|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
网络安全和基础设施安全局 (CISA) 正在调查 Sisense 的违规行为,Sisense 是一家商业情报公司,允许企业跟踪多个第三方在线服务。 Sisense 敦促客户重置与该公司共享的任何凭据和机密,并建议谨慎行事并轮换 Sisense 应用程序中使用的任何凭据。

Cybersecurity Breach at Sisense: Critical Infrastructure Sector Organizations Impacted
Sisense 的网络安全漏洞:关键基础设施部门组织受到影响
The United States Cybersecurity and Infrastructure Security Agency (CISA) has initiated an investigation into a data breach at business intelligence company Sisense. Sisense's products enable businesses to monitor the status of various external online services through a centralized dashboard.
美国网络安全和基础设施安全局 (CISA) 已对商业情报公司 Sisense 的数据泄露事件展开调查。 Sisense 的产品使企业能够通过集中式仪表板监控各种外部在线服务的状态。
CISA has strongly advised all Sisense customers to reset any credentials and secrets shared with the company, a recommendation previously issued by Sisense on April 10th.
CISA 强烈建议所有 Sisense 客户重置与该公司共享的任何凭据和机密,Sisense 此前于 4 月 10 日发布了这一建议。
Sisense, headquartered in New York City, boasts over a thousand customers across multiple industries, including finance, telecommunications, healthcare, and higher education. On April 10th, Sangram Dash, Sisense's Chief Information Security Officer, informed customers of reports indicating that "certain Sisense company information may have been made available on what we have been advised is a restricted access server."
Sisense 总部位于纽约市,拥有金融、电信、医疗保健和高等教育等多个行业的一千多名客户。 4 月 10 日,Sisense 首席信息安全官 Sangram Dash 向客户通报称,有报告称“Sisense 公司的某些信息可能已在我们得知的受限访问服务器上公开”。
"We are treating this matter with the utmost seriousness and have promptly commenced an investigation," Dash stated. "We have enlisted industry-leading experts to aid in our investigations. Our business operations have not been interrupted by this incident. However, as a precautionary measure, we strongly urge you to immediately change any credentials you use within your Sisense application."
达什表示:“我们正在以最严肃的态度对待此事,并已立即开始调查。” “我们已经聘请了行业领先的专家来协助我们的调查。我们的业务运营并未因这一事件而中断。但是,作为预防措施,我们强烈敦促您立即更改在 Sisense 应用程序中使用的任何凭据。”
CISA's advisory acknowledges its collaboration with private industry partners in response to the incident, particularly considering the potential impact on critical infrastructure sectors. CISA pledged to provide updates as more information becomes available.
CISA 的咨询承认其与私营行业合作伙伴合作应对这一事件,特别是考虑到对关键基础设施部门的潜在影响。 CISA 承诺在获得更多信息后提供更新信息。
Sisense declined to comment when contacted about the accuracy of information shared by reliable sources close to the investigation. These sources indicate that the breach likely originated with the attackers' access to Sisense's Gitlab code repository. Within this repository, a token or credential provided the attackers access to Sisense's Amazon S3 buckets in the cloud.
当我们联系到接近调查的可靠消息来源所分享的信息的准确性时,Sisense 拒绝发表评论。这些消息来源表明,此次泄露可能源于攻击者访问 Sisense 的 Gitlab 代码存储库。在此存储库中,攻击者可以通过令牌或凭证访问 Sisense 云中的 Amazon S3 存储桶。
Sources further revealed that the attackers utilized their S3 access to exfiltrate terabytes of Sisense customer data, reportedly including millions of access tokens, email account passwords, and even SSL certificates.
消息人士进一步透露,攻击者利用 S3 访问权限窃取了 TB 级的 Sisense 客户数据,据报道,其中包括数百万个访问令牌、电子邮件帐户密码,甚至 SSL 证书。
This incident raises concerns about Sisense's safeguards for protecting sensitive customer data, particularly regarding whether the large volume of stolen data was encrypted while stored on Amazon cloud servers.
