tenable cloud security
26 TopicsTenable product update: Standardizing Tenable risk scoring
At Tenable, we are committed to providing the most accurate, defensible, and actionable view of organizational risk. To achieve this, we must continually refine the intelligence that powers your prioritization. On July 1, 2026, we are implementing a series of foundational updates to our risk scoring engines. As part of this update, you may see changes to your risk scores, depending on the Tenable product(s) you own. These changes simplify your workflow by standardizing scoring on a single, high-fidelity model for vulnerability and asset risk. The new standard for VPR For the past several months, many of you have utilized VPR (Beta) to gain deeper insights into exploitability. We are excited to announce that on July 1, this model will be promoted to the primary Vulnerability Priority Rating (VPR) across the Tenable platform. By standardizing on this advanced model, we are retiring legacy VPR scoring to ensure every customer benefits from our most sophisticated threat intelligence. The new version of VPR incorporates more threat intelligence and vulnerability metadata so that you can focus on the 1.6% of vulnerabilities that actually matter. Better context through enhanced asset classification Alongside the VPR update, we are enhancing our asset classification engine. This update improves how we identify the function and importance of assets across your entire attack surface, including Cloud, OT, and third-party devices. As a result, customers with access to Asset Criticality Ratings (ACR) for VM assets will see these scores more accurately reflect real-world business risk. What this means for you These are backend enhancements designed to provide immediate value with zero manual configuration. On July 1, your dashboards, reports, and APIs will automatically reflect these updated metrics. Because both VPR and ACR serve as inputs to Cyber Exposure Score (CES) and Asset Exposure Score (AES), customers using these scores may see changes that reflect a more accurate understanding of exposure. Customer FAQ What happens to the VPR (Beta) score in the Tenable UI? The Beta label will be removed. The high-fidelity model you’ve been previewing will become the standard VPR. The legacy version of VPR will be retired to ensure a single, unified source or truth. Do I need to rewrite my custom API scripts using VPR? No. For customers using APIs, updated values will be mapped into legacy VPR fields on the back end to ensure compatibility and a smooth transition for your scripts and third-party tools. How does this affect my SLAs? Because many organizations use VPR as their operational prioritization layer, your SLA statistics and remediation tracking will now reflect the more precise scoring model. This helps ensure your team is meeting response goals for the vulnerabilities that pose the highest actual risk. How does Enhanced Asset Classification affect my scores? The system now automatically identifies the function and criticality of assets across Cloud, OT, and third-party sources. This improved context leads to more accurate Asset Criticality Rating (ACR) adjustments. For customers with access to ACR, this ensures your most critical business assets are effectively prioritized. What actions does my team need to take, and when will the changes be reflected in my container? These updates will occur automatically within your Tenable console. Depending on the size of your environment, it may take time for score recalculations to be fully reflected across your console. For a detailed guide on our enhanced VPR, check out this FAQ. Want to see the why behind our scoring? View our scoring explained.6.9KViews9likes13CommentsTenable Enhances Its Cloud Security Solution with Expanded Just-in-Time Access
Tenable has enhanced its Just-in-Time (JIT) Access capabilities to provide more comprehensive and streamlined cloud security for organizations. The Just-in-Time (JIT) Access feature significantly strengthens cloud security by granting temporary, need-based access to sensitive resources, minimizing the risks associated with persistent privileges. This approach offers several critical benefits for organizations striving to enhance their cloud security posture: Reduced Attack Surface: By eliminating always-on privileges, JIT Access significantly minimizes the window of opportunity for attackers to exploit compromised identities. Enhanced Security Posture: Granting access only when required and for a limited duration adheres to the principle of least privilege, mitigating the risk of both external threats and insider misuse. Seamless User Experience: Tenable's JIT Access offers user-friendly workflows, including integration with popular messaging platforms like Slack and Microsoft Teams, allowing users to request and receive necessary access without disrupting their productivity. Improved Auditability and Compliance: The solution provides a clear and comprehensive audit trail of all access requests, approvals, and session activities, simplifying compliance with various regulatory frameworks. Achieving Zero Standing Privileges: Tenable's JIT Access empowers organizations to move towards a "zero standing privileges" model in their cloud environments, a critical step in modern cybersecurity. For more information, please visit the page.90Views3likes1CommentTenable Product Update Newsletter — July 2026
Check out our July newsletter to learn about the latest product and research updates, events, and educational content. Plus, this month we’re featuring the launch of the CyberAgents Exchange, powered by Tenable. Keep reading to read more about the new open-source AI exchange! Tenable One - Platform updates Integrate application security data into Tenable One for code-to-runtime security Your codebase is growing faster than your security program, and in the age of AI, developers are introducing security findings at 10 times the rate of their peers. It is critical to see code as part of your entire attack surface. Application security data now integrates directly into Tenable One to further close visibility gaps and ensure secure code development in the AI era. Whether code is human- or machine-written, you can now integrate application security risks, like those from Snyk, Claude Security, or any other application security tool via Tenable One Connectors — directly alongside your existing exposure data. What this means for you: Achieve full code-to-runtime visibility by bringing application security risks together with the rest of your exposure data in one place. Fix code flaws before they become incidents by identifying your most business-critical code flaws and fixing them early in the development lifecycle. Measure organizational exposure and transform technical static code vulnerabilities into clear risk metrics on business resilience. Read the blog post Explore the guided demo Check out Open Connector documentation and Snyk Connector documentation Improved workflow orchestration capabilities in Tenable One Vulnerability Management and Tenable One New enhancements to Tenable's workflow orchestration capabilities are now generally available. This release streamlines remediation workflows and improves operational efficiency with the following key updates: Plugin output in tickets: You can now attach Plugin Output directly to tickets, providing immediate context and critical information while eliminating the need for further navigation. Tenable Hexa AI for ServiceNow: You can now leverage Tenable Hexa AI for ServiceNow incident and initiative creation to match already available Jira functionality. Review the exposure management release notes Review the Tenable Vulnerability Management release notes Tenable unified scoring is now live Tenable has unified its risk prioritization standard, moving the high-fidelity Vulnerability Priority Rating (VPR) model out of beta to become the sole standard. To sharpen your prioritization, an updated asset classification engine also delivers more accurate Asset Criticality Ratings (ACR) for your assets. Because VPR and ACR feed directly into your Cyber Exposure Score (CES) and Asset Exposure Score (AES), your console will automatically update to reflect a precise understanding of your exposure. These recalculations occur automatically, though completion times depend on the size of your environment. To prevent errors in your saved views, you must manually update any filters or combinations that still use VPR v1. No data migration is required. Visit Tenable Connect for more details Learn more about Tenable One scoring The CyberAgents Exchange, powered by Tenable Tenable launches the industry’s first open-source AI exchange (and we want your agents on it) Security teams are building AI agents in isolation, reinventing the wheel with no neutral place to share what actually works. The CyberAgents Exchange, powered by Tenable, is the only purpose-built, cybersecurity-native registry for AI agents, skills, MCP servers, and multi-agent playbooks in the current market. Built by defenders. For defenders: Purpose-built for security teams to solve the exposure problems practitioners actually face. Collective defense for the agentic era: Anyone can contribute; everyone benefits. Agents and skills are shared under open licenses with no fees or gates. Trust through transparency: Every agent links directly to its source repository, so there are no bundled binaries or black boxes. Build your reputation. Elevate your craft: Contributing is career capital. We give practitioners a platform to earn validation and build an undeniable resume. Join the community, build your reputation, and start automating risk reduction. Explore the directory and submit your builds Tenable One Cloud Exposure Tenable One Cloud Exposure achieves FedRAMP High authorization Tenable is committed to being the trusted partner of choice for the public sector, providing the advanced protection required for the U.S. government’s most sensitive environments. We are proud to announce that Tenable One Cloud Exposure has achieved FedRAMP High and Impact Level 5 (IL5) authorization. Purpose-built for sensitive government cloud environments, this high-level authorization delivers: Unified visibility: Gain a single view across infrastructure, identities, and workloads — even in air-gapped environments. Zero-trust enforcement: Leverage advanced identity analytics to enforce least privilege principles and align with DoW CIO mandates. Blast radius reduction: Map the Web of Risk to see how vulnerabilities connect to identities and sensitive data, stopping problems before they snowball. Cost reduction: Support fiscal modernization by eliminating tool sprawl and reducing costs without compromising security. Read the press release Learn more about our FedRAMP High solutions Take control of your sensitive data When data classification engines scan the cloud, they often flag false positives, like internal test data, mock databases, or benign corporate email domains, as critical risks. With Tenable’s new data classification exclusions, customers can fine-tune their data scans to get to the bottom of what’s actually sensitive. Exclude by resource scope: Narrow exclusions to specific data types or resources using user-friendly Explorer-based queries. Exclude specific values: Filter out known text patterns or regex strings (like internal email domains). Target precise locations: Use OR logic to pinpoint exact databases, schemas, tables, file extensions, or object paths. Learn how to create a data classification exclusion Read about the recent releases here Tenable One Web App Scanning Authenticate web app scans with OAuth 2.0 You can now scan protected applications and APIs using OAuth 2.0 authentication within Tenable One Web App Scanning. Configure these options under your scan credential settings using