Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach

May 1, 2025, 8:26 p.m.

Description

Commvault, an enterprise data backup platform, disclosed a breach in its Microsoft Azure environment by an unknown nation-state threat actor. The attackers exploited CVE-2025-3928 as a zero-day vulnerability, affecting a small number of shared customers with Microsoft. Commvault emphasized that no unauthorized access to customer backup data occurred and there was no material impact on business operations. The company has implemented security measures, including credential rotation and enhanced monitoring. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog, requiring federal agencies to patch affected systems. Commvault advised customers to apply Conditional Access policies, rotate client secrets, and monitor sign-in activity from specific IP addresses associated with malicious activity.

Date

  • Created: May 1, 2025, 8:13 p.m.
  • Published: May 1, 2025, 8:13 p.m.
  • Modified: May 1, 2025, 8:26 p.m.

Indicators

  • 184.153.42.129
  • 159.242.42.20
  • 128.92.80.210
  • 108.69.148.100
  • 108.6.189.53

Attack Patterns