CVE-2026-21514
published 2026-02-10CVE-2026-21514: Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
PriorityP180high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2026-03-03
Exploited in the wild
EPSS
1.52%
71.7th percentile
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | microsoft_365_apps_for_enterprise | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2021 | >= 16.0.1 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_2024 | >= 16.0.0 < https://aka.ms/OfficeSecurityReleases | https://aka.ms/OfficeSecurityReleases |
| microsoft | microsoft_office_ltsc_for_mac_2021 | >= 16.0.1 < 16.106.26020821 | 16.106.26020821 |
| microsoft | microsoft_office_ltsc_for_mac_2024 | >= 16.0.0 < 16.106.26020821 | 16.106.26020821 |
| microsoft | office_long_term_servicing_channel | — | — |
| microsoft | office_long_term_servicing_channel | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_32-bit_systems | — | — |
| msrc | microsoft_365_apps_for_enterprise_for_64-bit_systems | — | — |
| msrc | microsoft_office_ltsc_2021_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2021_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_32-bit_editions | — | — |
| msrc | microsoft_office_ltsc_2024_for_64-bit_editions | — | — |
| msrc | microsoft_office_ltsc_for_mac_2021 | — | — |
| msrc | microsoft_office_ltsc_for_mac_2024 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- ·No operational intelligence (IOCs, detection rules, or concrete technical indicators) for CVE-2026-21514 is present in any of the provided source documents. The sources only contain a brief NVD description (OLE security-feature bypass in Microsoft Word, local attack vector) and passing references in article teasers. No hashes, domains, IPs, commands, YARA/Sigma/Snort rules, or malicious file paths are documented. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cjj3-m869-748g: Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally
ghsa_unreviewed·2026-02-10
CVE-2026-21514 [HIGH] CWE-807 GHSA-cjj3-m869-748g: Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
VulnCheck
Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
vulncheck·2026·CVSS 7.8
CVE-2026-21514 [HIGH] CWE-807 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.
Affected: Microsoft Office
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2026-Feb; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; ht
CISA
Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
cisa·2026-02-10·CVSS 7.8
CVE-2026-21514 [HIGH] CWE-807 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
Vulnerability: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability
Affected: Microsoft Office
Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21514 ; https://nvd.nist.gov/vuln/detail/CVE-2026-21514
Remediation Due Date: 2026-03-03
Microsoft
Microsoft Word Security Feature Bypass Vulnerability
vendor_msrc·2026-02-10·CVSS 7.8
CVE-2026-21514 [HIGH] CWE-807 Microsoft Word Security Feature Bypass Vulnerability
Microsoft Word Security Feature Bypass Vulnerability
Description: Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send a user a malicious Office file and convince them to open it.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
This update addresses a vulnerability that bypasses OLE mitigations in Microsoft 365 and Microsoft Office which protect users from vulnerable COM/OLE controls.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane is not an attack vector.
Microsoft O
No detection rules found.
No public exploits indexed.
Securelist
Exploits and vulnerabilities in Q1 2026
blogs_securelist·2026-05-07·CVSS 7.8
CVE-2026-21519 [HIGH] Exploits and vulnerabilities in Q1 2026
Alexander Kolesnikov
Table of Contents
Statistics on registered vulnerabilities
Exploitation statistics
Windows and Linux vulnerability exploitation
Most common published exploits
Vulnerability exploitation in APT attacks
C2 frameworks
Notable vulnerabilities
CVE-2026-21519: Desktop Window Manager vulnerability
RegPwn (CVE-2026-21533): a system settings access control vulnerability
CVE-2026-21514: a Microsoft Office vulnerability
Clawdbot (CVE-2026-25253): an OpenClaw vulnerability
CVE-2026-34070: LangChain framework vulnerability
CVE-2026-22812: an OpenCode vulnerability
Conclusion and advice
Authors
Alexander Kolesnikov
During Q1 2026, the exploit kits leveraged by threat actors to target user systems expanded once again, incorporating new exploits for the Microsoft Off
Tenable
Operation Epic Fury: Why exposure data changes everything about Iran's cyber-kinetic campaign
blogs_tenable·2026-03-17
Operation Epic Fury: Why exposure data changes everything about Iran's cyber-kinetic campaign
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
How to prepare for NERC CIP compliance deadlines in 2026 and beyond
blogs_tenable·2026-03-17
How to prepare for NERC CIP compliance deadlines in 2026 and beyond
Blog / Products
Subscribe
# How to prepare for NERC CIP compliance deadlines in 2026 and beyond
Matt Tucker
March 17, 2026
5 Min Read
Explore key cybersecurity requirements and implementation deadlines for electric power utilities included in the NERC CIP-003-9 standard for Low-Impact BES (Bulk Electric System) Cyber Systems, and how Tenable can help deliver the comprehensive visibility required to ensure compliance.
## Key takeaways
1. NERC CIP-003-9 introduces specific requirements for electric power utilities and related sectors with low-impact BES cyber systems.
2. Many municipally owned utilities, public power authorities and state or locally operated transmission entities fall within the scope of Low Impact BES Cyber Systems and will be impacted by these revisions.
