logo

CISA Warns of Attacks Targeting Commvault SaaS Environment

ID: 911c2d0a-dc67-5b40-b88c-2d9f586fcee7

STIX ID: report--911c2d0a-dc67-5b40-b88c-2d9f586fcee7

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2025-05-27

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A nation-state actor exploited a critical Commvault webserver zero-day (CVE-2025-3928) in the Azure-hosted Metallic SaaS to obtain Microsoft 365 application credentials for a small set of customers; Commvault and CISA issued advisories, released IOCs, and recommended rotating app secrets, reviewing Entra ID logs, applying conditional access and least-privilege, and other mitigations while Commvault patched the flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.