Passwords have shifted from a security foundation to a primary attack vector; phishing-resistant authentication is no longer a future vision but an operational necessity.
A security vulnerability in Exchange Online allows email sender spoofing under certain conditions, facilitating phishing and social engineering attacks.