Security News > 2024 > April > CISA says Sisense hack impacts critical infrastructure orgs
The U.S. Cybersecurity and Infrastructure Security Agency is investigating the recent breach of data analytics company Sisense, an incident that also impacted critical infrastructure organizations.
Today, CISA says the incident also affects critical infrastructure sector organizations in the United States, with the agency now working with partners in the private sector to assess its impact.
"CISA is taking an active role in collaborating with private industry partners to respond to this incident, especially as it relates to impacted critical infrastructure sector organizations. We will provide updates as more information becomes available."
Sisense CISO Sangram Dash reiterated CISA's advice in a message sent to customers and shared by investigative reporter Brian Krebs.
Customers should also report any suspicious activity involving potentially exposed credentials or unauthorized access to Sisense services to CISA. When BleepingComputer contacted them earlier today for more details regarding this potential supply-chain attack, CISA and Sisense spokespersons were not immediately available for comment.
One year ago, a supply chain attack that led to the 3CX breach also impacted several critical infrastructure organizations, including "Power suppliers generating and supplying energy to the grid" in the United States and Europe.
News URL
Related news
- CISA warns of critical Palo Alto Networks bug exploited in attacks (source)
- CISA Alerts to Active Exploitation of Critical Palo Alto Networks Vulnerability (source)
- CISA Urges Agencies to Patch Critical "Array Networks" Flaw Amid Active Attacks (source)
- CISA, FBI Issue Guidance for Securing Communications Infrastructure (source)
- New IOCONTROL malware used in critical infrastructure attacks (source)
- CISA confirms critical Cleo bug exploitation in ransomware attacks (source)
- Iran-linked crew used custom 'cyberweapon' in US critical infrastructure attacks (source)
- CISA urges switch to Signal-like encrypted messaging apps after telecom hacks (source)
- CISA Adds Critical Flaw in BeyondTrust Software to Exploited Vulnerabilities List (source)