The US federal government has issued an urgent warning about the risk of password for users of the Sisense business analytics platform, urging them to change them immediately.

The Cybersecurity and Infrastructure Security Agency (CISA) recommends that Sisense users renew their platform passwords, as well as passwords for any other sensitive information they may have access to through the use of Sisense services
Read also: Vietnam: Issues guidelines on cybersecurity
The Software-as-a-Service (SaaS) platform uses so-called “ AI -powered Analytics ” to provide specialized information to more than 2,000 companies, including Air Canada, Nasdaq and ZoomInfo.
Sisense did not respond to Dark Reading's request for comment.
According to Patrick Tiquet, VP of Security and Architecture at Keeper Security, Sisense is a target for cyber threat actors seeking to execute advanced cyberattacks against the supply chain.
“Attackers may leverage the access they have gained to further penetrate networks connected to Sisense customers, causing a ripple effect throughout the supply chain,” Tiquet said in a statement. He noted that Sisense customers should immediately implement CISA guidance by restoring any credentials and secrets that have been exposed or used to access Sisense services.”
The federal government's immediate response is a telling sign of the seriousness with which the Sisense compromise is being taken, said Sean Deuby, chief technologist at Semperis, calling the CISA recommendation "disturbing at best.".
“As recent security breaches at MGM Resorts and Caesars Palace demonstrate, the supply chain remains one of the most challenging areas to secure, and a target for cybercriminals,” Deuby said in a statement. “Unfortunately, these incidents are only a small fraction of the widespread damage from supply chain attacks like WannaCry, SolarWinds and Kaseya, which have impacted tens of thousands of organizations and cost hundreds of millions in incident response and recovery costs.”
In addition to resetting passwords, Jason Soroko, senior vice president of product at Sectigo, also urges Sisense customers to check their API access keys.

Read also: US accuses Microsoft of inadequate cybersecurity
“ Information regarding the Sisense security breach remains unclear. As a precautionary measure, I strongly recommend immediately changing passwords on all Sisense accounts, resetting API keys used for any Sisense-related services, and monitoring for any unusual activity from April 5th onwards,” Soroko said.
Source: darkreading
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