这一事件引发了人们对 Sisense 保护敏感客户数据的保护措施的担忧,特别是大量被盗数据在存储在亚马逊云服务器上时是否经过加密。
Crucially, the breach has compromised all credentials that Sisense customers used within their dashboards.
至关重要的是,这次泄露破坏了 Sisense 客户在仪表板中使用的所有凭据。
The incident also highlights the limited scope of Sisense's remediation actions on behalf of customers. Access tokens are essentially text files that enable extended login sessions, sometimes indefinitely. Depending on the service, attackers may be able to reuse these tokens to impersonate victims without presenting valid credentials.
该事件还凸显了 Sisense 代表客户采取的补救措施的范围有限。访问令牌本质上是文本文件,可实现扩展登录会话(有时是无限期的)。根据服务的不同,攻击者可能能够重复使用这些令牌来冒充受害者,而无需提供有效的凭据。
Beyond resetting passwords, Sisense customers must assess their individual circumstances and determine whether to change passwords for third-party services previously integrated with Sisense.
除了重置密码之外,Sisense 客户还必须评估自己的个人情况,并确定是否更改之前与 Sisense 集成的第三方服务的密码。
Following the incident, a public relations firm representing Sisense inquired about KrebsOnSecurity's plans for further updates. Sisense requested an opportunity to provide comments before publication.
事件发生后,代表 Sisense 的一家公关公司询问了 KrebsOnSecurity 的进一步更新计划。 Sisense 要求有机会在发表前提供评论。
However, after being confronted with details provided by sources, Sisense reportedly changed its position. "After consulting with Sisense, they have told me that they don't wish to respond," the PR representative stated via email.
然而,据报道,在面对消息人士提供的细节后,Sisense 改变了立场。 “在与 Sisense 协商后,他们告诉我他们不想回应,”公关代表通过电子邮件表示。
Update, 6:49 p.m., ET:
东部时间下午 6:49 更新:
It has been clarified that Sisense utilizes a self-hosted version of Gitlab, not the cloud version managed by Gitlab.com.
已澄清,Sisense 使用自托管版本的 Gitlab,而不是由 Gitlab.com 管理的云版本。
Sisense's CISO, Dash, has issued a detailed update to customers. The revised guidance includes resetting access tokens across various technologies, such as Microsoft Active Directory credentials, GIT credentials, web access tokens, and single sign-on (SSO) secrets or tokens.
Sisense 的 CISO Dash 已向客户发布了详细的更新信息。修订后的指南包括重置各种技术的访问令牌,例如 Microsoft Active Directory 凭据、GIT 凭据、Web 访问令牌以及单点登录 (SSO) 机密或令牌。
Dash's full message to customers is as follows:
达世币向客户传达的完整信息如下:
"Good Afternoon,
“下午好,
We are following up on our prior communication of April 10, 2024, regarding reports that certain Sisense company information may have been made available on a restricted access server. As noted, we are taking this matter seriously and our investigation remains ongoing.
我们正在跟进 2024 年 4 月 10 日之前的沟通,有关报告称某些 Sisense 公司信息可能已在受限访问服务器上提供。如前所述,我们正在认真对待此事,我们的调查仍在进行中。
Our customers must reset any keys, tokens, or other credentials in their environment used within the Sisense application.
我们的客户必须重置 Sisense 应用程序中使用的环境中的任何密钥、令牌或其他凭据。
Specifically, you should:
具体来说,您应该:
- Change Your Password: Change all Sisense-related passwords on http://my.sisense.com
Non-SSO:
更改您的密码:更改 http://my.sisense.com 上所有与 Sisense 相关的密码非 SSO:
- Replace the Secret in the Base Configuration Security section with your GUID/UUID.
- Reset passwords for all users in the Sisense application.
- Logout all users by running GET /api/v1/authentication/logout_all under Admin user.
Single Sign-On (SSO):
将基本配置安全部分中的 Secret 替换为您的 GUID/UUID。重置 Sisense 应用程序中所有用户的密码。通过在管理员用户下运行 GET /api/v1/authentication/logout_all 注销所有用户。单点登录 (SSO) :
- If you use SSO JWT for the user's authentication in Sisense, you will need to update sso.shared_secret in Sisense and then use the newly generated value on the side of the SSO handler.