three supported flows: Authorization code: For user-driven logins, with optional PKCE and Selenium scripting for complex identity providers. Client credentials: For machine-to-machine API scans without user interaction. Device code: For headless and device-style authentication. To prevent scans from silently losing access, authorization verification continuously validates your session via response patterns, headers, or HTTP status codes across all credential types. Integrate these capabilities immediately through your existing credentials API without changing endpoints. You can call the List Credential Types endpoint to programmatically discover the new fields. Review the documentation Review the release notes Tenable One OT Exposure Extended OT visibility for grid operators and disconnected environments Our latest Tenable One OT Exposure release expands visibility for grid operators and disconnected environments, and introduces productivity and performance enhancements to accelerate analyst workflows. OT agent for disconnected environments: Secure air-gapped and isolated networks without deploying sensors or requiring live connectivity, featuring offline scan profiles, a local agent interface tailored for field technicians, and centralized Network Areas to resolve duplicate IP conflicts across distributed sites. Power substation anomaly detection: Passively monitor GOOSE streams and alert on anomalous activity (e.g., code revision changes) to protect utility and grid operations from unauthorized modifications or replay attacks. Yokogawa DCS activity detection: Get deep visibility into engineering activities on Yokogawa Centum VP systems to detect changes to critical operations and unauthorized access, including controller start/stop, code edits, function block changes, tag writes/deletes, and more. Simplified enterprise management: Manage all ICP subnets from a single Enterprise Manager interface — define CIDR boundaries, toggle monitoring per-site, and eliminate the need for per-ICP configuration for monitoring different network areas. Analyst workflow improvements: Reuse investigations with Saved Views, review Assets and Findings details faster with a quick-access side panel, and secure syslog transport with TLS support. Explore the user guide Review the release notes Tenable Security Center Reimagined vulnerability analysis, flexible deployment, and streamlined operations Tenable Security Center 6.9, now available in early access, modernizes vulnerability analysis and expands enterprise deployment flexibility with a reimagined query experience and deeper PAM and credential integrations. Explore Findings: A redesigned vulnerability query interface with expanded filtering and VPR key drivers surfaced directly in the findings detail panel. Tenable Nessus scanners via Tenable Sensor Proxy: Deploy Tenable Nessus scanners through Tenable Sensor Proxy for flexible, scalable enterprise and Tenable Enclave Security environments. Windows LAPS and PAM Kerberos support: Dynamically retrieve scan credentials via Windows LAPS and Kerberos Target Authentication across all supported PAM integrations. Performance improvements: Submit diagnostic bundles directly to Tenable Support, suppress rollover scans during freeze windows, and benefit from a modernized data architecture that reduces disk usage. Explore the user guide Download the early access release Tenable Ecosystem Now available: PyTenable 26.6.1 PyTenable 26.6.1 has officially been released, introducing a new temporal versioning scheme (YEAR.MONTH.PATCH) to better align with rapid API changes and enable critical updates to older modules. Marshmallow v4 support: Resolved issues preventing the use of newer Marshmallow versions. APA export: Added support in the current Tenable One package. Streamlined testing: Refactored workflow processes mean you no longer need Act and Docker installed just to run the test suite. Bug fixes: Addressed various minor issues introduced by recent API changes. Moving forward, support will be provided for the current month minus three releases, so we highly recommend pinning your software to a specific release and testing against the latest. Visit the PyTenable GitHub repository Training and product education Tenable One Exposure Management Platform introduction course includes CTEM This introductory course in Tenable University now incorporates the foundations of the Continuous Threat Exposure Management (CTEM) framework to identify exposures, prioritize remediations, and reduce risk across your modern attack surface. Practitioners and partners will learn the fundamentals of continuous hybrid asset discovery, risk-based scoring, and validating critical attack paths to effectively manage security posture. This no-cost course serves as the essential primer and recommended prerequisite for the Specialist tier. Access the course on demand in Tenable University On-demand Tenable One Exposure Management Platform Specialist course now available This brand-new paid Tenable University training course provides comprehensive Continuous Threat Exposure Management (CTEM) lifecycle training across the entire Tenable One architecture. The Specialist-level course delivers deep technical coverage of the Tenable One Exposure Management Platform, including: Tenable One Vulnerability Management Tenable One Attack Surface Management Tenable One Identity Exposure Tenable One OT Exposure Tenable One Cloud Exposure Tenable One Web App Scanning Practitioners will gain proficiency in third-party data integration, advanced asset tagging, and context-aware analytics (such as Attack Path Analysis and Exposure Signals) to drive risk-based prioritization and deliver actionable executive dashboards. Eligible for Continuing Education (CE) credit. Learn more and purchase online Tenable events and webinars Customer office hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable One Vulnerability Management, Tenable One Cloud Exposure, Tenable One Identity Exposure, and Tenable One OT Exposure. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa), and Asia-Pacific (APAC). Learn more and register Virtual events Now on demand — Tenable customer update, July 2026: Watch the most recent quarterly customer update session. This informative, fast-paced overview explores how to better secure your expanding attack surface and consolidate critical security data. Products covered include: Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, and Tenable Security Center. Watch on demand See all upcoming live and on-demand webinars Read Tenable documentation.676Views2likes0CommentsMay 2026 Tenable Product Newsletter
Check out our May newsletter to learn about the latest product and research updates, events, and educational content — all to help you get more value from your Tenable solutions. Tenable One Tenable Hexa AI: Intelligence into action at machine speed. We are thrilled to announce that Tenable Hexa AI, the agentic engine of the Tenable One Exposure Management Platform, is now generally available. Tenable Hexa AI orchestrates and automates security workflows to accelerate risk reduction. Built-in or custom agents: Start immediately with our pre-built agents for common security tasks like asset management and dashboard creation, or build custom agents via the MCP server for your unique environment. Execute the fix: Tenable Hexa AI handles complex multi-step tasks like identifying the root cause of a threat and automatically creating the necessary remediation tickets. Automate with confidence: You define the guardrails. Every action is fully auditable and requires the level of human oversight you choose, so you can scale automation without risking your production environment. Get more details on Tenable Connect or read the documentation. To learn more about how to leverage Tenable Hexa AI, reach out to your account team or contact us. The Tenable One Open Connector Connect more. See more. Act faster. We built Tenable One to be the open, connected hub that turns your scattered tools into a one-stop shop for risk reduction. While our standard Connectors already keep your favorite tools in sync, we’re taking integration to the next level with the new Tenable One Open Connector. We're no longer just talking about official integrations; we're talking about bringing in your data from across unsupported or custom tools, spreadsheets, and even homegrown internal systems. What this means for you: Get a more complete view of risk by bringing your security data together in a single, contextual view. Unlock an open, flexible platform for your security stack by staying independent of pre-built integrations. Act faster with automated data syncs that keep your information always current. Tailor your data mapping to enable precise segmentation that fits your organization’s needs. Ready to achieve a truly unified view of your entire attack surface? Read the blog and view the demo. To get started, see the setup guide. Lifecycle management in attack path analysis Take control of your security workflows with our new lifecycle management features in attack path analysis. You can now manually transition attack techniques through specific stages — To Do, In Review, In Progress, Resolved, and Excluded — to ensure seamless collaboration across your team. What’s new: Manual technique control: Track progress accurately by assigning specific statuses to each technique. Smart attack path sync: When you update a technique’s status, the system automatically updates the status of all related attack paths to reflect that change. Unified workflow: Align your team around a shared lifecycle, providing a clear and consistent view of every identified threat. Learn more. Tenable One + Recorded Future integration Our new Recorded Future connector bridges the gap between your internal exposure data and the external threat landscape, giving you a single source of truth to accelerate remediation where it matters most. By layering Recorded Future’s threat intelligence over Tenable’s deep attack surface visibility, you can now achieve: Truly unified visibility: View high-fidelity threat intelligence alongside your full exposure data in one pane of glass. Holistic context: Instantly see how internal asset criticality aligns with real-world exploit trends. Targeted remediation: Ignore the noise and focus exclusively on the vulnerabilities threat actors are actively weaponizing in the wild. Learn more. Tenable integrates with the Claude Compliance API for AI governance Tenable has announced an integration between the Tenable One Exposure Management Platform and the Claude Compliance API. This new capability provides security and compliance teams with unprecedented visibility and governance over enterprise AI usage directly within their existing workflows. Key highlights of this release include: Granular visibility: Monitor enterprise Claude AI interactions, including chats and file uploads, natively within Tenable One. Risk detection: Identify malicious or suspicious activity across your AI ecosystem. Regulatory alignment: Ensure AI usage complies with corporate acceptable-use policies and global mandates like the EU AI Act. This integration is available immediately for all Tenable One customers, allowing organizations to safely adopt Claude Enterprise at scale while proactively managing AI-related risks. Tenable One Cloud Exposure This month, we are focusing on automated orchestration and shifting security further left into native developer workflows. What's New: Retroactive cloud automations: Apply new or re-enabled automation rules retrospectively to your entire backlog of cloud findings to wipe out historical cloud risks in a single click. 