Close Menu
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
What's Hot

Top Startups and High-Tech Funding News for the Weekly Ends June 20, 2025

Harvard International Students: What the Judge’s Judgment Means

Apple is talking to you to win AI startup confusion

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Academy
  • Events
  • Identity
  • International
  • Inventions
  • Startups
    • Sustainability
  • Tech
  • Spanish
Fyself News
Home » Commvault confirms that hackers misuse CVE-2025-3928 as zero day in an Azure violation
Identity

Commvault confirms that hackers misuse CVE-2025-3928 as zero day in an Azure violation

userBy userMay 1, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

May 1, 2025Ravi LakshmananZero Day/Threat Intelligence

Zero Day Violation of Azure

By leveraging CVE-2025-3928, the enterprise data backup platform Commvault revealed that an unknown nation-state threat actor violated the Microsoft Azure environment, but emphasized that there was no evidence of unauthorized data access.

“This activity has impacted a small number of customers that we share with Microsoft, and we work with these customers to provide support,” the company said in the update.

“The important thing is that there is no unauthorized access to customer backup data that protects and protects Commvault, and does not have a significant impact on our business operations and our ability to provide products and services.”

In a recommendation issued on March 7, 2025, Commvault said that on February 20, Microsoft was notified of unauthorized activity within an Azure environment, and that threat actors used CVE-2025-3928 as a zero day. He also said it had rotated the affected credentials to enhance security measures.

This disclosure requires that the US Cybersecurity and Infrastructure Security Agency (CISA) add CVE-2025-3928 to its known Exploitation Vulnerabilities (KEV) catalog and apply the necessary patches to the Commvault web server by May 19, 2025, as it requires a Federal Private Enforcement Division (FCEB) agency.

Cybersecurity

To mitigate the risk posed by such attacks, customers are encouraged to apply conditional access policies to all Microsoft 365, Dynamics 365, Azure AD single tenant app registrations, and rotate and sync client secrets every 90 days between the Azure portal and Commvault.

The company also encourages users to monitor sign-in activity and detect attempts to access from IP addresses other than Alloplisted Range. The following IP addresses are associated with malicious activity –

108.69.148.100 128.92.80.210 184.153.42.129 108.6.189.53, and 159.242.42.20

“These IP addresses are explicitly blocked within conditional access policies and must be monitored by Azure sign-in logs,” Commvault said. “If any attempts to access from these IPS are detected, please report the incident immediately to Commvault Support for further analysis and action.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleFrom tech pioneers to “extremists”: Belarusian founders face exile and statelessness
Next Article Horizon Europe offers a GDP return of 11 euros for every 1 euro investment
user
  • Website

Related Posts

Qilin ransomware adds “Cole Lawyer” feature that puts pressure on victims for larger ransoms

June 20, 2025

Television in Iranian states hijacked mid-distance broadcasts amid geopolitical tensions. $90 million stolen from Crypto Heist

June 20, 2025

Successful In-house SOC 6 steps up to 24 hours a day, 365 days a year

June 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Top Startups and High-Tech Funding News for the Weekly Ends June 20, 2025

Harvard International Students: What the Judge’s Judgment Means

Apple is talking to you to win AI startup confusion

The wavy spy says the man is following him, his wife is afraid

Trending Posts

Sana Yousaf, who was the Pakistani Tiktok star shot by gunmen? |Crime News

June 4, 2025

Trump says it’s difficult to make a deal with China’s xi’ amid trade disputes | Donald Trump News

June 4, 2025

Iraq’s Jewish Community Saves Forgotten Shrine Religious News

June 4, 2025

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Top Startups and High-Tech Funding News for the Weekly Ends June 20, 2025

Apple is talking to you to win AI startup confusion

Mira Murati’s AI Startup Thinking Machine Lab emerges from stealth at $20 billion seed and $1 billion valuation

Elon Musk’s AI startup Xai will increase bond yields to 12.5% ​​with a $5 billion debt hike due to weak investor demand

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.