CISA warns about the recent breach at Commvault that could potentially put many Software-as-a-Service (SaaS) providers at risk.
State-sponsored attackers are abusing a zero-day vulnerability in Commvault Web Server to target SaaS companies, as confirmed by Commvault and Microsoft.
CISA advises Commvault's customers to patch their systems and follow mitigations to minimize the risk of unauthorized access to client environments.
A large-scale campaign targeting various SaaS companies' cloud applications with default configurations and elevated permissions is currently ongoing, according to CISA.