<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #MFA</title><description>Cybersecurity articles tagged #MFA on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Auditing Entra ID MFA Gaps with PowerShell and Microsoft Graph</title><link>https://runtimerebel.com/blog/auditing-entra-id-mfa-gaps-with-powershell-and-microsoft-graph</link><guid isPermaLink="true">https://runtimerebel.com/blog/auditing-entra-id-mfa-gaps-with-powershell-and-microsoft-graph</guid><description>A new PowerShell script helps security teams identify Microsoft Entra ID users not registered for MFA or using weaker authentication methods.</description><pubDate>Fri, 21 Aug 2026 08:32:39 GMT</pubDate><category>Microsoft Entra ID</category><category>MFA</category><category>PowerShell</category><category>Identity Access</category><category>Microsoft Graph</category></item><item><title>Securing SSO Environments Against Modern Credential Attacks</title><link>https://runtimerebel.com/blog/securing-sso-environments-against-modern-credential-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-sso-environments-against-modern-credential-attacks</guid><description>An analysis of SSO vulnerabilities and strategies for hardening identity providers against phishing, password spraying, and session hijacking.</description><pubDate>Tue, 28 Jul 2026 14:10:10 GMT</pubDate><category>Sso Security</category><category>MFA</category><category>Credential Stuffing</category><category>Identity Hardening</category><category>FIDO2</category></item><item><title>South Korea Diplomatic Academy Breach Exposes MFA Staff Data</title><link>https://runtimerebel.com/blog/south-korea-diplomatic-academy-breach-exposes-mfa-staff-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/south-korea-diplomatic-academy-breach-exposes-mfa-staff-data</guid><description>South Korea&apos;s National Diplomatic Academy suffered a 10-month data breach, exposing personal info of MFA employees and diplomats globally.</description><pubDate>Wed, 22 Jul 2026 21:12:04 GMT</pubDate><category>South Korea</category><category>MFA</category><category>Diplomatic Academy</category><category>Data Breach</category><category>Government Security</category></item><item><title>Bypassing Identity Verification: Mitigating Phishing &amp; MFA Fatigue</title><link>https://runtimerebel.com/blog/bypassing-identity-verification-mitigating-phishing-mfa-fatigue</link><guid isPermaLink="true">https://runtimerebel.com/blog/bypassing-identity-verification-mitigating-phishing-mfa-fatigue</guid><description>Attackers exploit weak identity verification through phishing, MFA fatigue, and social engineering. Learn best practices to secure access.</description><pubDate>Wed, 10 Jun 2026 17:16:10 GMT</pubDate><category>Identity Verification</category><category>MFA</category><category>Phishing</category><category>MFA Fatigue</category><category>Social Engineering</category><category>Authentication</category><category>Access Security</category></item><item><title>Dashlane Account Lockouts: Brute-Force Attacks Target Password Manager Users</title><link>https://runtimerebel.com/blog/dashlane-account-lockouts-brute-force-attacks-target-password-manager-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/dashlane-account-lockouts-brute-force-attacks-target-password-manager-users</guid><description>Dashlane users are experiencing widespread account lockouts due to brute-force attacks. Learn how credential stuffing impacts password managers and mitigation strategies.</description><pubDate>Mon, 01 Jun 2026 21:15:04 GMT</pubDate><category>Dashlane</category><category>Password Manager</category><category>Brute Force</category><category>Credential Stuffing</category><category>Account Lockout</category><category>MFA</category></item><item><title>23andMe 2023 Data Breach: AG Sues Over Exposed Health Data</title><link>https://runtimerebel.com/blog/23andme-2023-data-breach-ag-sues-over-exposed-health-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/23andme-2023-data-breach-ag-sues-over-exposed-health-data</guid><description>California AG sues 23andMe for a 2023 credential stuffing data breach exposing genetic and personal health data of 6.9 million users.</description><pubDate>Fri, 29 May 2026 20:54:34 GMT</pubDate><category>23andMe</category><category>Data Breach</category><category>Credential Stuffing</category><category>Genetic Data</category><category>Health Data</category><category>California AG</category><category>MFA</category></item><item><title>OpenAI Advanced Account Security: Mitigating AI Identity Risks</title><link>https://runtimerebel.com/blog/openai-advanced-account-security-mitigating-ai-identity-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-advanced-account-security-mitigating-ai-identity-risks</guid><description>OpenAI releases Advanced Account Security features for ChatGPT, including FIDO2 support and session management to prevent unauthorized account access.