280 cloud-native secret types: Our original generic categories are now split into 280 specific data types (like GitHub App Tokens), allowing you to customize sensitivity criteria to fit your exact cloud compliance requirements. Native PR scanning (IaC): Catch security risks natively inside GitHub and Azure DevOps pull requests so developers can fix configuration errors directly on the relevant lines of code before merging. Windows container scans: Maintain robust protection across your entire application footprint with shift-left vulnerability scanning that now supports Windows-based container images within cloud CI/CD pipelines. On-demand registry scans: Manually push critical cloud container images or full repositories to the top of the scan queue to instantly verify your security fixes. For more information on these updates, please view “documentation” inside the Tenable One Cloud Exposure interface. Tenable One Vulnerability Management Automate remediation with direct ticketing Stop bouncing between disconnected tools. You can now create Jira or ServiceNow tickets directly within your Explore Findings view and launch Exposure Response Initiatives straight from Vulnerability Intelligence. Even better, Tenable automatically closes these tickets the moment a vulnerability is fixed, eliminating tedious manual cleanup for your team. To keep your security and IT teams aligned, we've also added live ticket log tracking inside the finding details page, new ticket filters for your findings table, and easy exports for Exposure Response logs. To get started, check out our documentation or interactive tour. Clear your blind spots and validate your security coverage To protect your network, you need to know your security tools are working correctly. New dashboards and reports help you eliminate hidden gaps and prioritize fixes faster. The program health dashboard monitors your deployment health and scanning coverage. It gives you a central view to ensure your security agents are active and fully patched, preventing silent operational failures. The program health report unifies fragmented asset data and scan authentication indicators into a single document. It resolves conflicting inventories and credential issues, giving you a clean, trusted report to plan and execute remediation. The endpoint application visibility dashboard cuts out the hours your team spends hunting down software inventories. It automatically consolidates application data across endpoints so you can prioritize fixes based on real-world exploit likelihood and deployment scale. Nessus Whether you are a seasoned pro with Nessus or just starting out as a first-time user, don’t forget to check out our on-demand training courses and learn from the team that built Nessus. Nessus Fundamentals: Maximize your Nessus Professional or Expert deployments. You’ll master the essential building blocks of vulnerability assessment, conquering everything from initial installation and asset discovery to compliance checks and in-depth analysis. No prerequisites necessary. Nessus Advanced: Elevate your Nessus Expert skills. You’ll build upon your foundational knowledge to take command of external attack surface discovery, web app scans, and results analysis. Accelerate your time-to-value with a full year of unlimited access to expert-led video instruction. You will master critical workflows, maximize your security ROI, and earn a digital badge and Certificate of Completion to validate your hard-earned expertise. Learn more and enroll today at www.tenable.com/buy/training Tenable Security Center Tenable Security Center 6.8 Focus on the vulnerabilities that matter with AI-powered VPR insights and mitigation guidance. This release streamlines your operations with unified asset repositories for IPv4, IPv6, and Agents, and improves efficiency with new background query processing and scan optimization capabilities. View the full release notes to learn more. Tenable Patch Management Scale patching and simplify upgrades Broader environment coverage, faster endpoint updates, and a much smoother platform upgrade are available with the latest releases. Version 10.1.971.12 (SaaS & on-premise) expands your coverage across new Linux distributions and architectures. On your endpoints, you can now run lightweight, native driver and BIOS updates without the heavy files that cause CPU bloat, and deploy Windows upgrades via bandwidth-saving peer-to-peer rollouts. This release also cuts console memory usage, hardens library security, and fixes interface bugs affecting patch previews. Version 10.1.972.14 (server) delivers a targeted hotfix that corrects server upgrade task-sequencing and strategy validation issues, ensuring you a seamless, error-free migration from older versions. Broader environment coverage, faster endpoint updates, and a much smoother platform upgrade are available with the latest releases. Version 10.1.971.12 (SaaS and on-premises): Expands your coverage across new Linux distributions and architectures. On your endpoints, you can now run lightweight, native driver and BIOS updates without the heavy files that cause CPU bloat, and deploy Windows upgrades via bandwidth-saving peer-to-peer rollouts. This release also cuts console memory usage, hardens library security, and fixes interface bugs affecting patch previews. Version 10.1.972.14 (server): Delivers a targeted hotfix that corrects server upgrade task-sequencing and strategy validation issues, ensuring a seamless, error-free migration from older versions. How to update: SaaS tenants have been updated automatically. For on-prem deployments, download the latest installers via the Tenable Downloads Portal. For the further details, check out the release notes. Tenable One OT Exposure Tenable OT Security 4.6 Our latest release introduces a variety of new features and performance enhancements, including refined scan controls and streamlined workflows for large-scale enterprise environments. Massive subnet scaling: Now supports up to 5,000 subnets per ICP, significantly increasing visibility for distributed large enterprise deployments. Centralized network management: A new Monitored Networks page includes bulk-add capabilities and the ability to stage inactive networks before monitoring. Precision scanning: New scan customization options allow you to define specific credential usage per scan for safe discovery of sensitive assets. Streamlined platform navigation: Updated workflow for SSO/SAML users allows you to instantly pivot back to Tenable One with a single click. Remote agent updates and query restrictions: Update OT agents directly from the ICP, remove local site visits or manual CLI intervention, and restrict specific protocol queries with OT agents. Enhanced diagnostics: Deeper metadata in asset log exports for faster troubleshooting. IoT connector updates: Major stability and performance upgrades for Milestone, AvigilonES, and Exacq Edge integrations for IoT asset discovery. Update required: Tenable OT Security 4.5 Service Pack (version 4.5.61) All customers running version 4.5 should apply this upgrade immediately for optimal system stability and performance when processing high volumes of network conversations. This update also addresses communication gaps with Rockwell Stratix devices and Nessus scans. View the full release notes. Tenable Ecosystem Tenable App for Microsoft Sentinel v3.1.2 Version 3.1.2 of the Tenable App for Microsoft Sentinel is now available, bringing connector enhancements and schema updates to optimize your integration. What’s new: TIE data connector: The UI now supports multiple rsyslog configurations. Schema updates: Updated table schemas for Tenable One Vulnerability Management and Tenable One Web App Scanning vulnerabilities within the ARM Template. Improved data handling: The Tenable Vulnerability SDK now utilizes indexed_at instead of last_found. We highly recommend upgrading to v3.1.2 to ensure full support for these latest changes. For more details, please read Tenable Documentation or visit the Azure Marketplace to download. Please note, this application is also available via the Microsoft Azure Gov Cloud marketplace. Tenable events and webinars Tune in for product updates, demos, how-to advice and Q&A. See all upcoming live and on-demand webinars at https://www.tenable.com/webinars. Customer Office Hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable One Vulnerability Management, Tenable One Cloud Exposure, Tenable One Identity Exposure and Tenable One OT Exposure. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa and Asia Pacific (APJ). Learn more and register here. On-demand TenableTalk Live: Responding to Mythos and Frontier AI vulnerability discovery: Catch the replay of this conversation about the impact of frontier AI models on the threat landscape and how security teams can evolve vulnerability discovery into a machine-speed agentic defense. Watch on LinkedIn or in Tenable Connect. Tenable customer update: April 2026: Watch this quarterly Tenable customer update to learn how to use AI to augment your security team, secure your expanding AI attack surface, uncover hidden risk across your connected IT/OT environments, and more. Products covered: Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, OT functionality, third-party data connections, and Tenable Security Center. Tenable Research Research Security Operations Subscribe to the Research team blog posts here. Why the approaching flood of vulnerabilities changes everything — and what to do about it New content Almost 7,000 new published vulnerability plugins. More than 60 new audits delivered to customers. Read Tenable documentation.845Views2likes0CommentsTenable Product Update Newsletter — August 2026
Welcome to your monthly round-up of the latest Tenable product updates, platform enhancements, and community news. This month, we’re focused on agentic automation, quantum-readiness, and sharper visibility across your attack surface. Tenable One Platform Updates Tenable Hexa AI now supports Routines and Agent Center in Tenable One Introducing the next major evolution in agentic security: an always-on workforce powered by Tenable Hexa AI Routines, Agent Center, and a new Jamf integration directly within the Tenable One platform. Moving past conversational search and one-off actions, mobilize an autonomous fleet that runs in the background to seamlessly coordinate multi-step security tasks across your entire exposure landscape. Routines: Define an exposure workflow once and set a schedule. Hexa reasons through fresh context on every run and automatically delivers actionable results. Agent Center: A central workspace to track all routines to get clear visibility into what’s running, completed, queued, or awaiting user input. Jamf integration: Fetch Jamf-managed Mac context on demand and push patch policies directly back to Jamf without ever leaving Tenable One. Available now. Get started by navigating to Agent Center > Create a Routine or the Routines tab in Hexa AI. Get more details in the release notes CyberAgents Exchange CyberAgents Exchange and SWARM event recap The CyberAgents Exchange, powered by Tenable, is an open-source, vendor-agnostic hub where security practitioners and CISOs can discover, share, and collaborate on AI agents, skills, MCP servers, and playbooks built for cybersecurity. This free-to-use community infrastructure allows defenders to scale their capabilities, eliminate development silos, and outpace AI-generated threats without vendor lock-in. In conjunction with the CyberAgents Exchange launch, Tenable hosted SWARM, a hands-on cybersecurity agentic AI build event at Black Hat USA 2026 in Las Vegas. Real-world solutions: Sponsored by AWS and presented with support from Anthropic, the event challenged security practitioners to build open-source components that automate real-world security workflows. Winners: Congratulations to our first-, second-, and third-place winning teams! Your incredible builds are now on the CyberAgents Exchange for the global security community to adopt and build upon. Explore