Comfort Mmoledi,
Your assumption that those SharePoint vulnerabilities have anything to do with these completely unrelated IPv6 Activity log entries is inaccurate.
Though the article you referenced by PaloAlto Networks doesn't specifically mention it, it's been well known since at least July 22nd, per the following excerpt from the CISA article I'll reference below, that these vulnerabilities only affected on-premise SharePoint servers, not Microsoft's own cloud provided SparePojnt servers.
"CISA is aware of active exploitation of a spoofing and RCE vulnerability chain involving CVE-2025-49706 and CVE-2025-49704, enabling unauthorized access to on-premise SharePoint servers."
UPDATE: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities | CISA
Also note that SharePojnt and OneDrive are entirely separate systems operating on the Azure business and Microsoft Personal account-based systems respectively, so even if they might share portions of the same code that caused the vulnerabilities mentioned, that hasn't been confirmed in anything I've seen, nor should it matter, since the vulnerabilities themselves had been patched by Microsoft for their cloud-provided SharePoint servers before the exploitation of some customers unpatched on-premise SharePoint servers occurred. So even if OneDrive had contained similar code that might have been vulnerable, it's reasonable to expect that Microsoft would have realized this fact and fixed that parallel code as well, though I'd have expected them to mention this via a CISA or similar alert if it were actually true.
Microsoft has not been 'quiet about these data breaches' since everyone here with a level head has been stating there's nothing at all suspicious about these notifications, they're simply not something that most of those posting understand, so they're concerned because they don't have any past experience upon which to base the reason the notifications might be appearing in the Activity logs.
Those of us who understand that the mobile device apps that appear to be consistently involved in causing the log entries are often IPv6-based, quite often make connections with different servers in different countries, and in reality, may have little to do with the normal daily activities of the user himself, only find their sudden appearance for a limited subset of users globally an interesting curiosity.
In my case I've seen similar Activity display issues relating to IPv6 and specifically mobile devices as well back shortly after these first started to be supported officially on the Azure business platform a few years ago, since they also started to display with similar characteristics for Microsoft Personal account logins as well. However, since Microsoft clearly indicated more recently in the Activity logs that no maps were displayed for mobile devices, the appearance of these more likely back-end support connections within the Microsoft services operations displayed using IPv6 are obviously confusing to those without that same past experience.
I'm not saying I know for certain what every single one of these activity items might represent, but absolutely nothing I've seen described by anyone in the recent threads relating to these IPv6 entries has appeared truly suspicious, and in fact have always fit some of the less often described situations relating to either Microsoft Authenticator or other mobile applications like OneDrive that are known to operate in different ways than other apps.
Rob