Microsoft has discovered 44 million user accounts are using usernames and passwords that have been leaked through security breaches.
As ZDNet reports, the vulnerable account logins were discovered when Microsoft's threat research team carried out a scan of all Microsoft accounts between January and March this year. The accounts were compared to a database of over three billion sets of leaked credentials and resulted in 44 million matches.
These accounts were spread between regular user accounts used by consumers (Microsoft Services Accounts) and enterprise accounts in the form of Microsoft Azure AD logins. In response, Microsoft explained, "For the leaked credentials for which we found a match, we force a password reset. No additional action is required on the consumer side ... On the enterprise side, Microsoft will elevate the user risk and alert the administrator so that a credential reset can be enforced."
Microsoft goes on to recommend that, "Given the frequency of passwords being reused by multiple individuals, it is critical to back your password with some form of strong credential. Multi-Factor Authentication (MFA) is an important security mechanism that can dramatically improve your security posture. Our numbers show that 99.9% of identity attacks have been thwarted by turning on MFA."
SEE ALSO: Absolutely humongous data breach exposes more than a billion recordsPicking a password is always a trade-off between what's memorable and what's strong, which is why using a password manager makes so much sense. But we have another problem: security breaches expose passwords and they shouldn't be used by anyone.
While Microsoft did the right thing resetting the passwords on these account, it currently can't stop a user selecting a new password that's also been exposed as part of a past security breach. A positive next move would be to perform a check when a password is entered to see if it appears on a breach list, and if it is, to reject it and request the user pick something else.
Copyright © 2023 Powered by
Microsoft found 44 million accounts using breached passwords-纤悉无遗网
sitemap
文章
9559
浏览
1556
获赞
2
There are four new iPhones. So which iPhone 12 should you buy?
Not long ago, Apple used to release just two new iPhones per year. That number has now ballooned allFord patents self
Remember the scene in Minority Reportwhere Tom Cruise's self-driving car tries to automatically takeTwitter will take your blue checkmark on April 1 if you don’t pay
Twitter's blue "verified" checkmark was originally a way to tell real accounts from fake one. Then,Dan Stevens' brutal takedown of Boris Johnson makes BBC presenters audibly gasp
People having a go at politicians on live TV is nothing new, but it's not often you get an actor styProposed tax on WhatsApp calls causes massive protests in Lebanon
After word got around in Lebanon that the government was planning to tax WhatsApp calls, thousands oReported Google AI bot will be able to make music from text prompts
As AI slowly creeps it way into every facet of our digital lives — from essay writing to conveTikTok commissions its first musical
This past week, a TikTok musical won a Grammy. Now, riding on the wave of this success, the social pDuckDuckGo is the latest search engine to launch an AI assistant
Search engine DuckDuckGo now has an artificial intelligence-based assistant of its own. Called DuckAThe Homebrew Litecoin Mining Project
It's hard not to be intrigued by Bitcoin, the peer-to-peer digital currency devised by the mysteriouTwitter will take your blue checkmark on April 1 if you don’t pay
Twitter's blue "verified" checkmark was originally a way to tell real accounts from fake one. Then,The Great Resignation hasn't quit in 2022
People aren't ready to quit quitting. You've likely heard of "The Great Resignation", the term referDoors or wheels? TikTok's latest debate
Confused why you are seeing #TeamDoor and #TeamWheel content all over your FYP? We've got you covere5 Great Chrome Extensions You Should Install
With almost 60 percent share of the browser market, Chrome is around three times more popular than iAre the Samsung Galaxy S23 colors really lavender and green?
My unofficial beat at Mashable is complaining about Apple's phone colors. The "deep purple" iPhone wMore layoffs coming to Meta soon report shows
Work at Meta is coming to a standstill as the company prepares for a fresh round of job cuts in the