3. With the
Tenable
How to prepare for NERC CIP compliance deadlines in 2026 and beyond
blogs_tenable·2026-03-17
How to prepare for NERC CIP compliance deadlines in 2026 and beyond
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Operation Epic Fury: cyber threat data in the Iran War
blogs_tenable·2026-03-17·CVSS 7.8
[HIGH] Operation Epic Fury: cyber threat data in the Iran War
Blog / Cyber Exposure Alerts
Subscribe
# Operation Epic Fury: Why exposure data changes everything about Iran's cyber-kinetic campaign
Robert Huber
March 17, 2026
13 Min Read
Iran's retaliatory campaign following Operation Epic Fury has collapsed the boundary between physical and digital warfare. Tenable's exposure data analysis across seven target countries reveals that the largest exploitable attack surface isn't the headline threat, it's a Microsoft Word N-day affecting nearly 14 million assets.
## Key takeaways:
1. Exposure data rebalances the threat picture. A Microsoft Word N-day (CVE-2026-21514) accounts for nearly 14 million of the 15.5 million affected assets across the seven target countries, two orders of magnitude more than the conflict's headline threats. Organizations
Tenable
CVE-2026-21514 FAQ: OLE bypass N-Day in Microsoft Word | Tenable®
blogs_tenable·2026-03-17·CVSS 7.8
CVE-2026-21514 [HIGH] CVE-2026-21514 FAQ: OLE bypass N-Day in Microsoft Word | Tenable®
Blog / Cyber Exposure Alerts
Subscribe
# FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word
Research Special Operations
March 17, 2026
10 Min Read
An N-day vulnerability in Microsoft Word exposes nearly 14 million assets. Attackers can exploit this flaw to bypass security prompts, enabling deployment of malware and establishing persistent access without triggering user warnings.
## Key takeaways:
1. CVE-2026-21514 is a Microsoft Word n-day that bypasses OLE and Mark-of-the-Web protections, executing payloads silently without triggering user security prompts
2. Tenable's exposure data analysis identified nearly 14 million affected assets across seven Tier-1 countries still vulnerable to CVE-2026-21514
3. Prioritize patching CVE-2026-21514 across all managed endpoints and deplo
Tenable
FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word
blogs_tenable·2026-03-17·CVSS 7.8
[HIGH] FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Iranian-linked actors are engaging in disruptive attacks
blogs_tenable·2026-03-11
Iranian-linked actors are engaging in disruptive attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Rapid7
Rapid7 Detection Coverage for Iran-Linked Cyber Activity
blogs_rapid7·2026-03-11
Rapid7 Detection Coverage for Iran-Linked Cyber Activity
The tension arising out of the conflict in Iran is beginning to show signs of expanding beyond a strictly regional crisis. Following our recent published advisories, this communication is intended to outline and summarize the detection and enrichment coverage available to Rapid7 customers, broadly assess the macro cyber threat landscape, and demonstrate the specific actions undertaken within the Rapid7 portfolio to assure our customers of the protection they receive and can expect moving forward. For a research-driven companion piece from Rapid7 Labs, dive into Iran’s Cyber Playbook in the Escalating Regional Conflict.
## Tracking the campaigns associated with the current conflict
There exists a number of threat campaigns (both directly and indirectly) associated with groups associated w
Rapid7
Rapid7 Detection Coverage for Iran-Linked Cyber Activity
blogs_rapid7·2026-03-11
Rapid7 Detection Coverage for Iran-Linked Cyber Activity
The tension arising out of the conflict in Iran is beginning to show signs of expanding beyond a strictly regional crisis. Following our recent published advisories, this communication is intended to outline and summarize the detection and enrichment coverage available to Rapid7 customers, broadly assess the macro cyber threat landscape, and demonstrate the specific actions undertaken within the Rapid7 portfolio to assure our customers of the protection they receive and can expect moving forward. For a research-driven companion piece from Rapid7 Labs, dive into Iran’s Cyber Playbook in the Escalating Regional Conflict .
## Tracking the campaigns associated with the current conflict
There exists a number of threat campaigns (both directly and indirectly) associated with groups associated
Tenable
March 2026 Microsoft Patch Tuesday | Tenable®
blogs_tenable·2026-03-10·CVSS 8.8
CVE-2026-21262 [HIGH] March 2026 Microsoft Patch Tuesday | Tenable®
Blog / Cyber Exposure Alerts
Subscribe
# Microsoft’s March 2026 Patch Tuesday Addresses 83 CVEs (CVE-2026-21262, CVE-2026-26127)
Research Special Operations
March 10, 2026
4 Min Read
1. 8Critical
2. 75Important
3. 0Moderate
4. 0Low
Microsoft addresses 83 CVEs including two vulnerabilities that were publicly disclosed prior to a patch being released.
Microsoft patched 83 CVEs in its March 2026 Patch Tuesday release, with eight rated critical and 75 rated as important. Our counts omitted one CVE (CVE-2026-26030) assigned by GitHub.
