Microsoft Self-Service Password Reset abused in Azure data theft attacks
…To defend against Storm-2949 attacks, Microsoft recommends following security hardening and best practices that include adopting the principle of least privilege, enabling conditional access policies, adding MFA protection for all users…