Close Menu
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
What's Hot

Spiraling with ChatGPT | TechCrunch

June 15, 2025

Taiwan places export controls on Huawei and SMIC

June 15, 2025

New Spy×Family Musical Announces Anya Forger Actresses – News

June 15, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
  • Home
  • Technology
    • Docker
    • Kubernetes
    • AI
    • Cybersecurity
    • Blockchain
    • Linux
    • Python
    • Tech Update
    • Interview Preparation
    • Internet
  • Entertainment
    • Movies
    • TV Shows
    • Anime
    • Cricket
Luminari | Learn Docker, Kubernetes, AI, Tech & Interview PrepLuminari | Learn Docker, Kubernetes, AI, Tech & Interview Prep
Home » Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach
Cybersecurity

Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach

HarishBy HarishMay 1, 2025No Comments2 Mins Read
Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
Share
Facebook Twitter Pinterest Reddit WhatsApp Email


May 01, 2025Ravie LakshmananZero-Day / Threat Intelligence

Zero-Day in Azure Breach

Enterprise data backup platform Commvault has revealed that an unknown nation-state threat actor breached its Microsoft Azure environment by exploiting CVE-2025-3928 but emphasized there is no evidence of unauthorized data access.

“This activity has affected a small number of customers we have in common with Microsoft, and we are working with those customers to provide assistance,” the company said in an update.

“Importantly, there has been no unauthorized access to customer backup data that Commvault stores and protects, and no material impact on our business operations or our ability to deliver products and services.”

In an advisory issued on March 7, 2025, Commvault said it was notified by Microsoft on February 20 about unauthorized activity within its Azure environment and that the threat actor exploited CVE-2025-3928 as a zero-day. It also said it rotated affected credentials and enhanced security measures.

The disclosure comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-3928 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the necessary patches for Commvault Web Server by May 19, 2025.

Cybersecurity

To mitigate the risk posed by such attacks, customers are advised to apply a Conditional Access policy to all Microsoft 365, Dynamics 365, and Azure AD single-tenant app registrations, and rotate and sync client secrets between Azure portal and Commvault every 90 days.

The company is also urging users to monitor sign-in activity to detect any access attempts originating from IP addresses outside of the allowlisted ranges. The following IP addresses have been associated with malicious activity –

108.69.148.100
128.92.80.210
184.153.42.129
108.6.189.53, and
159.242.42.20

“These IP addresses should be explicitly blocked within your Conditional Access policies and monitored in your Azure sign-in logs,” Commvault said. “If any access attempts from these IPs are detected, please report the incident immediately to Commvault Support for further analysis and action.”

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.



Source link

Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
Previous ArticleBeyoncé kicks off Cowboy Carter tour in Los Angeles with the help of her two daughters
Next Article Multi-wallet usage up 16%, but AI may address crypto fragmentation gap
Harish
  • Website
  • X (Twitter)

Related Posts

Discord Invite Link Hijacking Delivers AsyncRAT and Skuld Stealer Targeting Crypto Wallets

June 14, 2025

Over 269,000 Websites Infected with JSFireTruck JavaScript Malware in One Month

June 13, 2025

Ransomware Gangs Exploit Unpatched SimpleHelp Flaws to Target Victims with Double Extortion

June 13, 2025

Shifting from Monitoring Alerts to Measuring Risk

June 13, 2025

Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware

June 13, 2025

How VexTrio and Affiliates Run a Global Scam Network

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Our Picks

Spiraling with ChatGPT | TechCrunch

June 15, 2025

Taiwan places export controls on Huawei and SMIC

June 15, 2025

New Spy×Family Musical Announces Anya Forger Actresses – News

June 15, 2025

Seth Rogen, Adam Brody, John Mulaney & THR’s Comedy Actors Roundtable

June 15, 2025
Don't Miss
Blockchain

Deep liquidity issue is crypto’s silent structural risk

June 15, 20255 Mins Read

Opinion by: Arthur Azizov, Founder and Investor at B2 VenturesDespite its decentralized nature and big…

Is it the future of finance?

June 14, 2025

Trump Reports $57M Crypto Income From WLFI Venture

June 14, 2025

Former Blockchain Exec Joins SEC As Director Of Trading And Markets

June 13, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to Luminari, your go-to hub for mastering modern tech and staying ahead in the digital world.

At Luminari, we’re passionate about breaking down complex technologies and delivering insights that matter. Whether you’re a developer, tech enthusiast, job seeker, or lifelong learner, our mission is to equip you with the tools and knowledge you need to thrive in today’s fast-moving tech landscape.

Our Picks

Spiraling with ChatGPT | TechCrunch

June 15, 2025

Taiwan places export controls on Huawei and SMIC

June 15, 2025

Google reportedly plans to cut ties with Scale AI

June 14, 2025

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

Facebook X (Twitter) Instagram Pinterest
  • Home
  • About Us
  • Advertise With Us
  • Contact Us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 luminari. Designed by luminari.

Type above and press Enter to search. Press Esc to cancel.