CTM360-linked research points to a shift from delayed credential theft to real-time account hijacking, a change that shrinks the defender’s window from hours to seconds.