CISA Warns of Attacks Targeting Commvault SaaS Environment
ID: 911c2d0a-dc67-5b40-b88c-2d9f586fcee7
STIX ID: report--911c2d0a-dc67-5b40-b88c-2d9f586fcee7
Feed Name: Dark Reading
Threat Score
A nation-state actor exploited a critical Commvault webserver zero-day (CVE-2025-3928) in the Azure-hosted Metallic SaaS to obtain Microsoft 365 application credentials for a small set of customers; Commvault and CISA issued advisories, released IOCs, and recommended rotating app secrets, reviewing Entra ID logs, applying conditional access and least-privilege, and other mitigations while Commvault patched the flaw.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