the CyberAgents Exchange today, and check out our official press release and SWARM recap blog post for complete details. Explore the CyberAgents Exchange Read the SWARM recap blog Read the press release Tenable One Vulnerability Management Accelerate software discovery and compliance reporting in Explore Seamlessly track software inventory and isolate compliance checks directly within Tenable One Vulnerability Management. The new Software and Host Audit tabs in Explore deliver dedicated views to eliminate UI clutter, track deployed application footprints, and speed up audit reporting. Use these views to: Pinpoint software exposure: Search installed software, versions, and vendors alongside risk metrics like ACR and AES to maximize SBOM value. Isolate compliance findings: Separate CIS benchmark and hardening checks from general vulnerability noise without building complex filters. Export audit evidence: Instantly group and export targeted software inventories or configuration results for internal teams and external auditors. Read the full post on Tenable Connect Tenable One AI Exposure Now covering all major AI platforms and developer tools AI adoption is outpacing most teams’ ability to govern it, and every new LLM, agent, or IDE plugin adds another blind spot to the attack surface. Tenable One AI Exposure closes that gap further, adding support for Google Gemini and extending coverage across the tools where AI actually gets used inside your environment. Expanded coverage and capabilities include: Full LLM coverage: Monitor prompts, responses, and usage patterns across Google Gemini, Anthropic Claude, OpenAI ChatGPT Enterprise, and Microsoft Copilot, with policy enforcement and detection of risky or unauthorized activity. Broader shadow AI visibility: Discover sanctioned and unsanctioned AI use across Model Context Protocol (MCP) deployments, AI-native IDEs like Cursor, Windsurf, and Trae, and AI-enabled browser extensions. Faster remediation workflows: Route policy violations straight into Jira or ServiceNow, or trigger automated alerts over email, Slack, or Teams, so issues get worked instead of just logged. Read the Tenable One AI Exposure press release Tenable One Cloud Exposure Identify non-compliant post-quantum cryptography cloud resources Encrypted traffic captured today can be stored and decrypted later, once quantum computing matures, a threat known as harvest-now-decrypt-later (HNDL). Organizations relying on outdated Transport Layer Security (TLS) configurations or non-quantum-safe encryption are exposed to this risk without even knowing it. Tenable One Cloud Exposure now helps customers identify non-compliant post-quantum cryptography (PQC) cloud resources to support future compliance regulations. We’ve added four new properties to the Network Endpoint profile for HTTPS-supported endpoints. The enhancement allows teams to: Get visibility into quantum readiness: See which endpoints already support post-quantum cryptography and which don’t, so you can prioritize upgrades ahead of emerging compliance mandates. Get all non-PQC-compliant resources listed in one query. Identify weak encryption faster: Surface outdated TLS versions and vulnerable cipher suites across your environment without manual audits or separate scanning tools. Reduce HNDL exposure: Proactively harden key exchange methods and ciphers before intercepted traffic becomes a future liability. Gain compliance evidence: Customers in regulated industries, such as healthcare and financial services, can easily prove compliance as quantum computing matures. To find these resources in your cloud environment, go to Tenable One Cloud Exposure and filter or query “non-ready PQC resources” using the Network Endpoint page or Explorer. Check out other recent releases in the product documentation Tenable One OT Exposure Deeper IT/OT visibility for every corner of your environment Our latest release of Tenable One OT Exposure 4.7 expands visibility for grid operators and disconnected environments, and introduces a variety of productivity enhancements. OT agents for isolated networks: Get asset visibility and vulnerability coverage in air-gapped and disconnected environments (no sensors or live connectivity required) with offline scan profiles and a local agent UI for field technicians. Power substation anomaly detection: Passively monitors GOOSE streams and flags anomalous activity, such as configuration revision changes, giving utilities and grid operators critical visibility. Yokogawa DCS activity detection: Surfaces critical operational changes on Yokogawa Centum VP systems, so you can spot engineering activity that may signal unauthorized access. Centralized subnet management: Define CIDR boundaries and toggle monitoring across all ICPs from a single interface in Enterprise Manager, eliminating per-site configuration. Saved Views: Save, name, and reuse custom filter combinations across asset and findings views, cutting down repetitive setup during investigations. Asset side panel: Review asset details without leaving the findings or asset grid, for faster pivoting during investigations. Upgrade today to put these new capabilities to work in your environment. Explore the release notes Tenable Security Center Sharper visibility, streamlined operations The latest release of Tenable Security Center 6.9 brings several upgrades to help you accelerate your self-hosted vulnerability management program. Updated vulnerability findings interface: Rich filtering options (severity, asset, plugin, IP-based) and surfaced Vulnerability Priority Rating (VPR) insights help you zero in on what matters most, faster. Tenable Nessus scanner support via Sensor Proxy: Link Tenable Nessus scanners through the Sensor Proxy service for more flexible deployments and horizontal scaling across large enterprise and Tenable Enclave Security environments. Windows LAPS credential support: Dynamic credential retrieval from Active Directory (AD) strengthens scan security and reduces the admin burden of credential management. Expanded PAM Kerberos authentication: Support across BeyondTrust, Delinea, and CyberArk integrations gives you tighter credential control. One-click diagnostic bundle upload: Submit diagnostic files directly to Tenable Support from within your console, so we can resolve your cases faster. (Requires a valid Tenable Nessus feed license. Not supported in air-gapped environments.) Trending data moves to PostgreSQL: A lighter disk footprint and better performance for your trend reporting. Explore the release notes Tenable Nessus Stability fixes and continued security hardening with the latest Tenable Nessus releases Tenable Nessus 10.12.2 and 10.12.3 are now available, resolving a scanner connectivity issue and rounding out a batch of stability fixes: Your scanners stay online and up to date: We’ve addressed a bug where scanners could drop offline and stop receiving plugin updates after an upgrade, so you get consistent scan coverage without needing to manually check scanner status. Fewer stuck or incomplete agent scans: Cluster-based agent scans will finish reliably, so you will not need to re-run them. More accurate reporting on linked agents: You can always trust what you see in the console (requires Tenable Agent 11.2.0 or later). Want to see Tenable Nessus in action or level up your team’s skills? View a Tenable Nessus demo or purchase our on-demand training course. What these updates mean for you: If you were experiencing scanners going offline or missing plugin updates, updating to 10.12.3 will solve it. Tenable Agent customers should update to v11.2.0 or later to get the linked-agent plugin reporting fix. Review the release notes Tenable Nessus Professional data sheet Tenable Nessus Expert data sheet Tenable Patch Management Instant patch verification and expanded Linux support This latest update focuses on saving you time and verifying your fixes faster. Instantly verify patches: Automatically trigger a Nessus Agent scan the moment a patch finishes installing. You get immediate proof of CVE remediation without waiting for your next scheduled scan window. Natively patch EPEL packages: Update community-maintained add-on software across your Enterprise Linux distributions on the exact same schedule as your core OS, eliminating the need for custom scripts. Stronger security and faster performance: Benefit from upgraded AES-GCM encryption, easier TLS certificate management directly from your console, faster dashboard load times, and fixes that keep your maintenance windows accurate to prevent unwanted reboots. Read the full details on Tenable Connect Training and Product Education Tenable One Cloud Exposure Specialist Training refreshed in Tenable University The instructor-led Tenable One Cloud Exposure Specialist product training in Tenable University is rebuilt with modernized content and hands-on lab exercises. All labs and course content now reflect the latest user interface and recent feature releases. Learn more Buy instructor-led training Tenable Events and Webinars Virtual events Tenable customer update, July 2026: Watch the most recent quarterly customer update session. This informative, fast-paced overview explores how to better secure your expanding attack surface and consolidate critical security data. Products covered include Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, and Tenable Security Center. Watch the July customer update Live from SWARM: An announcement to shift the future of agentic AI security. Watch the replay of a special 15-minute session streaming directly from SWARM, our exclusive agentic AI build event at Black Hat USA 2026. The session dives into the realities of AI-augmented exposure management and a special announcement that will change how the infosec community collaborates on AI security. Watch on LinkedIn --- Read Tenable documentation.793Views1like0CommentsTenable Product Update Newsletter — June 2026
Check out our June newsletter to learn about the latest product and research updates, events, and educational content. Tenable One - Platform Updates Improve exposure prioritization in Tenable One with continuous security control validation As frontier AI models accelerate vulnerability discovery, the work of validating, prioritizing, and remediating vulnerabilities alongside other security weaknesses to understand the true exposure they create has become much more urgent. Validation in exposure management is a key capability to help you understand which exposures attackers can actually reach by understanding the accessibility and exposure. Prioritize exposures more effectively by seeing which attack paths active prevention and detection controls mitigate. Accelerate investigations and triage by filtering top attack paths and attack techniques based on the presence of security controls. Understand control context and status by viewing security control information in the node details view. Check out continuous control validation in Tenable One: Read the blog post Explore the guided demo Read more about Attack Technique Details Tenable One Vulnerability Management Implement granular custom roles for enhanced access control Give your teams exactly the access they need to do their jobs — without exposing sensitive scan settings, sensors, or compliance reports. Streamline access control by building custom roles. You can now build granular custom roles that dictate exactly what your users can see and do within the platform. With straightforward, one-click toggles, you can grant read or full-write access to specific tools like scans, sensors, or reports. Your existing custom roles will automatically transition to this new format, so existing custom roles will transition seamlessly with no manual migration required. Take the guided walkthrough Read the documentation Review the best practice guide Gain comprehensive visibility into endpoint