[0] https://twitter.com/WHHackersBR/status/1118393568656334850
[0] https://twitter.com/WHHackersBR/status/1118393568656334850
(that said, google main page vulnerable to xss is kind of like... what, we're afraid someone will take over google and put some cryptominers on the google.com main page?)
6% of the people received a specific email saying the body of their email was accessed and they had to backtrack.
> This unauthorized access could have allowed unauthorized parties to access and/or view information related to your email account (such as your e-mail address, folder names, the subject lines of e-mails, and the names of other e-mail addresses you communicate with), but not the content of any e-mails or attachments, between January 1st 2019 and March 28th 2019.
Notice it says your email account. The whole email is about the account of the recipient, not those of other recipients. Given that they explicitly worded it this way and people clearly misinterpreted it to mean something else, I hope you can forgive me for being a little skeptical of third-party anecdotes that suggest Microsoft claimed nobody's email contents were accessed...
Why wasn’t that the case before?!
There's always a way to enhance your processes, monitor more indicators, etc. or otherwise improve your security.