Commvault says recent breach didn't impact customer backup data
ID: 5b738274-a109-5dcb-bc1c-2995bf9b207b
STIX ID: report--5b738274-a109-5dcb-bc1c-2995bf9b207b
Feed Name: Bleeping Computer
Threat Score
**Commvault disclosed that a nation-state threat actor breached its Azure environment in early 2025 by exploiting a now-patched zero-day (CVE-2025-3928) in Commvault Web Server to deploy webshells; the company reports no unauthorized access to customer backup data, a limited customer impact, and has published IOCs and mitigation guidance while coordinating with CISA, the FBI, and external security firms.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
