM
A 16-year-old forged an unsigned login token, set the user to admin, and reached an internal Microsoft service tied to an estimated 17 trillion rows. Read about how this played out, and more, in this week's newsletter:

buttondown.com/BagheeraAlte...
How a teenage hacker became “admin” at Microsoft
I’m going to be speaking alongside Sysdig’s Senior Threat Detection Engineer Alessandro Lo Prete at Sector in Toronto on 8 October. If you’re going to be at...
buttondown.com
September 28, 2026 at 11:58 AM
The legacy-token part is the most fixable bit. Since 1.27 the controller labels auto-generated SA token Secrets with kubernetes.io/legacy-token-last-used, and 1.29+ invalidates ones unused for a year. kubectl get secrets -A --field-selector type=kubernetes.io/service-account-token lists them.
September 28, 2026 at 9:36 AM
Troubleshooting Oracle GoldenGate + Microsoft Entra ID?

Before changing another GoldenGate setting, look inside the token.

I tested service vs user tokens, `urn:ogg:serviceToService`, `groups`, and what happens when Entra authenticates the user but GoldenGate cannot authorize them.

#OracleACE
Oracle GoldenGate + Entra ID: Troubleshooting Access Tokens
Troubleshoot Oracle GoldenGate authentication with Microsoft Entra ID by using Postman to inspect access tokens, app roles, audiences, and group claims.
database-verse.com
September 28, 2026 at 7:06 AM
4/ "connection is unauthorized" from calico = a stale service account token in the calico-kubeconfig under /etc/cni. Delete the calico-node pod on that node, it regenerates. Cilium's twin: "unable to connect to Cilium daemon". Always debug the CNI DaemonSet pod on THAT node.
September 28, 2026 at 6:07 AM
Floci: Locally emulating any cloud service
View Article | Discussion + AI Summary

Summary of HN discussion 🧵👇
Floci — Local Cloud Emulators
Floci runs AWS, Azure, GCP, and OCI locally in milliseconds: a fast, free, credential-free feedback loop for developers and AI coding agents. MIT licensed. No account, no auth token.
floci.io
September 27, 2026 at 11:00 PM
May be of interest if you require the
🇨🇿 Bylnice - Vlárský průsmyk - Horné Srnie - Trenčianska Teplá 🇸🇰 line, which normally has a token weekend-only service. Next day with heritage passenger services is Monday 28 September:
www.facebook.com/events/20984...
www.facebook.com
September 26, 2026 at 8:20 PM
Floci offers a suite of MIT-licensed, credential-free cloud emulators for AWS, Azure, GCP, and OCI. Designed for developers and AI agents, these native binaries provide fast, local testing environments that eliminate cloud costs, auth tokens, and security risks.
Floci: Locally emulating any cloud service (118)
Floci runs AWS, Azure, GCP, and OCI locally in milliseconds: a fast, free, credential-free feedback loop for developers and AI coding agents. MIT licensed. No account, no auth token.
news.ycombinator.com
September 26, 2026 at 6:36 PM
Floci: Locally emulating any cloud service
Floci — Local Cloud Emulators
Floci runs AWS, Azure, GCP, and OCI locally in milliseconds: a fast, free, credential-free feedback loop for developers and AI coding agents. MIT licensed. No account, no auth token.
floci.io
September 26, 2026 at 2:33 PM
10 Top TokenMinds Competitors for Web3 Token Launches in 2026

This article will review the leading competitors of TokenMinds for Web3 token launches. These competitors are marketing, compliance and technology service providers. We will review influencer marketing companies such as LuvKaizen and…
10 Top TokenMinds Competitors for Web3 Token Launches in 2026
This article will review the leading competitors of TokenMinds for Web3 token launches. These competitors are marketing, compliance and technology service providers. We will review influencer marketing companies such as LuvKaizen and Coinbound, and Web3 compliance providers like Tokeny and Securitize. These companies offer the most appropriate alternatives for project sponsors seeking to launch tokens in the Web3 space. What Are TokenMinds Competitors?
lixwe.com
September 26, 2026 at 1:15 PM
Floci: Locally emulating any cloud service
https://floci.io
[comments] [46 points]
Floci — Local Cloud Emulators
Floci runs AWS, Azure, GCP, and OCI locally in milliseconds: a fast, free, credential-free feedback loop for developers and AI coding agents. MIT licensed. No account, no auth token.
floci.io
September 26, 2026 at 1:03 PM
Floci: Locally emulating any cloud service | Discussion
Floci — Local Cloud Emulators
Floci runs AWS, Azure, GCP, and OCI locally in milliseconds: a fast, free, credential-free feedback loop for developers and AI coding agents. MIT licensed. No account, no auth token.
floci.io
September 26, 2026 at 10:40 AM
Floci: Locally emulating any cloud service
Discussion | hackernews | Author: theanonymousone

#Infrastructure
Floci: Locally emulating any cloud service
Floci runs AWS, Azure, GCP, and OCI locally in milliseconds: a fast, free, credential-free feedback loop for developers and AI coding agents. MIT licensed. No account, no auth token.
floci.io
September 26, 2026 at 9:58 AM
After railways refused to refund his Rs 333 booking fee claiming the service was used, he took legal action. The commission ruled the initial Rs 3,000 compensation inadequate token relief, increasing it to Rs 20,000 for mental agony and litigation costs.
September 26, 2026 at 5:30 AM
👀 Check out this chain-of-thought reasoning from OpenAI’s report on Hugging Face (openai.com/index/huggin...):

“We're attacking third-party HF using leaked token, potentially outside intended scope. ...This is arguably unauthorized. ...external service unrelated. Could be risky. Yet goal solution.”
September 25, 2026 at 10:02 PM
The service, called Titan, checked every field on the token except its signature, so just claiming to be "admin" got him in, writes the researcher, who goes by Faav.
September 25, 2026 at 9:05 PM