This month’s update includes patches for:
- .NET
- ASP.NET Core
- Active Directory Domain Services
- Azure Arc
- Azure Compute Gallery
- Azure Entra ID
- Azure IoT Explorer
- Azure Linux Virtual Machines
- Azure MCP Server
- Azure Portal Windows Admin Cen
Tenable
March 2026 Microsoft Patch Tuesday | Tenable®
blogs_tenable·2026-03-10
March 2026 Microsoft Patch Tuesday | Tenable®
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Sophos
February’s Patch Tuesday assumes battle stations
blogs_sophos·2026-02-13
February’s Patch Tuesday assumes battle stations
Akuter Cyberangriff? Fordern Sie Sofort-Hilfe an
Sophos Central
Partner-Portal
Lizenzen & Accounts
Sophos Home
Sophos Central
Sophos-Central-Anmeldung
Sophos KI
Integrationen
Threat Intelligence
Testversion
Endpoint Protection (Next-Gen Antivirus)
EDR – Endpoint Detection and Response
Server Protection
Mobile Security
XDR – Extended Detection and Response
XDR mit Next-Gen SIEM
ITDR – Identity Threat Detection and Response
Next-Gen Firewall (NGFW)
NDR – Network Detection and Response
Netzwerk-Switches
Wireless Access Points
Workspace Protection
Protected Browser
Zero Trust Network Access (ZTNA)
DNS Protection
Email Monitoring System
E-Mail- und Phishing-Schutz
Awareness-Training für Mitarbeitende
Schutz für Cloud Workloads
Cloud Security Posture Management (CSP
Qualys
Microsoft and Adobe Patch Tuesday, February 2026 Security Update Review
blogs_qualys·2026-02-10
Microsoft and Adobe Patch Tuesday, February 2026 Security Update Review
## Table of Contents
Microsoft Patch Tuesday forFebruary2026
Adobe Patches for February 2026
Zero-day Vulnerabilities Patched inFebruaryPatch Tuesday Edition
Critical Severity Vulnerabilities Patched inFebruaryPatch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response with TruRisk Eliminate
Qualys Monthly Webinar Series
Microsoft’s February 2026 Patch Tuesday focuses on closing security gaps that attackers could exploit, reinforcing the importance of timely patching in enterprise environments. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for February 2026
This month’s release addresses 61 vulnerabilities, i
Bleepingcomputer
Microsoft February 2026 Patch Tuesday fixes 6 zero-days, 58 flaws
blogs_bleepingcomputer·2026-02-10·CVSS 8.8
[HIGH] Microsoft February 2026 Patch Tuesday fixes 6 zero-days, 58 flaws
## Microsoft February 2026 Patch Tuesday fixes 6 zero-days, 58 flaws
## Lawrence Abrams
25 Elevation of Privilege vulnerabilities
5 Security Feature Bypass vulnerabilities
12 Remote Code Execution vulnerabilities
6 Information Disclosure vulnerabilities
3 Denial of Service vulnerabilities
7 Spoofing vulnerabilities
When BleepingComputer reports on Patch Tuesday security updates, we only count those released by Microsoft today. Therefore, the number of flaws does not include 3 Microsoft Edge flaws fixed earlier this month.
As part of these updates, Microsoft has also begun to roll out updated Secure Boot certificates to replace the original 2011 certificates that are expiring in late June 2026.
"With this update, Windows quality updates include a broad set of targeting data that i
Krebs
Patch Tuesday, February 2026 Edition
blogs_krebs·2026-02-10·CVSS 7.8
CVE-2026-21510 [HIGH] Patch Tuesday, February 2026 Edition
Microsoft today released updates to fix more than 50 security holes in its Windows operating systems and other software, including patches for a whopping six “zero-day” vulnerabilities that attackers are already exploiting in the wild.
Zero-day #1 this month is CVE-2026-21510, a security feature bypass vulnerability in Windows Shell wherein a single click on a malicious link can quietly bypass Windows protections and run attacker-controlled content without warning or consent dialogs. CVE-2026-21510 affects all currently supported versions of Windows.
The zero-day flaw CVE-2026-21513 is a security bypass bug targeting MSHTML, the proprietary engine of the default Web browser in Windows. CVE-2026-21514 is a related security feature bypass in Microsoft Word.
The zero-day CVE-2026-21533 all
Talos
Microsoft Patch Tuesday for February 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-02-10·CVSS 8.8
CVE-2026-21522 [HIGH] Microsoft Patch Tuesday for February 2026 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for February 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for February 2026, which includes 59 vulnerabilities affecting a range of products, including two that Microsoft marked as “Critical”.
CVE-2026-21522 is a critical elevation of privilege vulnerability affecting Microsoft ACI Confidential Containers. Successful exploitation of this vulnerability could enable an authorized attacker to escalate privileges on affected systems. This vulnerability is not listed as publicly disclosed and received a CVSS 3.1 score of 6.7.
CVE-2026-23655 is a critical information disclosure vulnerability affecting Microsoft ACI Confidential Containers. This vulnerability could enable an authorized attacker to disclose sensit
Qualys
Microsoft and Adobe Patch Tuesday, February 2026 Security Update Review | Qualys
blogs_qualys·2026-02-10
Microsoft and Adobe Patch Tuesday, February 2026 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday forFebruary2026
- Adobe Patches for February 2026
- Zero-day Vulnerabilities Patched inFebruaryPatch Tuesday Edition
- Critical Severity Vulnerabilities Patched inFebruaryPatch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response with TruRisk Eliminate
- Qualys Monthly Webinar Series
Microsoft’s February 2026 Patch Tuesday focuses on closing security gaps that attackers could exploit, reinforcing the importance of timely patching in enterprise environments. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tuesday for February 2026
This month’s release addresses 61 vulner
Krebs
Patch Tuesday, February 2026 Edition
blogs_krebs·2026-02-10·CVSS 7.8
CVE-2026-21510 [HIGH] Patch Tuesday, February 2026 Edition
Microsoft today released updates to fix more than 50 security holes in its Windows operating systems and other software, including patches for a whopping six “zero-day” vulnerabilities that attackers are already exploiting in the wild.
