1. Domain like "abcde.teams.microsoft.com" has a CNAME that points to a domain like "abcde.microsoft-teams.com", but "microsoft-teams.com" is no longer registered to or controlled by Microsoft.
2. Hacker registers microsoft-teams.com, gets a LetsEncrypt SSL for it.
3. Send a message to someone with a GIF that was uploaded to "abcde.teams.microsoft.com". Teams thinks it's legit because it's a subdomain of "teams.microsoft.com", and SSL checks out, so it sends the user's auth token along with the HTTP request for the GIF. Problem is, it's sending it to the attacker controlled "abcde.microsoft-teams.com".
4. Since the hacker controls "abcde.microsoft-teams.com", they now have your auth token, which they can use to impersonate you.
Et voila, account takeover.
I'd bet that plenty of whitehats and blackhats have bots automatically crawling domains belonging to tech companies searching for subdomain takeover opportunities.
Can you elaborate a bit on this? I get that these are example domains, but why would "abcde.teams.microsoft.com" (which is presumably controlled by Microsoft) point to a domain "microsoft-teams.com" that is not controlled by Microsoft? Was that a mistake on Microsoft's part, or did the attackers do something clever to gain control of that domain/point a Microsoft-owned subdomain to the attacker's domain?
Microsoft has a lot of these, just random Microsoft-ish domains that were used at one point or another. It's a problem because it makes it harder to look at the domain name as a sanity check against phishing.
It is likely there is a detailed change approval process for updating a *.microsoft.com DNS record. Or that only certain depts can make changes, and only for certain reasons. Someone involved with Teams avoided that by using a separate domain and a cname record, then they could update their separate domain records more easily. Later someone forgot to register this domain, and/or forgot to update the DNS to somewhere that is over their control, or forgot to put in sufficient checks to prevent tokens being shared with unauthorized servers.
Since you control the DNS for microsoft-teams.com, you can point it to your server. Now both domains point at your server and you get all requests to abcde.teams.microsoft.com. That's how they get cookies.
You can get an SSL certificate because you can serve anything for abcde.teams.microsoft.com. That includes abcde.teams.microsoft.com/.well-known/acme-challenge/* and the .gif (or other) resource you use to steal cookies.
Either abcde.microsoft-teams.com is a typo or you seem to think CNAMEs work like an HTTP redirect, which they don't.
If Microsoft had one of these, they could've caught this before it was exploited.
TLDR; Authorization cookie for an important Account API is sent to *.teams.microsoft.com and they got control of a subdomain of that somehow.