application risk Managing decentralized endpoint applications introduces visibility gaps. Focus your patching on the software your employees actually use, instead of chasing thousands of generic alerts. Get a single view of all software running on your endpoints with the new Endpoint Application Visibility and Exposures One-Stop Shop report. Prioritize fixes based on how widely an app is deployed and its actual risk to your business, rather than just relying on generic severity scores. Access the endpoint application visibility report Enhance your threat analysis expertise with specialist training You can now access the updated instructor-led Tenable One Vulnerability Management Specialist Course in Tenable University, featuring: Streamlined curriculum focusing on advanced analysis, enabling you to interpret data and counter threats faster. Deep dives into critical new features, including Vulnerability Intelligence and Exposure Response. Refreshed educational experience with hands-on lab exercises to solidify your expertise. Learn more about this course and other instructor-led and on-demand Tenable University training and certification offerings: Course details Tenable training and certification Tenable One Cloud Exposure Transform disparate alerts into one threat story with Tenable cloud detection and response Cloud detection and response (CDR) in Tenable One Cloud Exposure is now generally available, adding near-real-time behavioral detection across multi-cloud environments. Tenable CDR capabilities include: AI-powered threat stories: AI-powered threat stories automatically correlate related detections by actor, resource, and tactic, transforming hundreds of raw alerts into a clear narrative of the attack, allowing teams to start investigating instantly. Runtime vulnerability validation: Uses active scanning to confirm cloud resources that are reachable from the internet. Dual coverage: Combines agentless detections with an optional eBPF runtime sensor, giving security teams comprehensive near-real-time visibility across cloud workloads without sacrificing deployment flexibility or coverage. Guided response: As the agentic engine of Tenable One, Tenable Hexa AI is the intelligence layer that reasons across live exposure context, threat findings, and environment history to deliver a prioritized, actionable response plan, in plain language, at attacker speed. With Tenable CDR, teams can leverage AI-driven pathways to investigate and remediate with speed, drive informed, actionable resolution, close the exposure gap, and extend attack path analysis to holistic remediation of real threats. Watch the guided demo Tenable One OT Exposure Tenable OT Security 4.7 (early access) This release expands visibility for grid operators and disconnected environments, and introduces a variety of productivity enhancements to accelerate analyst workflows: Power substation anomaly detection: Passively monitor GOOSE streams and alert on anomalous activity to protect utility and grid operations from unauthorized modifications or replay attacks. Yokogawa DCS activity detection: Get deep visibility into engineering activities on Yokogawa systems to easily detect critical operations and unauthorized access. OT agent for disconnected environments: Secure air-gapped networks without deploying sensors or requiring live connectivity, featuring offline scan profiles and a local agent UI. Workflow and enterprise management enhancements: Centrally manage subnets from a single Enterprise Manager interface, and speed up recurring investigations with new Saved Views, a quick-access Asset Side Panel, and TLS Syslog support. Explore the user guide Review the release notes Tenable Security Center Tenable Security Center 6.8 Focus on the vulnerabilities that matter with AI-powered VPR insights and mitigation guidance. This release streamlines your operations with unified asset repositories for IPv4, IPv6, and Agents, and improves efficiency with new background query processing and scan optimization capabilities. View the full release notes Tenable Nessus Maximize your Nessus capabilities with the Tenable Documentation hub Optimize your vulnerability assessments and accelerate troubleshooting with the official Tenable Nessus Documentation hub. Want to ensure you’re getting the absolute most out of your vulnerability assessments? Whether you’re a seasoned security pro fine-tuning your environment or just setting up your first Nessus Pro or Expert deployment, the hub provides everything you need to optimize your security workflows and troubleshoot: Stay ahead of the curve: Instantly access the latest release notes, system requirements, and seamless upgrade guides. Optimize your assessments: Find step-by-step instructions for configuring and launching scans. Streamline your reporting: Learn exactly how to customize, generate, and export compliance-ready scan results in PDF, HTML, or CSV formats to keep your stakeholders informed. Bookmark the documentation site to quickly discover new features, resolve configuration questions, and keep your attack surface secure. Tenable Nessus documentation Tenable Patch Management Synchronize asset tags across patching workflows Sync your existing security tags directly with your patching workflows to eliminate manual setup and fix vulnerabilities faster. If you already group your devices using tags or asset lists in Tenable One Vulnerability Management or Tenable Security Center, those groups will automatically synchronize with your patch console. You can target them for patch schedules and deployment waves without rebuilding them from scratch. This update also extends full patch support to SUSE Linux 15 SP6 (Server & Desktop). Get the full update details on Tenable Connect Tenable events and webinars Customer office hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable One Vulnerability Management, Tenable One Cloud Exposure, Tenable One Identity Exposure, and Tenable One OT Exposure. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa), and Asia-Pacific (APAC). Learn more and register Virtual events Tenable customer update, July 2026: Join the next quarterly customer update session at 11 a.m. EST/3 p.m. BST/5 p.m. CEST July 16. This informative, fast-paced overview will explore how to better secure your expanding attack surface and consolidate critical security data. Products covered include: Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, and Tenable Security Center. Register See all upcoming live and on-demand webinars Tenable Research Research security operations Read the latest insights from top security and data science researchers: Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect Key findings from the Verizon DBIR 2026 Read Tenable documentation.747Views1like0CommentsMarch 2026 Tenable Product Newsletter
Check out our March newsletter to learn about the latest product and research updates, upcoming and on-demand webinars, and educational content — all to help you get more value from your Tenable solutions. EXPOSURE 2026 Save 50% on the security conference of the year Don’t miss EXPOSURE 2026, the first-ever conference dedicated exclusively to proactive, unified exposure management. Join us in Boston, Mass., from May 19-21, 2026, to get: Hands-on instruction with Exposure Management Strategy or Tenable One Technical Training Practical resources and real-world insights from Tenable leaders and industry experts Register before March 31 to save 50% off admission and training with early-bird pricing. Tenable customer update webinar 11 a.m. EST/3 p.m. BST, April 9, 2026 Join our upcoming webinar for an informative, fast-paced overview of recent product updates and best practices. Hosted by a team of Tenable product experts, this session will explore how to better secure your expanding attack surface and consolidate critical security data. Register now. Tenable One Coming soon: Data portability for Tenable Attack Path Analysis (APA) We’re introducing Full Export for Tenable APA, allowing you to move beyond single-page views and transform high-level visualizations into actionable offline intelligence. Key capabilities: Comprehensive data: Export full datasets for Top Attack Paths and Top Attack Techniques into CSV or JSON formats. Risk context: Exports include critical metrics like Source NES (Node Exposure Score) and Target ACR (Asset Criticality Rating). High capacity: Easily trigger exports for up to 100K+ results via a new global UI button. API parity: Programmatically pull path data into your SIEM, SOAR, or custom tools using the Tenable Public API. Tenable Cloud Security This month’s updates focus on operational scale, synchronizing security standards, and automating remediation across complex multi-cloud environments. Highlight: Synchronized policy management With linked queries, you can now connect saved explorer searches directly to custom policies and reports. Eliminate manual version control: When you update a source query, every linked policy and report automatically syncs, so your security standards are identical across your entire organization. Operational control: Pause automated workflows for maintenance without losing your configurations using the new enable/disable toggle for automation rules. High-impact capabilities Actionable CI/CD pipelines: Maintain developer velocity by excluding unresolvable vulnerabilities from container image scans. This prevents noise from breaking builds when no patch is currently available. Confirmed reachability: Bridge the gap between theoretical risk and actual exposure with Network Endpoints now displayed in your Inventory to surface the actual, validated entry points for your resources. Dynamic IaC protection: Tenable now scans Terraform dynamic configurations to give you visibility into scaled infrastructure and complex definitions before deployment. Expanded compliance: Immediate support for CIS AWS 6.0.0 and the NIS2 Directive keeps your cloud accounts aligned with the latest global regulatory benchmarks. Strategic update: Domain transition Note: Critical for continued service. The Console URL has officially transitioned to app.tenable.com. Please update your bookmarks and firewall allow lists to include *.app.tenable.com immediately to prevent service interruption. View Full March Release Notes Tenable Vulnerability Management Introducing VM-Native OT Discovery Safely identify and profile connected PLCs, HMIs, and IoT devices using the vulnerability management toolset you already own. No specialized hardware or complex deployments required. Turn your existing IT security tools into a safe OT discovery engine today and get visibility into your IT/OT security gap. Watch the guided demo to see this new capability in action. For more information, explore the user guide documentation for Scan Templates and Discovery Settings. Clean up your scan data: New OS and app inventory dashboard Our new Operating System and Application Inventory with Data Troubleshooting dashboard gives you an instant, high-level view of your asset counts across every OS and application. By using built-in troubleshooting queries, you can identify and fix scan fidelity issues and prioritize risk based on the most accurate data possible. View the dashboard details. Nessus Maximize your vulnerability assessment strategy with our recently introduced interactive Tenable Nessus demos. Skip the manuals and get immediate, hands-on experience securing your attack surface. Explore the Nessus Professional Onboarding demo to launch your first comprehensive scans in minutes. Dive into the Nessus Expert Onboarding demo to master advanced assessment features and eliminate security blind spots, whether on-prem or in the cloud. Tenable Security Center Uncover the OT blind spots across your network If you’re not already a Tenable OT Security user, your IT environment is likely full of shadow OT, like HVAC