logo

CISA Updates Alert On Commvault Metallic Exploitation

ID: 02a91bdf-c94f-5071-b820-4b45d45c711e

STIX ID: report--02a91bdf-c94f-5071-b820-4b45d45c711e

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

## Executive Summary CISA warns of active supply-chain exploitation of Commvault’s Metallic SaaS backup platform where attackers leveraged stolen service-principal credentials and poorly stored client secrets to authenticate to customer Microsoft Entra ID tenants (CVE-2025-3928 is listed in CISA’s KEV); the advisory describes observed unauthorized sign-ins, credential modifications, and lateral movement into M365 environments and provides immediate mitigation, rotation, audit, and hardening guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.