Microsoft users' commercial (Microsoft Entra) or consumer (Microsoft account) sign-in experiences will remain unchanged.
The attacker can also use the compromised account to message or email colleagues with additional phishing messages.
Digital thieves – quite possibly Kremlin-linked baddies – have been emailing out bogus Microsoft Teams meeting invites ... Broker in the device code sign-in flow," and included in the above-linked ...