Microsoft Self-Service Password Reset abused in Azure data theft attacks
…The hacker then reset the password, removed the MFA controls, and enrolled Microsoft Authenticator on their device. Targeting Microsoft 365 apps After hijacking the accounts, Storm-2949 used the Microsoft Graph API…