UK NCSC experts: It’s the CVE-2020-16952. It can be exploited when a user uploads a specially crafted application package to an affected version of SharePoint.
NCSC launched some dedicated services, as Suspicious Email Reporting Service, and a Cyber Aware campaign to help protecting people against COVID-19 scams, phishing and attacks.
The National Cyber Security Centre (NCSC) assesses with the highest level of probability that on 28 October 2019 the GRU carried out large-scale, disruptive cyber-attacks.
The NCSC cyber security experts: The goal is credential harvesting. It has been active since at least July 2018 through various iterations, with a recent spike in early October 2019.