|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
CISA(사이버보안 및 인프라 보안국)는 기업이 여러 제3자 온라인 서비스를 추적할 수 있도록 지원하는 비즈니스 인텔리전스 회사인 Sisense에서 발생한 침해 사고를 조사하고 있습니다. Sisense는 고객에게 회사와 공유된 모든 자격 증명과 비밀을 재설정할 것을 촉구하고 Sisense 애플리케이션 내에서 사용되는 모든 자격 증명의 순환과 주의를 권고했습니다.

Cybersecurity Breach at Sisense: Critical Infrastructure Sector Organizations Impacted
Sisense의 사이버 보안 침해: 중요 인프라 부문 조직이 영향을 받음
The United States Cybersecurity and Infrastructure Security Agency (CISA) has initiated an investigation into a data breach at business intelligence company Sisense. Sisense's products enable businesses to monitor the status of various external online services through a centralized dashboard.
미국 사이버보안 및 인프라 보안국(CISA)이 비즈니스 인텔리전스 기업인 Sisense의 데이터 침해에 대한 조사를 시작했습니다. Sisense의 제품을 사용하면 기업은 중앙 집중식 대시보드를 통해 다양한 외부 온라인 서비스의 상태를 모니터링할 수 있습니다.
CISA has strongly advised all Sisense customers to reset any credentials and secrets shared with the company, a recommendation previously issued by Sisense on April 10th.
CISA는 모든 Sisense 고객에게 회사와 공유된 모든 자격 증명과 비밀을 재설정할 것을 강력히 권고했습니다. 이는 이전에 Sisense가 4월 10일 발표한 권장 사항입니다.
Sisense, headquartered in New York City, boasts over a thousand customers across multiple industries, including finance, telecommunications, healthcare, and higher education. On April 10th, Sangram Dash, Sisense's Chief Information Security Officer, informed customers of reports indicating that "certain Sisense company information may have been made available on what we have been advised is a restricted access server."
뉴욕시에 본사를 둔 Sisense는 금융, 통신, 의료, 고등 교육 등 다양한 산업 분야에 걸쳐 천 명 이상의 고객을 보유하고 있습니다. 4월 10일, Sisense의 최고 정보 보안 책임자인 Sangram Dash는 고객에게 "특정 Sisense 회사 정보가 제한된 액세스 서버라고 알려졌던 것에서 이용 가능하게 되었을 수 있다"는 보고를 알렸습니다.
"We are treating this matter with the utmost seriousness and have promptly commenced an investigation," Dash stated. "We have enlisted industry-leading experts to aid in our investigations. Our business operations have not been interrupted by this incident. However, as a precautionary measure, we strongly urge you to immediately change any credentials you use within your Sisense application."
대시는 "우리는 이 문제를 매우 심각하게 다루고 있으며 즉시 조사를 시작했다"고 말했다. "우리는 조사를 돕기 위해 업계 최고의 전문가를 모집했습니다. 이 사건으로 인해 우리의 비즈니스 운영이 중단되지 않았습니다. 그러나 예방 조치로 Sisense 애플리케이션에서 사용하는 모든 자격 증명을 즉시 변경하시기 바랍니다."
CISA's advisory acknowledges its collaboration with private industry partners in response to the incident, particularly considering the potential impact on critical infrastructure sectors. CISA pledged to provide updates as more information becomes available.
CISA의 자문은 특히 중요한 인프라 부문에 대한 잠재적 영향을 고려하여 사고에 대응하여 민간 업계 파트너와의 협력을 인정합니다. CISA는 더 많은 정보가 나오면 업데이트를 제공할 것을 약속했습니다.
Sisense declined to comment when contacted about the accuracy of information shared by reliable sources close to the investigation. These sources indicate that the breach likely originated with the attackers' access to Sisense's Gitlab code repository. Within this repository, a token or credential provided the attackers access to Sisense's Amazon S3 buckets in the cloud.
Sisense는 조사에 근접한 신뢰할 수 있는 출처가 공유한 정보의 정확성에 대해 연락을 받았을 때 논평을 거부했습니다. 이러한 소스는 침해가 공격자가 Sisense의 Gitlab 코드 저장소에 액세스하면서 시작되었을 가능성이 있음을 나타냅니다. 이 저장소 내에서 토큰 또는 자격 증명은 공격자가 클라우드에 있는 Sisense의 Amazon S3 버킷에 대한 액세스를 제공했습니다.
Sources further revealed that the attackers utilized their S3 access to exfiltrate terabytes of Sisense customer data, reportedly including millions of access tokens, email account passwords, and even SSL certificates.
소식통에 따르면 공격자는 S3 액세스를 활용하여 수백만 개의 액세스 토큰, 이메일 계정 비밀번호, 심지어 SSL 인증서까지 포함하여 테라바이트 규모의 Sisense 고객 데이터를 유출한 것으로 나타났습니다.