- We strongly recommend rotating the x.509 certificate for your SSO SAML identity provider.
- If you utilize OpenID, it's imperative to rotate the client secret as well.
- Following these adjustments, update the SSO settings in Sisense with the revised values.
- Logout all users by running GET /api/v1/authentication/logout_all under Admin user.
- Customer Database Credentials: Reset credentials in your database that were used in the Sisense application to ensure continuity of connection between the systems.
- Data Models: Change all usernames and passwords in the database connection string in the data models.
- User Params: If you are using the User Params feature, reset them.
- Active Directory/LDAP: Change the username and user password of users whose authorization is used for AD synchronization.
- HTTP Authentication for GIT: Rotate the credentials in every GIT project.
- B2D Customers: Use the following API PATCH api/v2/b2d-connection in the admin section to update the B2D connection.
- Infusion Apps: Rotate the associated keys.
- Web Access Token: Rotate all tokens.
- Custom Email Server: Rotate associated credentials.
- Custom Code: Reset any secrets that appear in custom code Notebooks.
If you need any assistance, please submit a customer support ticket at https://community.sisense.com/t5/support-portal/bd-p/SupportPortal and mark it as critical. We have a dedicated response team on standby to assist with your requests.
如果您在 Sisense 中使用 SSO JWT 进行用户身份验证,则需要更新 Sisense 中的 sso.shared_secret,然后在 SSO 处理程序一侧使用新生成的值。我们强烈建议为您的 SSO SAML 轮换 x.509 证书身份提供商。如果您使用 OpenID,也必须轮换客户端密钥。完成这些调整后,使用修改后的值更新 Sisense 中的 SSO 设置。通过在管理员用户下运行 GET /api/v1/authentication/logout_all 注销所有用户客户数据库凭证:重置数据库中用于 Sisense 应用程序的凭证,以确保系统之间连接的连续性。数据模型:更改数据模型中数据库连接字符串中的所有用户名和密码。用户参数:如果您是使用用户参数功能重置它们。Active Directory/LDAP:更改其授权用于 AD 同步的用户的用户名和用户密码。GIT 的 HTTP 身份验证:轮换每个 GIT 项目中的凭据。B2D 客户:使用以下 API在管理部分中修补 api/v2/b2d-connection 以更新 B2D 连接。Infusion Apps:轮换关联的密钥。Web 访问令牌:轮换所有令牌。自定义电子邮件服务器:轮换关联的凭据。自定义代码:重置出现的任何机密在自定义代码笔记本中。如果您需要任何帮助,请在 https://community.sisense.com/t5/support-portal/bd-p/SupportPortal 提交客户支持票证并将其标记为关键。我们有专门的响应团队随时待命,以协助满足您的请求。
At Sisense, we give paramount importance to security and are committed to our customers' success. Thank you for your partnership and commitment to our mutual security.
在 Sisense,我们非常重视安全性并致力于客户的成功。感谢您的合作以及对我们共同安全的承诺。
Regards,
问候,
Sangram Dash
Chief Information Security Officer"
Sangram Dash首席信息安全官”
免责声明:info@kdj.com
所提供的信息并非交易建议。根据本文提供的信息进行的任何投资,kdj.com不承担任何责任。加密货币具有高波动性,强烈建议您深入研究后,谨慎投资!
如您认为本网站上使用的内容侵犯了您的版权,请立即联系我们(info@kdj.com),我们将及时删除。
-
- 比特币、eCash 分叉和空投动态:深入探讨加密货币的最新争议
- 2026-05-03 00:52:02
- 探索最近的 eCash 分叉、其作为高风险空投的分类,以及对比特币和加密生态系统的更广泛影响。
-
-
- 美联储维持利率稳定,地缘政治紧张局势引发比特币价格下跌
- 2026-05-01 04:04:38
- 美联储维持利率的决定,加上中东冲突,影响了比特币的价格。分析近期趋势和市场反应。
-
-
-
-
-
-

