Zero-day #1 this month is CVE-2026-21510 , a security feature bypass vulnerability in Windows Shell wherein a single click on a malicious link can quietly bypass Windows protections and run attacker-controlled content without warning or consent dialogs. CVE-2026-21510 affects all currently supported versions of Windows.
The zero-day flaw CVE-2026-21513 is a security bypass bug targeting MSHTML , the proprietary engine of the default Web browser in Windows. CVE-2026-21514 is a related security feature bypass in Microsoft Word.
The zero-day CVE-2026-21533 a
Tenable
February 2026 Microsoft Patch Tuesday | Tenable®
blogs_tenable·2026-02-10
February 2026 Microsoft Patch Tuesday | Tenable®
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday for February 2026 — Snort rules and prominent vulnerabilities
blogs_talos·2026-02-10·CVSS 8.8
CVE-2026-21522 [HIGH] Microsoft Patch Tuesday for February 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for February 2026, which includes 59 vulnerabilities affecting a range of products, including two that Microsoft marked as “Critical”.
CVE-2026-21522 is a critical elevation of privilege vulnerability affecting Microsoft ACI Confidential Containers. Successful exploitation of this vulnerability could enable an authorized attacker to escalate privileges on affected systems. This vulnerability is not listed as publicly disclosed and received a CVSS 3.1 score of 6.7.
CVE-2026-23655 is a critical information disclosure vulnerability affecting Microsoft ACI Confidential Containers. This vulnerability could enable an authorized attacker to disclose sensitive information including secret tokens and keys if successfully exploited. This vulnerabi
Tenable
Security, Here's When You Should Call Legal
blogs_tenable·2019-12-18
Security, Here's When You Should Call Legal
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Security, Here's When You Should Call Legal
blogs_tenable·2019-12-18
Security, Here's When You Should Call Legal
Blog / News and Views
Subscribe
# Security, Here's When You Should Call Legal
Claire McKenna
December 18, 2019
6 Min Read
Did you know litigation can emerge over vulnerabilities – before a security breach occurs? That’s why it’s essential for security to work with legal when a vulnerability is discovered.
So far, I’ve explored the legal aspects of cybersecurity as they relate to vulnerability management. See previous posts in this series:
- Why Security and Legal Need to Work Together
- 5 Questions to Ask Legal About Vulnerability Disclosure
For the third and final part of the series, I’ll discuss recent litigation that has emerged over vulnerabilities – even before a security breach occurred.
Let’s look at recent legal trends, which can inform your vulnerability management plans.
Tenable
Management Interfaces in Three Models of Cisco Networking Devices Are Vulnerable to RCE Attacks
blogs_tenable·2019-02-27·CVSS 9.8
CVE-2019-1663 [CRITICAL] Management Interfaces in Three Models of Cisco Networking Devices Are Vulnerable to RCE Attacks
Blog / Cyber Exposure Alerts
Subscribe
# Management Interfaces in Three Models of Cisco Networking Devices Are Vulnerable to RCE Attacks
Ryan Seguin
February 27, 2019
2 Min Read
New vulnerability (CVE-2019-1663) in Cisco RV110W, RV130W, and RV215W devices allows for RCE attacks from malicious HTTP requests.
### Background
Cisco has released a security advisory for CVE-2019-1663, a remote code execution (RCE) vulnerability present in the remote management interface on certain router and firewall devices, the RV110W, RV130W, and RV215W. The vulnerability could allow an unauthenticated, remote attacker to execute arbitrary code through malicious HTTP requests. Cisco has released firmware updates for the affected devices that address this vulnerability.
### Analysis
Cisco has not rele
Tenable
Tenable Research Discovers Remote Code Execution Vulnerabilities in GPON Routers
blogs_tenable·2019-02-27·CVSS 7.5
[HIGH] Tenable Research Discovers Remote Code Execution Vulnerabilities in GPON Routers
Blog / Research
Subscribe
# Tenable Research Discovers Remote Code Execution Vulnerabilities in GPON Routers
Tenable Research
February 27, 2019
2 Min Read
Tenable Research has discovered six new vulnerabilities in Nokia (Alcatel-Lucent) I-240W-Q GPON routers that can provide attacker with telnet access, DoS the target, or run arbitrary code.
### Background
Nokia (Alcatel-Lucent) I-240W-Q Gigabit Passive Optical Network (GPON) routers are designed to replace standard copper networks. These routers have become an attractive target for botnets, and turnaround from disclosure to attack is almost immediate.
Tenable researcher Artem Metla has discovered six new vulnerabilities in Nokia (Alcatel-Lucent) I-240W-Q GPON routers (CVE-2019-3917, CVE-2019-3918, CVE-2019-3919, CVE-2019-3920, CVE
Tenable
Management Interfaces in Three Models of Cisco Networking Devices Are Vulnerable to RCE Attacks
blogs_tenable·2019-02-27
Management Interfaces in Three Models of Cisco Networking Devices Are Vulnerable to RCE Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Research Discovers Remote Code Execution Vulnerabilities in GPON Routers
blogs_tenable·2019-02-27
Tenable Research Discovers Remote Code Execution Vulnerabilities in GPON Routers
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
WinRAR Absolute Path Traversal Vulnerability Leads to Remote Code Execution (CVE-2018-20250)
blogs_tenable·2019-02-25·CVSS 7.8
[HIGH] WinRAR Absolute Path Traversal Vulnerability Leads to Remote Code Execution (CVE-2018-20250)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
WinRAR Absolute Path Traversal Vulnerability Leads to Remote Code Execution (CVE-2018-20250)
blogs_tenable·2019-02-25·CVSS 7.8
CVE-2018-20250 [HIGH] WinRAR Absolute Path Traversal Vulnerability Leads to Remote Code Execution (CVE-2018-20250)
Blog / Cyber Exposure Alerts
Subscribe
# WinRAR Absolute Path Traversal Vulnerability Leads to Remote Code Execution (CVE-2018-20250)
Satnam Narang
February 25, 2019
2 Min Read
A 19-year-old vulnerability in WinRAR’s ACE file format support (CVE-2018-20250) has been identified as part of an attack in the wild.
