Attackers use external Teams accounts and remote-support tools to gain credential-backed access that can move laterally ...