The attacks exploit two critical vulnerabilities — CVE-2025-49706, a spoofing vulnerability, and CVE-2025-49704, a remote code execution flaw — which affect only on-premises SharePoint servers. Microsoft confirmed that SharePoint Online in Microsoft 365 remains unaffected.
What we know about the threat actors
Linen…








