Close Menu
TechurzTechurz

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    I’ve tried 3 different smart rings but I keep going back to Apple Watch – here’s why

    September 1, 2025

    You can buy an iPhone 16 Pro for $250 off on Amazon right now – how the deal works

    September 1, 2025

    ‘Cyberpunk 2077’ Is Teasing Something For Three Days From Now

    September 1, 2025
    Facebook X (Twitter) Instagram
    Trending
    • I’ve tried 3 different smart rings but I keep going back to Apple Watch – here’s why
    • You can buy an iPhone 16 Pro for $250 off on Amazon right now – how the deal works
    • ‘Cyberpunk 2077’ Is Teasing Something For Three Days From Now
    • WhatsApp 0-Day, Docker Bug, Salesforce Breach, Fake CAPTCHAs, Spyware App & More
    • 5 days left: Exhibit tables are disappearing for Disrupt 2025
    • Is AI the end of software engineering or the next step in its evolution?
    • Look out, Meta Ray-Bans! These AI glasses just raised over $1M in pre-orders in 3 days
    • How I took control of my email address with a custom domain
    Facebook X (Twitter) Instagram Pinterest Vimeo
    TechurzTechurz
    • Home
    • AI
    • Apps
    • News
    • Guides
    • Opinion
    • Reviews
    • Security
    • Startups
    TechurzTechurz
    Home»Apps»Commvault attack may put SaaS companies across the world at risk, CISA warns
    Apps

    Commvault attack may put SaaS companies across the world at risk, CISA warns

    TechurzBy TechurzMay 26, 2025No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Holographic representation of cloud computing over open businessman's hand
    Share
    Facebook Twitter LinkedIn Pinterest Email


    • Nation-state hackers are abusing a Commvault zero-day to target SaaS companies
    • CISA is warning users to patch their systems
    • A large-scale campaign is currently ongoing, it was said

    The US Cybersecurity and Infrastructure Security Agency (CISA) is warning the recent breach at Commvault could put many Software-as-a-Service (SaaS) providers at risk.

    In a recently published security advisory, the agency said the attack is being monitored, and urged Commvault’s customers to mitigate possible risks.

    Commvault’s flagship product, Metallic. is a cloud-based SaaS data protection platform that provides secure backup and recovery for Microsoft 365, endpoints, VMs, databases, and other workloads. It is all hosted on Microsoft Azure, and CISA says unnamed threat actors “may have accessed client secrets for Commvault’s (Metallic) Microsoft 365 backup SaaS solution.”


    You may like

    “This provided the threat actors with unauthorized access to Commvault’s customers’ M365 environments that have application secrets stored by Commvault.”

    At the same time, Commvault published a blog post in which it said that Microsoft reached out to warn about an ongoing state-sponsored cyberattack.

    The company confirmed a “handful of customers” were targeted through a zero-day vulnerability tracked as CVE-2025-3928, an unspecified flaw in Commvault Web Server that can be exploited by a remote, authenticated attacker.

    CISA added it to its catalog of known exploited vulnerabilities (KEV) on April 28, giving Federal Civilian Executive Branch (FCEB) agencies a three-week deadline to patch things up. The bug was fixed in versions 11.36.46, 11.32.89, 11.28.141, and 11.20.217 for Windows and Linux platforms.

    Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

    “CISA believes the threat activity may be part of a larger campaign targeting various SaaS companies’ cloud applications with default configurations and elevated permissions,” the agency added in the advisory.

    The agency has also made a list of mitigations that companies should follow to minimize the chances of getting struck. These include monitoring Entra audit logs, reviewing Microsoft logs, reviewing the list of Application Registrations and Service Principles in Entra, and more. The entire list can be found on this link.

    Via The Register

    You might also like

    Attack CISA Commvault Companies put Risk SaaS warns world
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleGet This $25 Microsoft Office License
    Next Article Breaking RSA encryption just got 20x easier for quantum computers
    Techurz
    • Website

    Related Posts

    Security

    China Is About to Show Off Its New High-Tech Weapons to the World

    September 1, 2025
    Startups

    Big Tech Companies in the US Have Been Told Not to Apply the Digital Services Act

    August 31, 2025
    Startups

    Use Rosetta Stone to Impress Clients Around the World with Fluent, Natural Speech

    August 31, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Start Saving Now: An iPhone 17 Pro Price Hike Is Likely, Says New Report

    August 17, 20258 Views

    You Can Now Get Starlink for $15-Per-Month in New York, but There’s a Catch

    July 11, 20257 Views

    Non-US businesses want to cut back on using US cloud systems

    June 2, 20257 Views
    Our Picks

    I’ve tried 3 different smart rings but I keep going back to Apple Watch – here’s why

    September 1, 2025

    You can buy an iPhone 16 Pro for $250 off on Amazon right now – how the deal works

    September 1, 2025

    ‘Cyberpunk 2077’ Is Teasing Something For Three Days From Now

    September 1, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2025 techurz. Designed by Pro.

    Type above and press Enter to search. Press Esc to cancel.