"Sisense Data Breach Prompts Urgent CISA Alert for Credential Resets"
TL;DR
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is investigating a breach at business intelligence company Sisense, urging all Sisense customers to reset any credentials and secrets shared with the company. The breach, which involved attackers gaining access to Sisense's code repository at Gitlab, resulted in the exfiltration of several terabytes of customer data, including access tokens, email account passwords, and SSL certificates. This incident raises concerns about data protection and encryption practices, as well as the potential impact on Sisense customers' security.
- Why CISA is Warning CISOs About a Breach at Sisense – Krebs on Security Krebs on Security
- Sisense Compromise Leaves Customer Data Vulnerable, US Says Yahoo Finance
- Sisense breach exposes customers to potential supply chain attack CyberScoop
- US government urges Sisense customers to reset credentials after hack TechCrunch
- Sisense Data Breach Triggers CISA Alert and Urgent Calls for Credential Resets SecurityWeek
Want the full story? Read the original reporting
Read on Krebs on Security