creating files with the .VSDX extension. The crooks would embed a malicious URL in this file leading to a fake Microsoft 365 ...