There is something potentially huge popping up now. Has to do with a compromise at business intelligence vendor Sisense. I'm hearing this is a supply chain attack affecting many millions of credentials and hundreds of tenants. This is a message the Sisense CISO just sent to customers.
We seriously need to add a Concerning emote.
Mediaocean do you have some information as they are one of your subprocessors?
Hopefully they can quickly determine the scope, might be some lateral movement if it's a supply chain compromise, Sisense might not even be the initial access. Customers should of course be on the lookout and closely scrutinize all technical trust relationships.
Rotate Your Credentials? This was stated as if it's a trivial process and that everyone should know the definition. Nothing be farther from the truth: In case you're a little mystified here's what AWS has to say on the topic: "The process for rotating credentials boils down to the following steps: -Generate new keys -Securely distribute keys to your applications -Ensure the applications refresh their keys -Disable the old access keys -Ensure everything still works -Delete the old access keys" #cyber #credentials #keyrotation #aws
Seeing Nasdaq as one of their customers... worrisome?
Security components and vendors the new vulnerability…
Steve T. "we got hacked and lost all your data, but it's ok, it hasn't interrupted our profit making business operations"
Business-IT Risk Feedback Loop Optimization Expert @ CarbonHelix | IT Dependency Polymath | Inverse Risk Workshops | Present Impact of Historical Automation Adoption
4moWithout more discrete details there isn’t much to comment on yet that wouldn’t just be cathartic venting; but at first blush it’s the right thing to do to notify clients immediately.