Brian Krebs’ Post

There is something potentially huge popping up now. Has to do with a compromise at business intelligence vendor Sisense. I'm hearing this is a supply chain attack affecting many millions of credentials and hundreds of tenants. This is a message the Sisense CISO just sent to customers.

  • No alternative text description for this image
Daryl Diebold

Business-IT Risk Feedback Loop Optimization Expert @ CarbonHelix | IT Dependency Polymath | Inverse Risk Workshops | Present Impact of Historical Automation Adoption

4mo

Without more discrete details there isn’t much to comment on yet that wouldn’t just be cathartic venting; but at first blush it’s the right thing to do to notify clients immediately.

We seriously need to add a Concerning emote.

David King

MSc., BSc. (Open), MBCS CITP, CISM, CISA C/BISO, Omnicom Media Group

4mo

Mediaocean do you have some information as they are one of your subprocessors?

Scott Lashua

Information Systems Security Officer

4mo

Hopefully they can quickly determine the scope, might be some lateral movement if it's a supply chain compromise, Sisense might not even be the initial access. Customers should of course be on the lookout and closely scrutinize all technical trust relationships.

Dan McNamara

Program Director / Project Manager / Business Development / Capture Management / Contract Management / Strategic Planning & Execution / Agile Management / National Security & DHS Experience / Passionate Volunteer

4mo

Rotate Your Credentials? This was stated as if it's a trivial process and that everyone should know the definition. Nothing be farther from the truth: In case you're a little mystified here's what AWS has to say on the topic: "The process for rotating credentials boils down to the following steps: -Generate new keys -Securely distribute keys to your applications -Ensure the applications refresh their keys -Disable the old access keys -Ensure everything still works -Delete the old access keys" #cyber #credentials #keyrotation #aws

Jean-Philippe Martin

Semiconductor Security | Assurance | AI/ML Risk Assessment

4mo

Seeing Nasdaq as one of their customers... worrisome?

Peter Rus

"Data is gold, but secure data sharing secure by design is the platinum standard that unlocks its true value.".#tripled Process Improvement, and Compliance (NIS2, DORA) | Strategic Planner | Tech Innovator

4mo

Security components and vendors the new vulnerability…

Sean R Turner

Chief Information Security Officer at Twinstake, SME and Climate angel investor, dad of four, hairy car nut (hairy me, not hairy cars). Superman doing everything :-P

4mo

Steve T. "we got hacked and lost all your data, but it's ok, it hasn't interrupted our profit making business operations"

See more comments

To view or add a comment, sign in

Explore topics