Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Coruna iOS exploit kit uses 23 exploits across 5 chains targeting iOS 13 to 17.2.1

EU project to accelerate hydrogen production in Norway

New RFP template for AI usage control and AI governance

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Commvault confirms that hackers misuse CVE-2025-3928 as zero day in an Azure violation
Identity

Commvault confirms that hackers misuse CVE-2025-3928 as zero day in an Azure violation

userBy userMay 1, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 1, 2025Ravi LakshmananZero Day/Threat Intelligence

Zero Day Violation of Azure

By leveraging CVE-2025-3928, the enterprise data backup platform Commvault revealed that an unknown nation-state threat actor violated the Microsoft Azure environment, but emphasized that there was no evidence of unauthorized data access.

“This activity has impacted a small number of customers that we share with Microsoft, and we work with these customers to provide support,” the company said in the update.

“The important thing is that there is no unauthorized access to customer backup data that protects and protects Commvault, and does not have a significant impact on our business operations and our ability to provide products and services.”

In a recommendation issued on March 7, 2025, Commvault said that on February 20, Microsoft was notified of unauthorized activity within an Azure environment, and that threat actors used CVE-2025-3928 as a zero day. He also said it had rotated the affected credentials to enhance security measures.

This disclosure requires that the US Cybersecurity and Infrastructure Security Agency (CISA) add CVE-2025-3928 to its known Exploitation Vulnerabilities (KEV) catalog and apply the necessary patches to the Commvault web server by May 19, 2025, as it requires a Federal Private Enforcement Division (FCEB) agency.

Cybersecurity

To mitigate the risk posed by such attacks, customers are encouraged to apply conditional access policies to all Microsoft 365, Dynamics 365, Azure AD single tenant app registrations, and rotate and sync client secrets every 90 days between the Azure portal and Commvault.

The company also encourages users to monitor sign-in activity and detect attempts to access from IP addresses other than Alloplisted Range. The following IP addresses are associated with malicious activity –

108.69.148.100 128.92.80.210 184.153.42.129 108.6.189.53, and 159.242.42.20

“These IP addresses are explicitly blocked within conditional access policies and must be monitored by Azure sign-in logs,” Commvault said. “If any attempts to access from these IPS are detected, please report the incident immediately to Commvault Support for further analysis and action.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFrom tech pioneers to “extremists”: Belarusian founders face exile and statelessness
Next Article Horizon Europe offers a GDP return of 11 euros for every 1 euro investment
user
  • Website

Related Posts

Coruna iOS exploit kit uses 23 exploits across 5 chains targeting iOS 13 to 17.2.1

March 4, 2026

New RFP template for AI usage control and AI governance

March 4, 2026

Fake Laravel packages on Packagist deploy RAT on Windows, macOS, and Linux

March 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Coruna iOS exploit kit uses 23 exploits across 5 chains targeting iOS 13 to 17.2.1

EU project to accelerate hydrogen production in Norway

New RFP template for AI usage control and AI governance

Inside the EU’s military innovation push

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.