時価総額: $2.2043T 0.58%
ボリューム(24時間): $56.8553B 3.76%
  • 時価総額: $2.2043T 0.58%
  • ボリューム(24時間): $56.8553B 3.76%
  • 恐怖と貪欲の指数:
  • 時価総額: $2.2043T 0.58%
暗号
トピック
暗号化
ニュース
暗号造園
動画
トップニュース
暗号
トピック
暗号化
ニュース
暗号造園
動画
bitcoin
bitcoin

$87959.907984 USD

1.34%

ethereum
ethereum

$2920.497338 USD

3.04%

tether
tether

$0.999775 USD

0.00%

xrp
xrp

$2.237324 USD

8.12%

bnb
bnb

$860.243768 USD

0.90%

solana
solana

$138.089498 USD

5.43%

usd-coin
usd-coin

$0.999807 USD

0.01%

tron
tron

$0.272801 USD

-1.53%

dogecoin
dogecoin

$0.150904 USD

2.96%

cardano
cardano

$0.421635 USD

1.97%

hyperliquid
hyperliquid

$32.152445 USD

2.23%

bitcoin-cash
bitcoin-cash

$533.301069 USD

-1.94%

chainlink
chainlink

$12.953417 USD

2.68%

unus-sed-leo
unus-sed-leo

$9.535951 USD

0.73%

zcash
zcash

$521.483386 USD

-2.87%

暗号通貨のニュース記事

Sisense データ侵害により重要インフラ部門の認証情報が侵害される

2024/04/12 08:08

サイバーセキュリティ・インフラストラクチャセキュリティ庁 (CISA) は、企業が複数のサードパーティオンラインサービスを追跡できるようにするビジネスインテリジェンス企業である Sisense の侵害を調査しています。 Sisense は顧客に対し、会社と共有している認証情報と秘密情報をリセットするよう促し、Sisense アプリケーション内で使用される認証情報のローテーションと注意を勧告しました。

Sisense データ侵害により重要インフラ部門の認証情報が侵害される

Cybersecurity Breach at Sisense: Critical Infrastructure Sector Organizations Impacted

Sisense でのサイバーセキュリティ侵害: 重要インフラ部門の組織が影響を受ける

The United States Cybersecurity and Infrastructure Security Agency (CISA) has initiated an investigation into a data breach at business intelligence company Sisense. Sisense's products enable businesses to monitor the status of various external online services through a centralized dashboard.

米国サイバーセキュリティ・インフラセキュリティ庁(CISA)は、ビジネスインテリジェンス企業Sisenseのデータ侵害に関する調査を開始した。 Sisense の製品を使用すると、企業は集中ダッシュボードを通じてさまざまな外部オンライン サービスのステータスを監視できます。

CISA has strongly advised all Sisense customers to reset any credentials and secrets shared with the company, a recommendation previously issued by Sisense on April 10th.

CISA は、Sisense のすべての顧客に対し、同社と共有されている資格情報と機密事項をリセットするよう強く勧告しました。これは、Sisense が 4 月 10 日に発行した勧告です。

Sisense, headquartered in New York City, boasts over a thousand customers across multiple industries, including finance, telecommunications, healthcare, and higher education. On April 10th, Sangram Dash, Sisense's Chief Information Security Officer, informed customers of reports indicating that "certain Sisense company information may have been made available on what we have been advised is a restricted access server."

ニューヨーク市に本社を置く Sisense は、金融、電気通信、ヘルスケア、高等教育など、複数の業界にわたって 1,000 を超える顧客を誇っています。 4 月 10 日、Sisense の最高情報セキュリティ責任者である Sangram Dash は、「特定の Sisense 企業情報が、アクセスが制限されているサーバー上で利用可能になった可能性がある」ことを示す報告を顧客に通知しました。

"We are treating this matter with the utmost seriousness and have promptly commenced an investigation," Dash stated. "We have enlisted industry-leading experts to aid in our investigations. Our business operations have not been interrupted by this incident. However, as a precautionary measure, we strongly urge you to immediately change any credentials you use within your Sisense application."

「我々はこの問題を最大限の真剣に受け止めており、直ちに調査を開始した」とダッシュ氏は述べた。 「当社は業界をリードする専門家に調査の協力を依頼しました。この事件により当社の事業運営は中断されていません。ただし、予防措置として、Sisense アプリケーション内で使用している認証情報を直ちに変更することを強くお勧めします。」

CISA's advisory acknowledges its collaboration with private industry partners in response to the incident, particularly considering the potential impact on critical infrastructure sectors. CISA pledged to provide updates as more information becomes available.

CISA の勧告は、特に重要なインフラ分野への潜在的な影響を考慮して、事件への対応における民間業界パートナーとの協力を認めています。 CISA は、より多くの情報が入手可能になり次第、最新情報を提供することを約束した。

Sisense declined to comment when contacted about the accuracy of information shared by reliable sources close to the investigation. These sources indicate that the breach likely originated with the attackers' access to Sisense's Gitlab code repository. Within this repository, a token or credential provided the attackers access to Sisense's Amazon S3 buckets in the cloud.