controllers and IoT devices, that standard scans can’t see. We recently added native OT discovery capabilities directly inside Tenable Security Center, so you can safely map these assets using the tools you already own. Get deep identity data for PLCs and HMIs without risking a disruption or deploying new network sensors. See it in action in this guided demo, and find out how to configure your first scan here. Reminder: Upgrade to Tenable Security Center 6.8 Focus on the vulnerabilities that truly matter with AI-powered VPR insights and clear mitigation guidance. This release streamlines your operations with unified asset repositories for IPv4, IPv6, and Agents, and improves efficiency with new background query processing and scan optimization tools. Explore the release notes for more information before you upgrade. Tenable Patch Management Improved patching precision and reliability Update (v10.0.971.26) includes critical fixes around strategy corruption and inaccurate compliance reporting. By upgrading, you keep your workflows intact, your data precise, and your environment benefits from the modernized performance and security of Java 25. View the release notes or access TPM documentation. Tenable OT Security Update required: Tenable OT Security 4.5 Service Pack (version 4.5.61) We advise all customers currently running version 4.5 apply this upgrade immediately to ensure optimal system stability and performance when processing high volumes of network conversations. This update also addresses specific communication gaps with Rockwell Stratix devices and Nessus scans. Review the release notes for the full list of fixes and improvements. Introducing Tenable OT Security 4.6 (Early Access) Our upcoming release introduces a variety of new features, performance enhancements, and streamlined workflows for large-scale industrial environments. Massive subnet scaling: Now supports up to 5,000 subnets per ICP, significantly increasing visibility for massive enterprise deployments. Centralized network management: A new Monitored Networks page includes bulk-add capabilities and the ability to stage inactive networks before monitoring. Precision scanning: New Nessus workflows let you define specific credential usage per scan for safe discovery of sensitive assets. Streamlined platform navigation: Updated workflow for SSO/SAML users helps you pivot back to the Tenable One platform instantly with the return button. Remote agent updates and query restrictions: Update OT agents directly from the ICP. and remove local site visits or manual CLI intervention. New infrastructure for OT agents also enables you to restrict specific protocol queries. Enhanced diagnostics: Exported asset logs now include deeper metadata to speed up Support and Engineering troubleshooting. IoT connector overhaul: Major stability and performance fixes for Milestone, AvigilonES, and Exacq Edge integrations for IoT asset discovery. This update focuses heavily on large-scale infrastructure, refined scan controls, and better integration with the Tenable One ecosystem. Check out the release notes and user guide for details. Tenable Web App Scanning Stop chasing dead keys: New secrets validation for WAS Don’t waste time manually verifying every leaked credential. Our new Secrets Validation automatically tests detected tokens, like GitHub or AI service API keys, to see if they are live and exploitable. By distinguishing between a harmless string and a critical vulnerability, you can prioritize your remediation efforts based on real-world risk, rather than noise. View the documentation or read the full breakdown on Tenable Connect. Tenable Training and Product Education Evolve from reactive patching to proactive risk oversight The Exposure Management Business Theory course, now available at no cost in Tenable University, guides you in self-paced modules toward building a sustainable exposure management program through the five pillars of the exposure lifecycle: scoping, discovery, prioritization, validation, and mobilization. Get strategic insight to align Tenable’s capabilities with your business goals, drive meaningful change, and make informed decisions. Get hands-on expertise with current industrial security capabilities The newly-updated Tenable OT Security Specialist instructor-led training course, now aligned with Tenable OT Security version 4.4, ensures you can effectively protect your critical infrastructure using the latest product features and workflows. You will learn to: Maximize visibility: Learn to leverage these enhancements to see and secure every asset in your OT environment. Reduce risk: Practice real-world scenarios to identify vulnerabilities and threats faster. Get expert guidance: Interact directly with instructors to master complex configurations and best practices. Visit tenable.com/education to learn more about our Tenable University education offerings, see global instructor-led training (ILT) schedules, and buy virtual ILT or on-demand courses. Tenable webinars Tune in for product updates, demos, how-to advice, and Q&A. See all upcoming live and on-demand webinars at https://www.tenable.com/webinars. Customer office hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable Vulnerability Management, Tenable Cloud Security, Tenable Identity Exposure and Tenable OT Security. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa and Asia Pacific (APJ). Learn more and register here. Tenable Research Research Security Operations blog posts Subscribe to the Research team blog posts here. The cloud and AI velocity trap: Why governance is falling behind innovation Dynamic objects in Active Directory: The stealthy threat New malicious npm package "ambar-src" targets developers with open-source malware Research release highlights Improvement: Handling component installs for vulnerability assessment: Adds the ability to remove findings for component-based vulnerabilities from scan results New Dell OS10 compliance plugin and audit files: Customers can now measure compliance against Dell OS10 devices with new plugin ID Dell OS10 Compliance Checks (275781) on Tenable Vulnerability Management and Nessus. Content coverage highlights More than 2,700 new published vulnerability plugins. Nearly 50 new audits delivered to customers. Read Tenable documentation.558Views1like0CommentsDecember 2025 Tenable Product Newsletter
Greetings! Check out our December newsletter to learn about the latest product and research updates, upcoming and on-demand webinars and educational content — all to help you get more value from your Tenable solutions. Tenable One What's new in Tenable One: November 2025 release This month's release delivers broader visibility, deeper insights, and more tailored data analysis to help you manage and reduce risk. Release highlights: New Tenable One Connector: Connect Tenable One with your Claroty platform to manage OT risks alongside the rest of your attack surface to reveal how IT exposures can directly impact industrial control systems and critical infrastructure. Protect uptime and safety by viewing IT and OT as a single, connected environment. Edit widgets: Edit and update widgets on dashboards you own. Customize all configuration parameters, including widget type, categories, values, data labels, stacking, and filters, to tailor insights to your specific needs. RBAC new roles: Unlock more precise access control with a new custom exposure management role for more granular access to the different modules in Tenable One, including tag enforcement, along with a dedicated read-only role for improved oversight. See all platform enhancements >> Tenable Is a Leader in the First-Ever Gartner®️ Magic Quadrant™️ for Exposure Assessment Platforms We’re proud to share that Tenable has been named a Leader in the first-ever 2025 Gartner Magic Quadrant for Exposure Assessment Platforms, ranking highest for both Ability to Execute and Completeness of Vision. Tenable was also positioned as a Leader in both the IDC MarketScape: Worldwide Exposure Management 2025 Vendor Assessment and The Forrester Wave™️: Unified Vulnerability Management, Q3 2025. This recognition wouldn’t be possible without you — our customers. Your insights, feedback, and collaboration have been instrumental in shaping Tenable One, helping organizations around the world reduce exposure risk across their entire attack surface. Get the report > Tenable Cloud Security Console | Unified cross-cloud view: Explorer is the new unified page. Get a complete cross-cloud view of all resources and findings. Query across objects, export results, and use Graph view to visualize risk paths. Network | Validate real-world exposure: Network Scanner now validates actual external exposure to identify truly reachable cloud resources and exposed endpoints. Use real-world data to cut false positives and sharpen prioritization. IAM | Full entitlement insight: Inventory now displays all roles and identity-based policies across AWS, Azure, GCP, Entra ID, and Google Workspace, including unused ones. Proactively reduce entitlement risk by creating custom least-privilege policies for any supported role. Vulnerability management | Public AMI scanning: Expanded AWS coverage now supports scanning public AMIs (cloud-managed AMIs), including vendor and AWS-published images in your posture assessments for a comprehensive security view. View all updates>> Tenable Vulnerability Management Mobilize your VM data Unify teams and streamline remediation workflows with the initial release of mobilization services, beginning with ticketing integrations in Tenable Vulnerability Management. Automatically or manually create bi-directional tickets in Jira Cloud via Exposure Response Initiatives. This capability accelerates response times by synchronizing your security findings with tickets in Jira Cloud. See mobilization in action: Watch this walkthrough to see how to set up and use the new ticketing integration. Review the documentation and Quick Reference Guide for detailed steps. Note: ServiceNow ITSM ticketing mobilization is coming soon. Tenable Security Center What’s new in Tenable Security Center 6.7 See your environment more clearly and act faster on what matters most. This release delivers a modern, intuitive experience that improves usability, scalability, and efficiency across your operations. Here’s what’s new: Explore – Assets (preview): Get a modern view of your assets with advanced filtering and improved navigation that helps you identify risks faster. Triggered agent scanning: Automate Tenable Agent scans based on conditions you define, so you can catch vulnerabilities sooner and respond confidently. Credential verification scan policy: Quickly validate Windows and Unix credential pairs with a built-in template that confirms authentication success. Performance and reporting enhancements: Experience faster scan ingestion, faster reporting, and improved backend performance that keeps pace with your team. Before you upgrade: Tenable Security Center 6.7 supports upgrades from version 6.3.0 and later. Hardware specifications are updated for this release. Systems below the new recommendations will still upgrade successfully, but performance may vary. Upgrade now and read the release notes to take advantage of these improvements and keep your environment running at peak performance. Patches for Tenable Security Center Address recent vulnerabilities by applying two security patches: 202509.2.1 (resolves Critical SimpleSAML CVEs) and 202509.1 (resolves High PostgreSQL CVEs). You need manual installation for both. The Software Updates feature is not compatible with these patches. Key requirements: Compatibility: Patch 202509.2.1 applies to SC 6.4 through 6.6. Patch 202509.1 applies to SC 6.5.1 and 6.6.0. Prerequisite: If you are on SC 6.5.0, you must first upgrade to 6.5.1. Upgrade note: Patch 202509.2.1 may impact future SC upgrades. See