This incident raises concerns about Sisense's safeguards for protecting sensitive customer data, particularly regarding whether the large volume of stolen data was encrypted while stored on Amazon cloud servers.
이 사건은 특히 대량의 도난 데이터가 Amazon 클라우드 서버에 저장되어 있는 동안 암호화되었는지 여부와 관련하여 민감한 고객 데이터를 보호하기 위한 Sisense의 보호 조치에 대한 우려를 불러일으킵니다.
Crucially, the breach has compromised all credentials that Sisense customers used within their dashboards.
결정적으로, 이번 침해로 인해 Sisense 고객이 대시보드 내에서 사용한 모든 자격 증명이 손상되었습니다.
The incident also highlights the limited scope of Sisense's remediation actions on behalf of customers. Access tokens are essentially text files that enable extended login sessions, sometimes indefinitely. Depending on the service, attackers may be able to reuse these tokens to impersonate victims without presenting valid credentials.
이 사건은 또한 고객을 대신한 Sisense의 교정 조치의 제한된 범위를 강조합니다. 액세스 토큰은 본질적으로 확장된 로그인 세션을 활성화하는 텍스트 파일이며 때로는 무기한입니다. 서비스에 따라 공격자는 유효한 자격 증명을 제시하지 않고 이러한 토큰을 재사용하여 피해자를 가장할 수 있습니다.
Beyond resetting passwords, Sisense customers must assess their individual circumstances and determine whether to change passwords for third-party services previously integrated with Sisense.
비밀번호 재설정 외에도 Sisense 고객은 개별 상황을 평가하고 이전에 Sisense와 통합된 제3자 서비스의 비밀번호를 변경할지 여부를 결정해야 합니다.
Following the incident, a public relations firm representing Sisense inquired about KrebsOnSecurity's plans for further updates. Sisense requested an opportunity to provide comments before publication.
사건 이후 Sisense를 대표하는 홍보 회사는 KrebsOnSecurity의 추가 업데이트 계획에 대해 문의했습니다. Sisense는 출판 전에 의견을 제공할 기회를 요청했습니다.
However, after being confronted with details provided by sources, Sisense reportedly changed its position. "After consulting with Sisense, they have told me that they don't wish to respond," the PR representative stated via email.
그러나 소식통이 제공한 세부 내용을 접한 후 시스센스는 입장을 바꾼 것으로 알려졌다. 홍보 담당자는 이메일을 통해 "Sisense와 상담한 후 응답을 원하지 않는다고 말했습니다."라고 말했습니다.
Update, 6:49 p.m., ET:
업데이트, 오후 6시 49분(ET):
It has been clarified that Sisense utilizes a self-hosted version of Gitlab, not the cloud version managed by Gitlab.com.
Sisense는 Gitlab.com에서 관리하는 클라우드 버전이 아닌 자체 호스팅 버전의 Gitlab을 활용하는 것으로 확인되었습니다.
Sisense's CISO, Dash, has issued a detailed update to customers. The revised guidance includes resetting access tokens across various technologies, such as Microsoft Active Directory credentials, GIT credentials, web access tokens, and single sign-on (SSO) secrets or tokens.
Sisense의 CISO인 Dash는 고객에게 자세한 업데이트를 발표했습니다. 개정된 지침에는 Microsoft Active Directory 자격 증명, GIT 자격 증명, 웹 액세스 토큰, SSO(Single Sign-On) 비밀 또는 토큰과 같은 다양한 기술에 걸친 액세스 토큰 재설정이 포함됩니다.
Dash's full message to customers is as follows:
Dash가 고객에게 전하는 메시지의 전체 내용은 다음과 같습니다.
"Good Afternoon,
"좋은 오후에요,
We are following up on our prior communication of April 10, 2024, regarding reports that certain Sisense company information may have been made available on a restricted access server. As noted, we are taking this matter seriously and our investigation remains ongoing.
우리는 특정 Sisense 회사 정보가 제한된 액세스 서버에서 이용 가능하게 되었을 수 있다는 보고와 관련하여 2024년 4월 10일자 이전 통신에 대해 후속 조치를 취하고 있습니다. 언급한 바와 같이, 우리는 이 문제를 심각하게 받아들이고 있으며 조사가 계속 진행 중입니다.
Our customers must reset any keys, tokens, or other credentials in their environment used within the Sisense application.
고객은 Sisense 애플리케이션 내에서 사용되는 환경에서 모든 키, 토큰 또는 기타 자격 증명을 재설정해야 합니다.
Specifically, you should:
구체적으로 다음을 수행해야 합니다.
- Change Your Password: Change all Sisense-related passwords on http://my.sisense.com
Non-SSO:
비밀번호 변경: http://my.sisense.comNon-SSO에서 모든 Sisense 관련 비밀번호를 변경하세요.
- Replace the Secret in the Base Configuration Security section with your GUID/UUID.
- Reset passwords for all users in the Sisense application.
- Logout all users by running GET /api/v1/authentication/logout_all under Admin user.