サイセンスは、捜査に近い信頼できる情報源から共有された情報の正確性について問い合わせられた際にコメントを拒否した。これらの情報源は、侵害の原因がおそらく Sisense の Gitlab コード リポジトリへの攻撃者によるアクセスであることを示しています。このリポジトリ内で、トークンまたは認証情報を使用して、クラウド内の Sisense の Amazon S3 バケットへのアクセスが攻撃者に提供されました。

Sources further revealed that the attackers utilized their S3 access to exfiltrate terabytes of Sisense customer data, reportedly including millions of access tokens, email account passwords, and even SSL certificates.

情報筋はさらに、攻撃者が S3 アクセスを利用して、数百万のアクセス トークン、電子メール アカウントのパスワード、さらには SSL 証明書を含むテラバイト規模の Sisense 顧客データを窃取したことを明らかにしました。

This incident raises concerns about Sisense's safeguards for protecting sensitive customer data, particularly regarding whether the large volume of stolen data was encrypted while stored on Amazon cloud servers.

この事件は、顧客の機密データを保護するための Sisense の保護措置、特に、盗まれた大量のデータが Amazon クラウド サーバーに保存されている間に暗号化されていたかどうかについての懸念を引き起こしました。

Crucially, the breach has compromised all credentials that Sisense customers used within their dashboards.

重要なのは、この侵害により、Sisense の顧客がダッシュボード内で使用していたすべての認証情報が侵害されたことです。

The incident also highlights the limited scope of Sisense's remediation actions on behalf of customers. Access tokens are essentially text files that enable extended login sessions, sometimes indefinitely. Depending on the service, attackers may be able to reuse these tokens to impersonate victims without presenting valid credentials.

この事件はまた、顧客に代わってSisenseが行う修復措置の範囲が限られていることも浮き彫りにしている。アクセス トークンは基本的にテキスト ファイルであり、これによりログイン セッションの延長 (場合によっては無期限) が可能になります。サービスによっては、攻撃者が有効な資格情報を提示しなくても、これらのトークンを再利用して被害者になりすますことができる場合があります。

Beyond resetting passwords, Sisense customers must assess their individual circumstances and determine whether to change passwords for third-party services previously integrated with Sisense.

Sisense の顧客は、パスワードをリセットするだけでなく、個々の状況を評価し、以前に Sisense に統合されていたサードパーティ サービスのパスワードを変更するかどうかを決定する必要があります。

Following the incident, a public relations firm representing Sisense inquired about KrebsOnSecurity's plans for further updates. Sisense requested an opportunity to provide comments before publication.

事件後、Sisenseを代表する広報会社は、KrebsOnSecurityの更なるアップデートの計画について問い合わせた。 Sisense は、出版前にコメントを提供する機会を求めました。

However, after being confronted with details provided by sources, Sisense reportedly changed its position. "After consulting with Sisense, they have told me that they don't wish to respond," the PR representative stated via email.

しかし、情報筋から提供された詳細に直面した後、Sisenseは立場を変えたと伝えられている。 「Sisenseと相談した結果、返答したくないと言われました」と広報担当者は電子メールで述べた。

Update, 6:49 p.m., ET:

東部時間午後 6 時 49 分更新:

It has been clarified that Sisense utilizes a self-hosted version of Gitlab, not the cloud version managed by Gitlab.com.

Sisense は、Gitlab.com が管理するクラウド バージョンではなく、Gitlab のセルフホスト バージョンを利用していることが明らかになりました。

Sisense's CISO, Dash, has issued a detailed update to customers. The revised guidance includes resetting access tokens across various technologies, such as Microsoft Active Directory credentials, GIT credentials, web access tokens, and single sign-on (SSO) secrets or tokens.

Sisense の CISO である Dash は、顧客に詳細な最新情報を発行しました。改訂されたガイダンスには、Microsoft Active Directory 資格情報、GIT 資格情報、Web アクセス トークン、シングル サインオン (SSO) シークレットまたはトークンなど、さまざまなテクノロジーにわたるアクセス トークンのリセットが含まれています。

Dash's full message to customers is as follows:

Dash の顧客へのメッセージ全文は次のとおりです。

"Good Afternoon,

"こんにちは、

We are following up on our prior communication of April 10, 2024, regarding reports that certain Sisense company information may have been made available on a restricted access server. As noted, we are taking this matter seriously and our investigation remains ongoing.

当社は、特定の Sisense 企業情報がアクセス制限されたサーバーで利用可能になっている可能性があるという報告に関して、2024 年 4 月 10 日の以前の連絡をフォローアップしています。前述のとおり、私たちはこの問題を真剣に受け止めており、調査は継続中です。

Our customers must reset any keys, tokens, or other credentials in their environment used within the Sisense application.