</description><pubDate>Mon, 04 May 2026 12:44:00 GMT</pubDate><category>OpenAI</category><category>ChatGPT</category><category>FIDO2</category><category>MFA</category><category>Identity Protection</category><category>Account Security</category></item><item><title>Quantifying Cyber Risk: CISO Budgeting with Insurance Data</title><link>https://runtimerebel.com/blog/quantifying-cyber-risk-ciso-budgeting-with-insurance-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/quantifying-cyber-risk-ciso-budgeting-with-insurance-data</guid><description>CISOs now have powerful data from cyber insurance policies to quantify cyber risk, demonstrate ROI, and justify critical security investments to boards.</description><pubDate>Wed, 29 Apr 2026 05:10:52 GMT</pubDate><category>Cyber Insurance</category><category>CISO</category><category>Budget</category><category>Risk Management</category><category>Ransomware</category><category>MFA</category><category>EDR</category><category>Security Strategy</category><category>Financial Impact</category></item><item><title>Identity-First Zero Trust Strategies to Prevent Credential Theft</title><link>https://runtimerebel.com/blog/identity-first-zero-trust-strategies-to-prevent-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/identity-first-zero-trust-strategies-to-prevent-credential-theft</guid><description>Learn how Zero Trust architecture mitigates stolen credentials and lateral movement by enforcing device trust, least privilege, and continuous verification.</description><pubDate>Tue, 14 Apr 2026 16:32:08 GMT</pubDate><category>Zero Trust</category><category>Identity Security</category><category>Credential Theft</category><category>Least Privilege</category><category>MFA</category></item><item><title>Hardening Endpoint Management Systems: CISA Alert on Intune Attacks</title><link>https://runtimerebel.com/blog/hardening-endpoint-management-systems-cisa-alert-on-intune-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/hardening-endpoint-management-systems-cisa-alert-on-intune-attacks</guid><description>CISA warns of active cyberattacks targeting endpoint management systems, specifically Microsoft Intune.</description><pubDate>Thu, 19 Mar 2026 00:37:58 GMT</pubDate><category>Microsoft Intune</category><category>Endpoint Management</category><category>Stryker Corporation</category><category>CISA</category><category>MFA</category><category>RBAC</category><category>Cyberattack</category></item><item><title>Proactive Defense: Hardening Against Destructive Cyberattacks (2026 Edition)</title><link>https://runtimerebel.com/blog/proactive-defense-hardening-against-destructive-cyberattacks-2026-edition</link><guid isPermaLink="true">https://runtimerebel.com/blog/proactive-defense-hardening-against-destructive-cyberattacks-2026-edition</guid><description>Comprehensive guide on hardening against destructive cyberattacks, including wipers, ransomware, and data destruction tactics across on-premises and cloud environments.</description><pubDate>Fri, 06 Mar 2026 16:26:03 GMT</pubDate><category>Destructive Attacks</category><category>Wiper Malware</category><category>Ransomware</category><category>Hardening</category><category>Cyber Resilience</category><category>MFA</category><category>Backup</category><category>Active Directory</category><category>Kubernetes</category><category>CI CD</category><category>Cloud Security</category><category>Network Segmentation</category></item><item><title>Credential Abuse Risks: Solving Microsoft Entra ID MFA Coverage Gaps</title><link>https://runtimerebel.com/blog/credential-abuse-risks-solving-microsoft-entra-id-mfa-coverage-gaps</link><guid isPermaLink="true">https://runtimerebel.com/blog/credential-abuse-risks-solving-microsoft-entra-id-mfa-coverage-gaps</guid><description>Examine how coverage gaps in Microsoft Entra ID and Okta MFA implementations allow attackers to exploit valid credentials within Windows network environments.</description><pubDate>Thu, 05 Mar 2026 12:18:56 GMT</pubDate><category>MFA</category><category>Microsoft Entra ID</category><category>Credential Abuse</category><category>Windows Security</category><category>Identity Provider</category></item></channel></rss>