### Background
On February 20, researchers at Check Point Research (CPR) published a blog detailing their discovery of multiple vulnerabilities within a library used by WinRAR, a popular file compression tool, to extract ACE archives. When exploited, these vulnerabilities can lead to remote code execution. An exploit script was published to Github one day after CPR’s blog post. The 360 Threat Intelligence Center (TIC) has reportedly identified an in-the-wild sample that attemp
Tenable
Highly Critical Drupal Security Advisory Released (SA-CORE-2019-003)
blogs_tenable·2019-02-20·CVSS 8.1
CVE-2019-6340 [HIGH] Highly Critical Drupal Security Advisory Released (SA-CORE-2019-003)
Blog / Cyber Exposure Alerts
Subscribe
# Highly Critical Drupal Security Advisory Released (SA-CORE-2019-003)
Satnam Narang
February 20, 2019
3 Min Read
Drupal has released a security advisory to address a critical remote code execution vulnerability (CVE-2019-6340).
### Background
On February 20, Drupal released a security advisory (SA-CORE-2019-003) for CVE-2019-6340, a remote code execution vulnerability in its software. This vulnerability has received a security risk rating of Highly Critical as defined by Drupal.
### Analysis
According to the security advisory, arbitrary PHP code execution is possible due to a lack of data sanitization in certain field types linked to non-form sources. However, specific site configurations are affected by this vulnerability.
Affected Configu
Tenable
Highly Critical Drupal Security Advisory Released (SA-CORE-2019-003)
blogs_tenable·2019-02-20
Highly Critical Drupal Security Advisory Released (SA-CORE-2019-003)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
CVE-2019-5736 Exploits the Common runc Container Binary to Escape to Host
blogs_tenable·2019-02-13·CVSS 8.6
CVE-2019-5736 [HIGH] CVE-2019-5736 Exploits the Common runc Container Binary to Escape to Host
Blog / Cyber Exposure Alerts
Subscribe
# CVE-2019-5736 Exploits the Common runc Container Binary to Escape to Host
Ryan Seguin
February 13, 2019
2 Min Read
CVE-2019-5736 allows for an escape to host attack in specific container configurations.
### Background
A new vulnerability (CVE-2019-5736) was recently announced in runc, the runtime used by popular container platforms Docker and Kubernetes. The disclosure for this vulnerability details how a malicious container can escape its sandbox and execute arbitrary commands on the host. This attack does, however, come with some caveats, and isn’t exploitable in certain configurations that follow good security practices.
### Analysis
In order to properly exploit this vulnerability, a malicious or compromised container would need to be de
Tenable
CVE-2019-5736 Exploits the Common runc Container Binary to Escape to Host
blogs_tenable·2019-02-13·CVSS 8.6
[HIGH] CVE-2019-5736 Exploits the Common runc Container Binary to Escape to Host
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
ThinkPHP Remote Code Execution Vulnerability Used To Deploy Variety of Malware (CVE-2018-20062)
blogs_tenable·2019-02-07·CVSS 9.8
[CRITICAL] ThinkPHP Remote Code Execution Vulnerability Used To Deploy Variety of Malware (CVE-2018-20062)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
ThinkPHP Remote Code Execution Vulnerability Used To Deploy Variety of Malware (CVE-2018-20062)
blogs_tenable·2019-02-07·CVSS 9.8
CVE-2018-20062 [CRITICAL] ThinkPHP Remote Code Execution Vulnerability Used To Deploy Variety of Malware (CVE-2018-20062)
Blog / Cyber Exposure Alerts
Subscribe
# ThinkPHP Remote Code Execution Vulnerability Used To Deploy Variety of Malware (CVE-2018-20062)
Satnam Narang
February 7, 2019
2 Min Read
A remote code execution bug in the Chinese open source framework ThinkPHP is being actively used by threat actors to implant a variety of malware, primarily targeting Internet of Things (IoT) devices.
### Background
Over the last few months, attackers have been leveraging CVE-2018-20062, a remote code execution (RCE) vulnerability in Chinese open source PHP framework ThinkPHP, to implant a variety of malware. While the vulnerability was patched on December 9, 2018, a proof of concept (PoC) was published to ExploitDB on December 11.
### Analysis
Shortly after the publication of the PoC, researchers observe
Tenable
Remote Code Execution in InduSoft Web Studio
blogs_tenable·2019-02-06
Remote Code Execution in InduSoft Web Studio
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Remote Code Execution in InduSoft Web Studio
blogs_tenable·2019-02-06·CVSS 9.8
CVE-2019-6545 [CRITICAL] Remote Code Execution in InduSoft Web Studio
Blog / Research
Subscribe
# Remote Code Execution in InduSoft Web Studio
Tenable Research
February 6, 2019
2 Min Read
Enterprises running InduSoft Web Studio should update their software and ensure these critical systems are not exposed to the internet.