当社の顧客は、Sisense アプリケーション内で使用される環境内のキー、トークン、またはその他の認証情報をリセットする必要があります。

Specifically, you should:

具体的には、次のことを行う必要があります。

  • Change Your Password: Change all Sisense-related passwords on http://my.sisense.com
  • Non-SSO:

    パスワードの変更: http://my.sisense.comSSO 以外の Sisense 関連のパスワードをすべて変更します。

    • Replace the Secret in the Base Configuration Security section with your GUID/UUID.
    • Reset passwords for all users in the Sisense application.
    • Logout all users by running GET /api/v1/authentication/logout_all under Admin user.
  • Single Sign-On (SSO):

    [Base Configuration Security] セクションの Secret を GUID/UUID に置き換えます。Sisense アプリケーションのすべてのユーザーのパスワードをリセットします。Admin ユーザーで GET /api/v1/authentication/logout_all を実行して、すべてのユーザーをログアウトします。シングル サインオン (SSO) :

    • If you use SSO JWT for the user's authentication in Sisense, you will need to update sso.shared_secret in Sisense and then use the newly generated value on the side of the SSO handler.
    • We strongly recommend rotating the x.509 certificate for your SSO SAML identity provider.
    • If you utilize OpenID, it's imperative to rotate the client secret as well.
    • Following these adjustments, update the SSO settings in Sisense with the revised values.
    • Logout all users by running GET /api/v1/authentication/logout_all under Admin user.
  • Customer Database Credentials: Reset credentials in your database that were used in the Sisense application to ensure continuity of connection between the systems.
  • Data Models: Change all usernames and passwords in the database connection string in the data models.
  • User Params: If you are using the User Params feature, reset them.
  • Active Directory/LDAP: Change the username and user password of users whose authorization is used for AD synchronization.
  • HTTP Authentication for GIT: Rotate the credentials in every GIT project.
  • B2D Customers: Use the following API PATCH api/v2/b2d-connection in the admin section to update the B2D connection.
  • Infusion Apps: Rotate the associated keys.
  • Web Access Token: Rotate all tokens.
  • Custom Email Server: Rotate associated credentials.
  • Custom Code: Reset any secrets that appear in custom code Notebooks.

If you need any assistance, please submit a customer support ticket at https://community.sisense.com/t5/support-portal/bd-p/SupportPortal and mark it as critical. We have a dedicated response team on standby to assist with your requests.

Sisense でのユーザー認証に SSO JWT を使用する場合は、Sisense で sso.shared_secret を更新し、SSO ハンドラー側で新しく生成された値を使用する必要があります。SSO SAML の x.509 証明書をローテーションすることを強くお勧めします。 ID プロバイダー。OpenID を利用する場合は、クライアント シークレットもローテーションすることが不可欠です。これらの調整に従って、Sisense の SSO 設定を修正された値で更新します。管理者ユーザーで GET /api/v1/authentication/logout_all を実行して、すべてのユーザーをログアウトします。顧客データベースの認証情報: システム間の接続の継続性を確保するために、Sisense アプリケーションで使用されたデータベースの認証情報をリセットします。データ モデル: データ モデルのデータベース接続文字列内のすべてのユーザー名とパスワードを変更します。ユーザー パラメータ:ユーザー パラメータ機能を使用してリセットします。Active Directory/LDAP: AD 同期に認証が使用されるユーザーのユーザー名とユーザー パスワードを変更します。GIT の HTTP 認証: すべての GIT プロジェクトで資格情報をローテーションします。B2D 顧客: 次の API を使用します。管理セクションで api/v2/b2d-connection にパッチを適用して、B2D 接続を更新します。Infusion アプリ: 関連するキーをローテーションします。Web アクセス トークン: すべてのトークンをローテーションします。カスタム電子メール サーバー: 関連する資格情報をローテーションします。カスタム コード: 表示されるシークレットをリセットします。サポートが必要な場合は、https://community.sisense.com/t5/support-portal/bd-p/SupportPortal でカスタマー サポート チケットを送信し、重要としてマークしてください。当社では、お客様のリクエストに対応するため、専任の対応チームを待機させています。

At Sisense, we give paramount importance to security and are committed to our customers' success. Thank you for your partnership and commitment to our mutual security.

Sisense では、セキュリティを最重要視しており、お客様の成功に全力で取り組んでいます。皆様のパートナーシップと相互の安全への取り組みに感謝いたします。

Regards,

よろしく、

Sangram Dash
Chief Information Security Officer"

サングラムダッシュ最高情報セキュリティ責任者」

免責事項:info@kdj.com

提供される情報は取引に関するアドバイスではありません。 kdj.com は、この記事で提供される情報に基づいて行われた投資に対して一切の責任を負いません。暗号通貨は変動性が高いため、十分な調査を行った上で慎重に投資することを強くお勧めします。

このウェブサイトで使用されているコンテンツが著作権を侵害していると思われる場合は、直ちに当社 (info@kdj.com) までご連絡ください。速やかに削除させていただきます。

2026年08月08日 に掲載されたその他の記事