Single Sign-On (SSO):
기본 구성 보안 섹션의 비밀을 GUID/UUID로 바꿉니다. Sisense 애플리케이션의 모든 사용자에 대한 비밀번호를 재설정합니다. 관리 사용자 아래에서 GET /api/v1/authentication/logout_all을 실행하여 모든 사용자를 로그아웃합니다. 싱글 사인온(SSO) :
- If you use SSO JWT for the user's authentication in Sisense, you will need to update sso.shared_secret in Sisense and then use the newly generated value on the side of the SSO handler.
- We strongly recommend rotating the x.509 certificate for your SSO SAML identity provider.
- If you utilize OpenID, it's imperative to rotate the client secret as well.
- Following these adjustments, update the SSO settings in Sisense with the revised values.
- Logout all users by running GET /api/v1/authentication/logout_all under Admin user.
- Customer Database Credentials: Reset credentials in your database that were used in the Sisense application to ensure continuity of connection between the systems.
- Data Models: Change all usernames and passwords in the database connection string in the data models.
- User Params: If you are using the User Params feature, reset them.
- Active Directory/LDAP: Change the username and user password of users whose authorization is used for AD synchronization.
- HTTP Authentication for GIT: Rotate the credentials in every GIT project.
- B2D Customers: Use the following API PATCH api/v2/b2d-connection in the admin section to update the B2D connection.
- Infusion Apps: Rotate the associated keys.
- Web Access Token: Rotate all tokens.
- Custom Email Server: Rotate associated credentials.
- Custom Code: Reset any secrets that appear in custom code Notebooks.
If you need any assistance, please submit a customer support ticket at https://community.sisense.com/t5/support-portal/bd-p/SupportPortal and mark it as critical. We have a dedicated response team on standby to assist with your requests.
Sisense에서 사용자 인증을 위해 SSO JWT를 사용하는 경우 Sisense에서 sso.shared_secret를 업데이트한 다음 SSO 핸들러 측면에서 새로 생성된 값을 사용해야 합니다. SSO SAML에 대해 x.509 인증서를 교체하는 것이 좋습니다. ID 공급자입니다. OpenID를 활용하는 경우 클라이언트 암호도 교체해야 합니다. 이러한 조정에 따라 Sisense의 SSO 설정을 수정된 값으로 업데이트합니다. 관리 사용자 아래에서 GET /api/v1/authentication/logout_all을 실행하여 모든 사용자를 로그아웃합니다. .고객 데이터베이스 자격 증명: Sisense 애플리케이션에서 사용된 데이터베이스의 자격 증명을 재설정하여 시스템 간 연결의 연속성을 보장합니다. 데이터 모델: 데이터 모델의 데이터베이스 연결 문자열에서 모든 사용자 이름과 비밀번호를 변경합니다. 사용자 매개변수: 사용자 매개변수 기능을 사용하여 재설정합니다.Active Directory/LDAP: AD 동기화에 인증이 사용되는 사용자의 사용자 이름과 사용자 비밀번호를 변경합니다. GIT에 대한 HTTP 인증: 모든 GIT 프로젝트에서 자격 증명을 교체합니다.B2D 고객: 다음 API를 사용합니다. B2D 연결을 업데이트하려면 관리 섹션에서 api/v2/b2d-connection을 패치하세요.Infusion 앱: 관련 키를 순환합니다.웹 액세스 토큰: 모든 토큰을 순환합니다.사용자 정의 이메일 서버: 관련 자격 증명을 순환합니다.사용자 정의 코드: 나타나는 비밀을 재설정합니다. 도움이 필요하면 https://community.sisense.com/t5/support-portal/bd-p/SupportPortal에서 고객 지원 티켓을 제출하고 중요로 표시하세요. 귀하의 요청을 지원하기 위해 전담 응답팀이 대기하고 있습니다.
At Sisense, we give paramount importance to security and are committed to our customers' success. Thank you for your partnership and commitment to our mutual security.
Sisense에서는 보안을 가장 중요하게 여기며 고객의 성공을 위해 최선을 다하고 있습니다. 상호 안보를 위한 귀하의 파트너십과 헌신에 감사드립니다.
Regards,
문안 인사,
Sangram Dash
Chief Information Security Officer"
Sangram Dash최고 정보 보안 책임자"
부인 성명:info@kdj.com
제공된 정보는 거래 조언이 아닙니다. kdj.com은 이 기사에 제공된 정보를 기반으로 이루어진 투자에 대해 어떠한 책임도 지지 않습니다. 암호화폐는 변동성이 매우 높으므로 철저한 조사 후 신중하게 투자하는 것이 좋습니다!
본 웹사이트에 사용된 내용이 귀하의 저작권을 침해한다고 판단되는 경우, 즉시 당사(info@kdj.com)로 연락주시면 즉시 삭제하도록 하겠습니다.

