this KB article for more information. Refer to the release notes and advisories (TNS-2025-20 and TNS-2025-18) for more information and download patches here. Tenable OT Security Introducing Tenable OT Security 4.5 (Early Access) The upcoming release of Tenable OT Security 4.5 – now available in Early Access – focuses on scalability for enterprise environments, enhanced power grid visibility, and improved integrations across the Tenable One portfolio. Advanced dynamic tagging: Streamline prioritization and reporting at scale with the ability to create rule-based groups and tags using multiple filters, including asset type, risk score, and criticality. Enhanced grid visibility (IEC 61850): Added support for IEC 61850 to improve passive detection of intelligent electronic devices (IEDs) with safer, deeper visibility for substation and power generation environments. RBAC for enterprise manager: New role-based access controls (RBAC) enable administrators to assign users to specific ICPs using user groups, so users only view the zones they are authorized to see while inheriting ICP-level roles. Unified SOC visibility: You can now directly view policy violations that Tenable OT Security detects, such as unauthorized access or failed logins, within Tenable Security Center dashboards and reports to bridge the gap between OT and the SOC. Expanded compliance mapping: The Compliance Dashboard now includes direct mapping for IEC 62443-3-3 and NIST-CSF to simplify how you measure and report against these critical security frameworks. In case you missed it: What’s new in Tenable OT Security 4.4 Unified exposure management: Sync your OT asset tags directly to Tenable One and Tenable Security Center to enrich enterprise IT security workflows with OT context. Deep visibility for specialized environments: Gain granular details on sensitive devices by importing PLC project files (starting with Rockwell Automation) without active queries. Reduced alert fatigue: A redesigned Policy Violations dashboard unifies disparate alerts into actionable insights to help you focus on your most critical exposures. Expanded protocols: Added support for Foxboro DCS and VXLAN environments. Streamlined workflows and sensor configuration: A new workflow helps you easily find and merge duplicate assets for a more accurate inventory, while a simplified sensor configuration reduces deployment complexity. Review the release notes to see what’s new and how to upgrade. Tenable Identity Exposure Attack path optimization: Complex attack path queries now time out after three minutes and automatically revert to the shortest, most viable path. Get critical findings faster when dealing with large-scale domain environments. (v3.109) Syslog direct linking: Syslog alerts now contain a new time-based URL. Use this link to jump instantly to the exact incident details within Tenable Identity Exposure to accelerate your investigation and response workflow. (v3.108) Kerberos IoE clarity: The Dangerous Kerberos Delegation Indicator of Exposure (IoE) now features dedicated paragraphs for each vulnerability reason to simplify understanding and make remediation steps clearer and more concise. (v3.108) View all updates>> Tenable Web App Scanning Optimized scanning for production environments Eliminate conflicts with peak traffic hours using enhanced scan windows. You can now define granular scan (green) or pause (red) windows for individual scans, independent of global settings. Whether spanning multiple days or scheduling multiple windows per day, your assessments automatically progress during approved hours without manual restarts. For more details, review the documentation for pause and resume scans and basic scan settings. Tenable Enclave Security Tenable Enclave Security and Container Security 1.7 now generally available This release brings Security Center 6.7 into the Enclave Security platform and introduces exposure response for container security. See our announcement above for more information on the benefits of Security Center 6.7. With exposure response in container security, customers can better track and prioritize remediation efforts by: Creating initiatives to identify critical exposures, assign ownership and apply SLAs Managing initiatives through customizable dashboards Using advanced query capabilities to drill into specific findings, assets or vulnerability combinations. For more information review the Tenable Enclave Security 1.7 release notes. Tenable Cloud Security FedRAMP Tenable Cloud Security now available through GSA OneGov Federal agencies can now purchase Tenable Cloud Security FedRAMP through the GSA OneGov program at a 65% discount through March 2027. This partnership makes it easier and more cost effective for federal agencies to identify and reduce cloud risk by gaining visibility into misconfigurations, vulnerabilities and excessive permission across cloud environments, supporting federal cloud first policies and zero trust initiatives. Interested agencies should request more information on our Tenable and GSA webpage or email [email protected]. For more information: Attend our webinar on January 15, 2026: Cloud security for federal agencies: Threats, best practices and the GSA OneGov advantage Read our blog: Tenable partners with GSA OneGov to help federal government boost its cloud security Tenable Training and Product Education Enhance your attack surface management skills Benefit from a superior learning experience with the updated Introduction to Tenable Attack Surface Management course. We've introduced a modernized interface and smoother navigation for immediate improvement. Access this no-cost course, along with many other on-demand options, anytime at Tenable University. Start learning today to gain essential skills and better manage your organization's external attack surface. Tenable Webinars Tune in for product updates, demos, how-to advice and Q&A. See all upcoming live and on-demand webinars at https://www.tenable.com/webinars. On-demand Escape the patching cycle. A guide to autonomous risk-based patching. Securing the future of AI in your enterprise. Policy frameworks that balance opportunity and oversight. Customer Office Hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable Vulnerability Management, Tenable Cloud Security, Tenable Identity Exposure and Tenable OT Security. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa and Asia Pacific (APJ). Learn more and register here. Tenable Research Research Security Operations blog posts Subscribe to the Research team blog posts here. Agentic AI security: Keep your cyber hygiene failures from becoming a global breach A practical defense against AI-led attacks CVE-2025-55182: Frequently asked questions about React2Shell: React server components remote code execution vulnerability FAQ About Sha1-Hulud 2.0: The "second coming" of the npm supply-chain campaign CVE-2025-64446: Fortinet FortiWeb zero-day path traversal vulnerability exploited in the wild Microsoft Patch Tuesday 2025 Year in Review Microsoft addresses 56 CVEs, including two publicly disclosed vulnerabilities and one zero-day that was exploited in the wild to close out the final Patch Tuesday of 2025 Research release highlights Introducing new plugins to assess security posture for the transition toward Post-Quantum Cryptography (PQC)! Tenable Research PQC support helps customers inventory use of TLS and SSH quantum-resistant and vulnerable algorithms within their infrastructure using remote Nessus-based scans. For more information, see the Release Highlight. Content coverage highlights More than 5,000 new vulnerability plugins published, including new detections for the recent F5 BIG-IP Breach. More than 50 new audits delivered to customers. Read Tenable documentation.408Views1like0CommentsTenable Cloud Vulnerability Management is now available
Identifying and remediating vulnerabilities is too important to settle for incomplete, inadequate, or poorly supported solutions. Tenable Cloud Vulnerability Management provides full visibility across your cloud environments to deliver detailed prioritization and remediation all in one user-friendly interface. This simplifies multi-cloud visibility and offers Tenable’s leading vulnerability management intelligence. To learn more about how your organization can benefit from Tenable Cloud VM, contact your Tenable account team or view these resources: Product Highlights Data Sheet: Vulnerability management for multi-cloud environments Product Overview: Tenable Cloud Vulnerability Management Blog: Reducing Vulnerability Risk in the Cloud Era Interactive Demo164Views1like0CommentsJune 2025 Product & Research Update Newsletter
The June 2025 Tenable Product & Research Newsletter is live. This month's edition covers updates on: Tenable Cloud Security, Tenable Identity Exposure, Tenable Patch Management, Tenable Security Center, and Tenable VM, along with updates about the Tenable Ecosystem, Tenable Connect, Training, Professional Services, Research, and more. Community Update Introducing Tenable Connect, your new customer community! Check out your new hub to connect, learn and grow with Tenable. Here’s what you’ll find: Ability to open and manage support cases Easy access to the improved account management portal Dedicated pages for product resources and training Discussion boards and opportunities to engage with your peers and Tenable Log into Tenable Connect before July 1 for a chance to win a limited edition Tenable Connect t-shirt! Tenable Identity Exposure Tenable’s Research-Driven Identity Defense Expands Tenable continues to deepen its coverage of real-world identity risks with a series of new indicators of exposure (IoEs) across both Active Directory (AD) and Entra ID. BadSuccessor—a rare, but forest-level critical, zero-day privilege escalation vulnerability in AD, was recently disclosed. Introduced with delegated Managed Service Accounts (dMSAs) in Windows Server 2025, its exposure depends on the presence of a 2025 domain controller, but the impact can be severe. An attacker with the right permissions could use a dMSA to inherit domain admin-level access and compromise the entire forest. Tenable has responded quickly with a dedicated IoE: BadSuccessor – Dangerous dMSA Permissions, now available in Tenable Identity Exposure (SaaS) v3.95. This detection flags risky dMSA inheritance paths that could enable exploitation, helping organizations stay ahead even in the absence of a Microsoft patch. Review Tenable’s technical advisory and FAQ for detailed context. More IoEs targeting real-world risk Other new IoEs target misconfigurations and gaps attackers routinely exploit, spanning Tier 0 risks in AD and hygiene issues in Entra ID. Each IoE is designed to be practical, observable and relevant, shaped by real attack behaviors, not just theoretical risks. Check out this product documentation for more information. Active Directory Tenable IoE “Sensitive Exchange Group Members” Who really sits in the most privileged Exchange groups: a Tier‑0 foothold. Tenable IoE “Exchange Permissions” Risky ACLs where Exchange rights bleed into domain control. Entra ID Tenable IoE “Users Allowed to Join Devices” Tenant setting that lets any user enroll a rogue workstation. Tenable IoE “Managed Devices Not Required for Auth” Conditional‑access gap allowing unmanaged logins. Tenable IoE “Auth‑Methods Migration Incomplete” Legacy authentication policy is still exposed. Tenable IoE “Dangerous Application Permissions” Third‑party app scopes that can exfiltrate data. Tenable IoE “Risky Users Without Enforcement” Risk‑based access policy missing for high‑risk accounts. Tenable Cloud Security Reminder: Tenable Cloud Security requires you to log in to view documentation. To access the documentation or try Tenable Cloud Security, contact your account manager or request a demo. Enhanced CVE detection and customizable severity