UNC6671 uses vishing and AitM phishing to steal cloud credentials and MFA tokens, then exfiltrate data from Microsoft 365, ...
Windows kept UAC but stopped making you open a second window.