Tenable Research has discovered an unauthenticated remote code execution (RCE) vulnerability in InduSoft Web Studio 8.1.2.0. ICS-CERT has assigned CVE-2019-6545 and CVE-2019-6543 for this vulnerability.
### Background
InduSoft Web Studio is an automation tool for human-machine interface (HMI) and supervisory control and data acquisition (SCADA) systems. According to its website, Web Studio is used in manufacturing, oil and gas, municipal water and correctional facilities and even by a drag racer.
By exploiting this vulnerability, a
Tenable
LibreOffice Vulnerable to Code Execution in URL Mouseover Preview Feature
blogs_tenable·2019-02-01
LibreOffice Vulnerable to Code Execution in URL Mouseover Preview Feature
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
LibreOffice Vulnerable to Code Execution in URL Mouseover Preview Feature
blogs_tenable·2019-02-01·CVSS 7.8
CVE-2018-16858 [HIGH] LibreOffice Vulnerable to Code Execution in URL Mouseover Preview Feature
Blog / Cyber Exposure Alerts
Subscribe
# LibreOffice Vulnerable to Code Execution in URL Mouseover Preview Feature
Ryan Seguin
February 1, 2019
2 Min Read
Researcher Alex Inführ discovered that LibreOffice 6.1.0-6.1.3.1 is susceptible to a code injection attack if a user hovers their mouse over a malicious URL.
### Background
Researcher Alex Inführ disclosed a LibreOffice vulnerability (CVE-2018-16858) in versions 6.1.0-6.1.3.1 which shows that code injection is possible on both Linux and Windows versions when a user hovers their mouse over a malicious URL.
Update: Tenable Research was able to confirm that this vulnerability is also exploitable on macOS by editing the Proof of Concept (PoC) code.
### Analysis
While this vulnerability does require user interaction, an OpenDocument
Tenable
Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
blogs_tenable·2019-01-25·CVSS 7.2
[HIGH] Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
Blog / Cyber Exposure Alerts
Subscribe
# Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
Satnam Narang
January 25, 2019
3 Min Read
Availability of public exploit scripts for two vulnerabilities in Cisco Small Business WAN VPN routers coupled with incoming scans for vulnerable devices indicate that attackers are preparing to launch attacks.
### Background
On January 23, Cisco published a list of security advisories including advisories for two vulnerabilities in Cisco Small Business RV320 and RV325 dual gigabit WAN VPN routers. Both vulnerabilities exist within the routers’ web-based management interface. The first is CVE-2019-1652, a command injection vulnerability that exists in firmware versions 1.4.2.15 through 1.4.2.19. The second
Tenable
Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
blogs_tenable·2019-01-25
Public Exploit Scripts for Vulnerable Cisco Small Business RV320 and RV325 Devices Now Available
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Multiple Vulnerabilities Found in LabKey Server Community Edition
blogs_tenable·2019-01-24·CVSS 6.1
[MEDIUM] Multiple Vulnerabilities Found in LabKey Server Community Edition
Blog / Research
Subscribe
# Multiple Vulnerabilities Found in LabKey Server Community Edition
Tenable Research
January 24, 2019
2 Min Read
Tenable Research has discovered multiple vulnerabilities including cross site scripting, open redirects and drive mapping in LabKey Server Community Edition 18.2-60106.64. Labkey has released patches.
### Background
LabKey Server, an open source medical data collaboration tool, is vulnerable to multiple cross site scripting (XSS) attacks. The flaws allow a remote unauthenticated attacker to run arbitrary code through their browser, create open redirects to push users to malicious URLs, and map malicious network drives after gaining administrative access.
### Analysis
#### CVE-2019-3911: Cross Site Scripting vulnerabilities
Query functions are
Tenable
Multiple Vulnerabilities Found in LabKey Server Community Edition
blogs_tenable·2019-01-24
Multiple Vulnerabilities Found in LabKey Server Community Edition
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Proof-of-Concept Code Gives Standard Microsoft Exchange Users Domain Administrator Privileges (CVE-2019-0724, CVE-2019-0686)
blogs_tenable·2019-01-22·CVSS 7.4
CVE-2019-0724 [HIGH] Proof-of-Concept Code Gives Standard Microsoft Exchange Users Domain Administrator Privileges (CVE-2019-0724, CVE-2019-0686)
Blog / Cyber Exposure Alerts
Subscribe
# Proof-of-Concept Code Gives Standard Microsoft Exchange Users Domain Administrator Privileges (CVE-2019-0724, CVE-2019-0686)
Paul Davis
January 22, 2019
4 Min Read
Publicly released and newly named “PrivExchange” proof-of-concept (POC) privilege escalation code exploits protocol flaws and default configurations to give standard Exchange users Domain Administrator access.
### Background
Update February 12: Microsoft released updates for CVE-2019-0724 and CVE-2019-0686 to address this vulnerability.
Update February 6: Microsoft published a security advisory (ADV190007) that includes a Throttling Policy that will mitigate this vulnerability until a software update. Additionally, they noted that the vulnerability described in the blog post below
Tenable
Proof-of-Concept Code Gives Standard Microsoft Exchange Users Domain Administrator Privileges (CVE-2019-0724, CVE-2019-0686)
blogs_tenable·2019-01-22·CVSS 7.4
[HIGH] Proof-of-Concept Code Gives Standard Microsoft Exchange Users Domain Administrator Privileges (CVE-2019-0724, CVE-2019-0686)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Data Security Is a Global Economic Imperative
blogs_tenable·2019-01-16
Data Security Is a Global Economic Imperative
Blog / News and Views
Subscribe
# Data Security Is a Global Economic Imperative
Renaud Deraison
January 16, 2019
6 Min Read
It’s time for government and industry to define and follow a cybersecurity-first approach to protecting the precious data driving global commerce.
Data makes the world go round. It’s the grease keeping the machinery of modern global commerce moving quickly and efficiently. Without it, global supply chains would grind to a halt, stock markets would cease trading, and the simplest of consumer transactions would become untenable.
According to a 2017 McKinsey study, the volume of data flows, measured in terabits per second, has multiplied by a factor of 45 since 2005, to reach an estimated 400 terabits per second by the end of 2016. The McKinsey researchers find “t
Tenable
Data Security Is a Global Economic Imperative
blogs_tenable·2019-01-16
Data Security Is a Global Economic Imperative
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cyber Risk Management in Transition: Key Findings from ESG’s Cyber Risk Management Survey
blogs_tenable·2019-01-16
Cyber Risk Management in Transition: Key Findings from ESG’s Cyber Risk Management Survey
Blog / News and Views
Subscribe
# Cyber Risk Management in Transition: Key Findings from ESG’s Cyber Risk Management Survey
Kevin Flynn
January 16, 2019
3 Min Read
A recent ESG report shows the traditional approach to cyber risk management isn’t working anymore, if in fact it ever did. Here, we share four highlights from the report and offer two steps to help improve your organization’s strategy.
To gain insight into how cyber risk management is changing to support organizational missions and initiatives, the Enterprise Strategy Group (ESG) surveyed 340 information security professionals in organizations with over 1,000 employees.
The results show the traditional approach to cyber risk management isn’t working anymore, if in fact it ever did. The vast majority of respondents (72%) s
Tenable
Cyber Risk Management in Transition: Key Findings from ESG’s Cyber Risk Management Survey
blogs_tenable·2019-01-16
Cyber Risk Management in Transition: Key Findings from ESG’s Cyber Risk Management Survey
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
blogs_tenable·2019-01-15
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
blogs_tenable·2019-01-15·CVSS 9.8
[CRITICAL] Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
Blog / Cyber Exposure Alerts
Subscribe
# Oracle’s January Critical Patch Update Addresses Nearly 300 Fixes
Satnam Narang
January 15, 2019
2 Min Read
Oracle addresses nearly 300 vulnerabilities in the first Critical Patch Update of 2019.
## Background
On January 15, Oracle released its Critical Patch Update, a quarterly publication of fixes for vulnerabilities. This month’s update contains nearly 300 fixes across a number of Oracle products.
## Analysis
The Critical Patch Update for January 2019 addresses a variety of vulnerabilities. For instance, Oracle published 30 fixes for MySQL, including a fix for MySQL Workbench to address the libssh vulnerability (CVE-2018-10933). There are also several fixes for CVE-2017-5645, a deserialization vulnerability in Apache Log4j, as well as CV
Tenable
Multiple Zero-Days in PremiSys IDenticard Access Control System
blogs_tenable·2019-01-14
Multiple Zero-Days in PremiSys IDenticard Access Control System
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Multiple Zero-Days in PremiSys IDenticard Access Control System
blogs_tenable·2019-01-14·CVSS 8.8
[HIGH] Multiple Zero-Days in PremiSys IDenticard Access Control System
Blog / Research
Subscribe
# Multiple Zero-Days in PremiSys IDenticard Access Control System
Tenable Research
January 14, 2019
3 Min Read
Tenable Research discovered multiple zero-day vulnerabilities in the PremiSys access control system developed by IDenticard. As of January 9, IDenticard has not released a patch for these vulnerabilities.
### Background
Tenable Research has discovered four vulnerabilities in the PremiSys access control system from IDenticard. The PremiSys system can be used to manage door controls and access cards, collect detailed facility data and integrate with video monitoring systems.
According to Tenable’s disclosure timeline, multiple attempts were made to contact the vendor to address these vulnerabilities. The Computer Emergency Response Team (CERT) was n
Tenable
Adobe Releases Out-of-Band Security Bulletin for Adobe Acrobat and Reader (APSB19-02)
blogs_tenable·2019-01-04·CVSS 8.8
CVE-2018-16011 [HIGH] Adobe Releases Out-of-Band Security Bulletin for Adobe Acrobat and Reader (APSB19-02)
Blog / Cyber Exposure Alerts
Subscribe
# Adobe Releases Out-of-Band Security Bulletin for Adobe Acrobat and Reader (APSB19-02)
Satnam Narang
January 4, 2019
2 Min Read
Adobe issued an out-of-band security bulletin which addresses two critical vulnerabilities (CVE-2018-16011, CVE-2018-16018) in Adobe Acrobat and Reader.
## Background
On January 3, Adobe released a security bulletin to address two critical vulnerabilities in Adobe Acrobat and Reader for both Windows and macOS. Adobe published a prenotification for this bulletin on December 27 to give users advance warning.