metrics Tenable Cloud Security now enhances CVE detection by integrating Tenable's vulnerability logic, leveraging the Tenable vulnerability data lake (TVDL) and Nessus. This improves accuracy and coverage in detecting new CVEs regardless of National Vulnerability Database (NVD) delays. The integration aligns CVE detection between Tenable Cloud Security and Tenable Vulnerability Management, reducing inconsistencies and boosting reliability within Tenable One. Users can select which CVE severity metric to display first: CVSS (static) or VPR (dynamic, factoring exploit likelihood). The metric chosen as primary impacts finding creation: severity changes can cause related findings to open or close. Just-in-time by resource groups and recurring access Thanks to your feedback, Just-in-Time (JIT) access is now even more powerful and flexible. Azure users can request access at the resource group level, not just by subscription, giving you greater granularity and control across your cloud environments. And for all JIT users, building on existing immediate/scheduled access request support, we’ve added recurring access scheduling — to better support business workflows, such as a contractor needing project access for a specified repeat duration or the need for access to a routine audit that lasts a full quarter. Easily set daily, weekly or monthly schedules with end dates — all through an intuitive UI. Consider using recurring access to replace standing permissions that some JIT users may still have, for more granular time-bound least privilege. Powerful Tenable cloud vulnerability insights within ServiceNow Tenable now integrates with ServiceNow’s new Vulnerability Response platform, enabling you to seamlessly import prioritized, actionable vulnerability data directly into ServiceNow. This streamlined integration, which also supports government environments, helps teams focus on what matters most by aligning Tenable findings with your existing remediation workflows, making it easier to act fast on critical risks. Already using ServiceNow ticketing? You can now sync Tenable findings with ServiceNow incidents, mapping severity and status to priority and state (such as open findings to new incidents). Note: Syncing incident states requires additional permissions and configuration within ServiceNow. Selectively scan data resources by exclusion tags You can now add exclusion tags to fine-tune scans of both managed databases and object storage in Tenable Cloud Security. Exclusion tags enable you to scope out resources starting from the next scanning cycle by specifying tags as configured at the resource level, for tailoring scans to your environment. This new capability helps you decrease costs by reducing unnecessary resource usage. Object storage comes to OCI As part of our growing capabilities around Oracle Cloud, Tenable Cloud Security now offers data analysis of object storage buckets in OCI. Out of the box, the feature is on a par with all other object storage that Tenable Cloud Security supports and is part of routine CSPM onboarding. In other updates, new dynamic scan scoping by tag is also supported for OCI. Tenable Vulnerability Management (TVM) Tenable Data Stream (TDS) now supports the streaming of TVM Host Audit Findings data as well as WAS assets, tags and findings data. TDS already supports TVM host assets, tags and vulnerabilities data streaming to AWS S3 buckets and is used by some of the largest TVM customers. Learn more about TDS here. Besides the new payloads, there are a few more improvements: Additional new fields in TVM findings payload like Resurfaced Data and Time Taken to Fix Grouping of the files written in the AWS S3 buckets is now based on timestamp, resulting in fewer files written, which in turn improves consumption and reduces latency. (Previously, this was based on both scan ID and timestamp, which resulted in writing a large number of small files.) Tenable Patch Management Tenable Patch Management now supports Red Hat Enterprise Linux (RHEL) We’re excited to announce that Tenable Patch Management (On-Prem) 9.2.967.20 now supports RHEL 8 and RHEL 9. This release also includes performance improvements, bug fixes, and an important security update to Java 17 JRE. Please note that Patch Notification Bots using WhatsApp require review and modification as they can no longer be combined with other providers. Please visit here for a list of third-party applications covered. Note: We are always adding more. For more information, please read the Tenable Documentation and Release Notes and visit the Downloads Portal for the latest version. Tenable OT Security Upgrade to Tenable OT Security 4.2 to unlock new layers of visibility across your OT/IT environment. Key enhancements in this release include: Advanced SNMP-based asset discovery: Gain deeper OT network topology insight. Our new SNMP Crawler discovers and maps all connected devices and switches, including previously hidden ones, down to the specific switch port. Intelligent hardware lifecycle management: Proactively manage obsolescence with EOL tracking for OT/IoT assets from vendors such as Schneider Electric and Siemens, complementing existing software EOL capabilities. Flexible Windows-based deployment (beta): Install OT Security sensors directly on Windows devices — ideal for segmented subnets or where deploying dedicated physical hardware appliances isn’t feasible. Enhanced IoT & VMS risk insights: With improved IoT connectors and expanded VMS support through enhanced credentialed authentication, extract richer data from IoT devices and VMS (including asset names, models and stream details). Navigation enhancements: A redesigned main menu and intuitive side panel simplify access to critical OT data, speeding workflows and improving usability. Additional improvements: Fewer operational reboots New vulnerability detections Expanded virtualization support for Microsoft Hyper-V and KVM-based platforms Upgraded embedded Tenable applications (Nessus, Nessus Network Monitor) Expanded Device Fingerprint Engine coverage for devices from various vendors To learn more about what’s new in Tenable OT Security, watch the latest customer update or review the release notes. Tenable Security Center Patch 202505.1 is now live This patch addresses high-severity CVEs in SQLite. It applies to SC versions 6.5.1 and 6.4.x and requires manual application. Release notes for 6.5.1 and 6.4x Download: https://www.tenable.com/downloads/security-center Security advisory: https://www.tenable.com/security/tns-2025-09 Tenable Ecosystem Tenable Plugin for Jira on-premises v10.4.1 now supports Tenable Web App Scanning We’re excited to launch Tenable Plugin for Jira v10.4.1. This release includes: Support for Tenable Web App Scanning (TWAS) Security update Cleaner logs regarding API responses And bug fixes For more information, please read the Tenable Documentation and visit Atlassian Marketplace to download the newest versions. Tenable App for Splunk v6.1.0 The Tenable App for Splunk v6.1.0 is now available. This release includes: Added support for Tenable Web App Scanning (TWAS) and Tenable OT Security (TOT) New “Assets Dashboard” for visualizing asset details across TVM, TSC, TOT, TWAS, and TASM For more information, please read the Tenable Documentation and visit Splunkbase to download. Tenable Nessus Early Access Release of Nessus 10.9.0 We’re excited to announce the early access of Nessus 10.9.0. For standalone Nessus Expert users, this includes web application scanning functionality for Nessus instances in air-gapped/offline environments. For more information, please see our release documentation. Tenable Training and Product Education Tenable University is excited to announce the refreshed Introduction to Tenable One course. This course covers key features of the Exposure Management platform, including the workspace, Exposure Signals, Attack Path Analysis, Inventory and more, giving you a strong foundation to understand and act on your exposure data. Tenable Professional Services Tenable Professional Services offers two levels of Tenable One Deployment Service, both of which provide a structured, end-to-end approach for implementing and optimizing the Exposure Management platform. With this guidance, your team can gain the visibility, confidence and capabilities needed to actively manage exposure and reduce cyber risk. Tenable Webinars Customer Update Webinars Tune in for product updates, demos, how-to advice and live Q&A to help you get more value from your investment in Tenable solutions. LIVE July 2025 Tenable WAS, July 8, 2025, 11 am ET: Join us for a deep dive into recently released WAS features and capabilities. Tenable Nessus, July 8, 2025, 1 pm ET: Testing for specific CVEs with Nessus. Tenable OT Security, July 9, 2025, 11 am ET: Learn how Tenable OT Security 4.3 unlocks unprecedented visibility and control across your OT/IT environment. Tenable Vulnerability Management, July 9, 2025, 1 pm ET: Credentialed scans versus uncredentialed scans and how to use managed credentials. Tenable One, July 10, 2025, 11 am ET: Learn how Tenable One can now ingest important security context from non-Tenable security tools to help better identify, prioritize and reduce cyber risk. Tenable Security Center, July 10, 2025, 1 pm ET: OS breakdown: reporting exposures by operating system. ON-DEMAND June 2025 Tenable Identity Exposure: Join us to explore new features and capabilities in the latest release of Tenable Identity Exposure. Tenable Nessus: Discovery scan templates and when to use them. Tenable Cloud Security: Just-in-time (JIT) access dramatically reduces exposure from compromised identities. Join us to learn how this capability is enabled with Tenable Cloud Security. Tenable Vulnerability Management: Develop exposure response strategies with Tenable Vulnerability Management. Tenable One: Learn how Exposure Signals and Installed Software leverage data from your security stack to enrich Tenable One findings and strengthen the impact of your exposure management efforts. Tenable Security Center: Learn when and how to use triggered Agent scanning in Security Center. Customer Office Hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable Vulnerability Management, Tenable Cloud Security, Tenable Identity Exposure and Tenable OT Security. Time-zone-appropriate sessions are available for the Americas and Europe (including the Middle East and Africa, and Asia Pacific). Learn more and register here. Other Webinars of Interest June 25, 2025: Research Insights from the 2025 Verizon DBIR: What You Need to Know to Secure Smarter June 24, 2025: From Fundamentals to Focus: Enhancing Cloud Security with Tenable - Customer Workshop Series June 17, 2025: Beyond Cyber Chaos: How Public Sector Orgs Secure Smarter with Exposure Management On-demand: Security Without Silos: How to Gain Real Risk Insights with Unified Exposure Management For More Webinars Please visit tenable.com/webinars for the most up-to-date schedule. Tenable Research Research Security Operations Announcement Where Capability Meets Opportunity: Meet the Tenable Research Special Operations Team Rapid Response Microsoft’s May 2025 Patch Tuesday Addresses 71 CVEs (CVE-2025-32701, CVE-2025-32706, CVE-2025-30400) CVE-2025-32756: Zero-Day Vulnerability in Multiple Fortinet Products Exploited in the Wild CVE-2025-4427, CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Remote Code Execution CVE-2025-31324: Vulnerability in SAP NetWeaver Exploited in the Wild Tenable Research Advisories HPE Insight Remote Support Multiple Vulnerabilities Siemens User Management Component V2.15 Multiple Vulnerabilities Feature Release Highlights New Plugin Family: Tencent Linux Local Security Checks Azure Cloud Infrastructure Scanning for Government Windows LAPS Support in Nessus-based scanners Over 400 New Vulnerability Detections in June!209Views1like1Comment