HomeSecurityCISA warns of suspected broader SaaS attacks

CISA warns of suspected broader SaaS attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) revealed Thursday that Commvault is monitoring cyberthreat activity targeting applications hosted in Microsoft Azure. CISA also noted that the activity may be part of a broader campaign targeting cloud infrastructure , exploiting default settings and elevated access privileges.

See also: JPMorgan urges redefinition of SaaS security

CISA SaaS

This warning was issued a few weeks after Commvault announced that Microsoft had notified it, in February 2025, of unauthorized activity within its Azure environment by a state-sponsored threat actor.

The incident led to the discovery that threat actors were exploiting a zero-day (CVE-2025-3928), an unspecified vulnerability in Commvault's Web server, that allows a remote, authorized attacker to create and execute web shells.

Commvault said it has taken several corrective actions, including changing application credentials for M365, but stressed that there was no unauthorized access to customer backup data.

See also: What you need to know about Ransomware-as-a-Service (RaaS)

CISA, which added the CVE-2025-3928 vulnerability to the List of Known Exploitable Vulnerabilities in late April 2025, said it continues to investigate the malicious activity in collaboration with partner organizations.

cisa attacks SaaS
CISA warns of suspected broader SaaS attacks

A key takeaway from these incidents is the growing need for enhanced security in cloud services, particularly in environments with default settings and elevated access privileges. Attacks of this nature demonstrate how cybercriminals—and particularly state-sponsored threat actors—exploit vulnerabilities in both infrastructure and often overlooked security parameters, such as unmodified default credentials or excessive privileges in SaaS services.

The Commvault case also highlights the importance of collaboration between private companies and government agencies like CISA, as well as the usefulness of tools like the Known Vulnerabilities List. Organizations relying on cloud services should strengthen their risk management by implementing practices such as the principle of least privilege, regular software updates, and continuous activity monitoring.

See also: BeyondTrust: Hackers breached Remote Support SaaS tools

What is becoming clear is that cloud security is not the responsibility of the provider alone — it is a shared responsibility between providers and customers.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS