Identity-driven cloud breaches
“Storm-2949” style attacks abuse self-service password reset and social-engineer MFA approvals to take over Entra ID accounts, then move laterally to SharePoint, mailboxes and connected services.
Closed by: least-privilege access reviews, just-in-time admin access (PIM), and phishing-resistant MFA.