Commvault attack may put SaaS companies across the world at risk, CISA warns


- Nation-state hackers are abusing a Commvault zero-day to target SaaS companies
- CISA is warning users to patch their systems
- A large-scale campaign is currently ongoing, it was said
The US Cybersecurity and Infrastructure Security Agency (CISA) is warning the recent breach at Commvault could put many Software-as-a-Service (SaaS) providers at risk.
In a recently published security advisory, the agency said the attack is being monitored, and urged Commvault’s customers to mitigate possible risks.
Commvault’s flagship product, Metallic. is a cloud-based SaaS data protection platform that provides secure backup and recovery for Microsoft 365, endpoints, VMs, databases, and other workloads. It is all hosted on Microsoft Azure, and CISA says unnamed threat actors “may have accessed client secrets for Commvault’s (Metallic) Microsoft 365 backup SaaS solution.”
“This provided the threat actors with unauthorized access to Commvault’s customers’ M365 environments that have application secrets stored by Commvault.”
At the same time, Commvault published a blog post in which it said that Microsoft reached out to warn about an ongoing state-sponsored cyberattack.
The company confirmed a “handful of customers” were targeted through a zero-day vulnerability tracked as CVE-2025-3928, an unspecified flaw in Commvault Web Server that can be exploited by a remote, authenticated attacker.
CISA added it to its catalog of known exploited vulnerabilities (KEV) on April 28, giving Federal Civilian Executive Branch (FCEB) agencies a three-week deadline to patch things up. The bug was fixed in versions 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“CISA believes the threat activity may be part of a larger campaign targeting various SaaS companies’ cloud applications with default configurations and elevated permissions,” the agency added in the advisory.
The agency has also made a list of mitigations that companies should follow to minimize the chances of getting struck. These include monitoring Entra audit logs, reviewing Microsoft logs, reviewing the list of Application Registrations and Service Principles in Entra, and more. The entire list can be found on this link.
Via The Register
You might also like
Nation-state hackers are abusing a Commvault zero-day to target SaaS companies CISA is warning users to patch their systems A large-scale campaign is currently ongoing, it was said The US Cybersecurity and Infrastructure Security Agency (CISA) is warning the recent breach at Commvault could put many Software-as-a-Service (SaaS) providers at…
Recent Posts
- Commvault attack may put SaaS companies across the world at risk, CISA warns
- Nintendo’s bold new era is full of safe bets
- NPM users warned dozens of malicious packages aim to steal host and network data
- What Is Matter? We Explain the Smart Home Standard (2025)
- watchOS 12 and tvOS 19 tipped to get a visual revamp, to match the ‘Solarium’ update coming to iOS 19 and macOS 16
Archives
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010