They just claim to have identified abuse of an "SSPR" attack happening against Azure AD in the wild. What part is a lie?
https://www.cloudflare.com/learning/security/glossary/attack...
An "attack vector" is not necessarily a TTP used by threat actors, it is a way in. Whether it is used or unused, an attack vector is an attack vector.
Yes, they've documented threat actors actively using it. And SSPR used against several other services before this one. But the claim is in the lede sentence: "novel attack vector".