<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="https://rqms.co.uk/blog/rss/xslt"?>
<rss xmlns:a10="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>Articulate Blog</title>
    <link>https://rqms.co.uk/blog/</link>
    <description>Welcome to my blog</description>
    <generator>Articulate, blogging built on Umbraco</generator>
    <item>
      <guid isPermaLink="false">1267</guid>
      <link>https://rqms.co.uk/archive/44-million-microsoft-customers-found-using-compromised-passwords/</link>
      <title>44 million Microsoft customers found using compromised passwords</title>
      <description>&lt;p&gt;The 44 million weak accounts comprised both Microsoft Services Accounts (regular users) and Azure AD accounts too, suggesting businesses are not adopting proper password hygiene.&lt;/p&gt;
&lt;div class="polaris__simple-grid--main"&gt;
&lt;p&gt;A total of three billion user credentials were checked in a database populated from numerous sources including law enforcement and public databases.&lt;/p&gt;
&lt;p&gt;Using the data set of three billion credentials, Microsoft was able to identify the number of users who were resuing credentials across multiple online services.&lt;/p&gt;
&lt;/div&gt;
&lt;div class="polaris__simple-grid--main"&gt;
&lt;p&gt;Microsoft forced a password reset for all of those users who were found to have leaked credentials during the scan which took place between January and March 2019.&lt;/p&gt;
&lt;p&gt;"On the enterprise side, Microsoft will elevate the user risk and alert the administrator so that a credential reset can be enforced," the company&lt;span&gt; &lt;/span&gt;&lt;a rel="noopener" href="https://www.microsoft.com/securityinsights/identity" target="_blank" class="polaris__link -is-external"&gt;said&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Microsoft also said if users are going to reuse login credentials across different services, enabling a form of&lt;span&gt; &lt;/span&gt;&lt;a href="https://www.itpro.co.uk/security/29982/what-is-two-factor-authentication" class="polaris__link"&gt;multi-factor authentication (MFA)&lt;/a&gt;&lt;span&gt; &lt;/span&gt;is imperative.&lt;/p&gt;
&lt;p&gt;"MFA is an important security mechanism that can dramatically improve your security posture," it said. "Our numbers show that 99.9% of identity attacks have been thwarted by turning on MFA."&lt;/p&gt;
&lt;/div&gt;</description>
      <pubDate>Fri, 06 Dec 2019 12:00:00 Z</pubDate>
      <a10:updated>2019-12-06T12:00:00Z</a10:updated>
    </item>
  </channel>
</rss>