Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Vicoviodtrap uses the lack of Cisco to create global Honeypot with 5300 compromised devices

May 23, 2025

300 servers and € 3.5 million, confiscated when Europe Strikes Ransomwark Networks worldwide

May 23, 2025

Firewall web applications with open source with zero day detection and bot protection

May 23, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » CISA warns of suspicion of extensive Saas attacks that exploit app secrets and incorrect cloud settings
Global Security

CISA warns of suspicion of extensive Saas attacks that exploit app secrets and incorrect cloud settings

AdminBy AdminMay 23, 2025No Comments3 Mins Read
Broader SaaS Attacks
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


May 23, 2025Red LakshmananCloud security / vulnerability

Wide attacks Saas

The US Cybersecurity and Infrastructure Agency (CISA) showed that Commvault monitors cyber -vault activities aimed at the Microsoft Azure Cloud applications.

“Actors threats can access customers’ secrets for Microsoft 365 (M365) Commvault (Metallic) Microsoft 365 (M365) Software Solution (SAAS) held at Azure,” Agency – Note.

“This gave the subject threats to the unauthorized access to the M365 COMMVAULT clients that have the secrets of the app stored by Commvault.”

Further, CISA noted that the activity could be part of a wider company aimed at various software providers (SAAS) with default configurations and increased permits.

The Advisory Company comes a few weeks after Commvault found that Microsoft reported the company in February 2025 of unauthorized activity by the actor on the threat of a nation -state.

Incident led to revelation that subjects threatens exploit vulnerability of the zero day (Cve-2025-3928)), an uncertain lack of the Commvault web -server that allows a remote, authentified attacker to create and perform web.

“Based on industry experts, this actor threats uses sophisticated methods to try access to M365 customer environment,” Commvault – Note In the ad. “This actor threats can access the subsidies of the App Appeal, which some Commvault customers use to authenticate their M365 conditions.”

Cybersecurity

Commvault said he had taken several correction actions, including the powers of turning applications for M365, but stressed that there was no unauthorized access to customer backup data.

To mitigate such threats, CISA recommends users and administrators to follow the recommendations below –

  • Monitoring Magazines on audit Entra for unauthorized modifications or accounts for service directors initiated by Commvault applications/Directors
  • Review Microsoft Magazines (Entra Audit, Entra, entered
  • For single tenant applications, implement conditional access policies that restricts the authentication of the Application Director to the approved IP -Adress, which is listed in the Allist IP list, listed in the Allist list.
  • View the list of registrations and service directors in Entra with consent to higher privileges than business need
  • Limit Access to Commvault Management Interfaces To Reliable Networks and Administrative Systems
  • Identify and lock the attempts of the traveled path and download suspicious files by deploying web applications and deleting external access to Commvault applications

Cisa who added Cve-2025-3928 At the end of April 2025, the well -known exploited vulnerable catalog said she continued to investigate the harmful activities in cooperation with partner organizations.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Vicoviodtrap uses the lack of Cisco to create global Honeypot with 5300 compromised devices

May 23, 2025

300 servers and € 3.5 million, confiscated when Europe Strikes Ransomwark Networks worldwide

May 23, 2025

Firewall web applications with open source with zero day detection and bot protection

May 23, 2025

The US Demonrates Danabot Malf

May 23, 2025

Duo Gitlab’s vulnerability allowed the attackers to steal AI with hidden tips

May 23, 2025

Chinese hackers operate the shortage of CityWorks Trimble to penetrate the US public networks

May 22, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Vicoviodtrap uses the lack of Cisco to create global Honeypot with 5300 compromised devices

May 23, 2025

300 servers and € 3.5 million, confiscated when Europe Strikes Ransomwark Networks worldwide

May 23, 2025

Firewall web applications with open source with zero day detection and bot protection

May 23, 2025

The US Demonrates Danabot Malf

May 23, 2025

Duo Gitlab’s vulnerability allowed the attackers to steal AI with hidden tips

May 23, 2025

CISA warns of suspicion of extensive Saas attacks that exploit app secrets and incorrect cloud settings

May 23, 2025

Chinese hackers operate the shortage of CityWorks Trimble to penetrate the US public networks

May 22, 2025

Unslaw the deficiencies of the Versa concert allow the attackers to avoid the dockery and the compromise host

May 22, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Vicoviodtrap uses the lack of Cisco to create global Honeypot with 5300 compromised devices

May 23, 2025

300 servers and € 3.5 million, confiscated when Europe Strikes Ransomwark Networks worldwide

May 23, 2025

Firewall web applications with open source with zero day detection and bot protection

May 23, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.