216.73.216.6

Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach

· Published 01/05/2025 20:13 · Modified 01/05/2025 20:26

Export JSON

Essential information

Published
01/05/2025 20:13
Modified
01/05/2025 20:26
Tags
2025-05-01 CVE-2025-3928 azure ad data breach dynamics 365 enterprise backup microsoft azure
Related entities
5 observables, 7 techniques (mitre)

Description

Commvault, an enterprise data backup platform, disclosed a breach in its environment by an unknown nation-state threat actor. The attackers exploited as a zero-day vulnerability, affecting a small number of shared customers with Microsoft. Commvault emphasized that no unauthorized access to customer backup data occurred and there was no material impact on business operations. The company has implemented security measures, including credential rotation and enhanced monitoring. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch affected systems. Commvault advised customers to apply Conditional Access policies, rotate client secrets, and monitor sign-in activity from specific IP addresses associated with malicious activity.

External references