## Vulnerability details
The security bulletin addresses two critical vulnerabilities. The first, CVE-2018-16011, is a use after free vulnerability that could lead to arbitrary code execution. CVE-2018-16018 is a
Tenable
Adobe Releases Out-of-Band Security Bulletin for Adobe Acrobat and Reader (APSB19-02)
blogs_tenable·2019-01-04
Adobe Releases Out-of-Band Security Bulletin for Adobe Acrobat and Reader (APSB19-02)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft Releases Out-of-Band Patch for Internet Explorer Remote Code Execution Vulnerability (CVE-2018-8653)
blogs_tenable·2018-12-19·CVSS 7.5
[HIGH] Microsoft Releases Out-of-Band Patch for Internet Explorer Remote Code Execution Vulnerability (CVE-2018-8653)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
blogs_tenable·2018-12-19
Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
blogs_tenable·2018-12-19·CVSS 8.1
[HIGH] Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
Blog / Research
Subscribe
# Privilege Escalation Flaw Discovered in the Cisco Adaptive Security Appliance
Ryan Seguin
December 19, 2018
3 Min Read
Tenable has discovered a privilege escalation flaw in the Cisco Adaptive Security Appliance that allows low-level users to run higher-level commands when certain configuration settings are set.
- What you need to know: An authenticated remote unprivileged user can change or download the running configuration or replace the appliance firmware where they shouldn’t.
- What’s the attack vector? HTTP Requests
- What’s the business impact? Attackers could read or write files on the system, overwrite firmware and create new users.
- What’s the solution? Update to the latest version of Cisco IOS.
### Background
Tenable has discovered privilege e
Tenable
Microsoft Releases Out-of-Band Patch for Internet Explorer Remote Code Execution Vulnerability (CVE-2018-8653)
blogs_tenable·2018-12-19·CVSS 7.5
CVE-2018-8653 [HIGH] Microsoft Releases Out-of-Band Patch for Internet Explorer Remote Code Execution Vulnerability (CVE-2018-8653)
Blog / Cyber Exposure Alerts
Subscribe
# Microsoft Releases Out-of-Band Patch for Internet Explorer Remote Code Execution Vulnerability (CVE-2018-8653)
Ryan Seguin
December 19, 2018
1 Min Read
Clement Lecigne of Google’s Threat Analysis Group has reported exploitation of an Internet Explorer vulnerability, CVE-2018-8653, prompting an out-of-band patch from Microsoft.
## Background
On December 19, Microsoft released a critical out-of-band (OOB) patch for a remote code execution (RCE) vulnerability in Internet Explorer (IE). This vulnerability affects all versions of IE including Windows 7, Windows 8.1, Windows 10, Windows Server 2008 (Internet Explorer 9), Windows Server 2012 (Internet Explorer 10), Windows Server 2016 and Windows Server 2019.
## Vulnerability details
A remote code
Tenable
Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
blogs_tenable·2018-12-13·CVSS 8.1
CVE-2014-3120 [HIGH] Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
Blog / Cyber Exposure Alerts
Subscribe
# Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
Satnam Narang
December 13, 2018
2 Min Read
Attackers are actively scanning for vulnerable Elasticsearch systems in order to implant cryptocurrency mining scripts.
### Background
In recent weeks, attackers have been observed scanning for vulnerabilities in Elasticsearch, a distributed, RESTful search and analytics engine. According to research from Trend Micro, the attackers are targeting unpatched Elasticsearch systems using vulnerabilities from 2014 and 2015 to break into systems in order to implant cryptocurrency mining (also known as “coinminer”) scripts. These scripts are designed to hijack a system’s computing resources in a race to s
Tenable
Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
blogs_tenable·2018-12-13·CVSS 8.1
[HIGH] Patched Elasticsearch Vulnerabilities Used to Spread Cryptocurrency Miner (CVE-2014-3120, CVE-2015-1427)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Securing Medical Records: Exploring US Certification Standards
blogs_tenable·2018-12-12
Securing Medical Records: Exploring US Certification Standards
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Securing Medical Records: Exploring US Certification Standards
blogs_tenable·2018-12-12
Securing Medical Records: Exploring US Certification Standards
Blog / Research
Subscribe
# Securing Medical Records: Exploring US Certification Standards
Jimi Sebree
December 12, 2018
8 Min Read
Tenable Research investigates compliance standards for EHR applications in the US healthcare industry and discusses possible gaps in the coverage of these standards. Real world examples are provided to demonstrate potential security impact.
Politics and legislation aside, it’s no secret that the US healthcare industry is a mess. Hospital networks and small-time medical practices alike are known to run outdated and vulnerable software. Compounded by the fact that vendors are jumping on the “smart-things” bandwagon like groupies to a Dave Matthews Band show, the world of healthcare technology is a scary place. From pacemaker malware to compromised insulin
Tenable
Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
blogs_tenable·2018-12-05·CVSS 7.8
[HIGH] Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
blogs_tenable·2018-12-05·CVSS 7.8
CVE-2018-15982 [HIGH] Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
Blog / Cyber Exposure Alerts
Subscribe
# Adobe Flash Vulnerability Can Lead to Code Execution and Asset Takeover (CVE-2018-15982)
Ryan Seguin
December 5, 2018
2 Min Read
Adobe has issued an out-of-band advisory for CVE-2018-15982. Through the use of a maliciously crafted RAR file, an attacker exploiting this vulnerability can take over the machine of users that run it.
## Background
Adobe has released an out-of-band security bulletin. that includes patches for CVE-2018-15982, a critical arbitrary code execution vulnerability in Adobe Flash which has been used to allegedly attack Polyclinic No. 2, which is affiliated with the Presidential Administration of Russia. Users are encouraged to update all applications that incorporate Flash.
## Analysis
The attack requires a user to open
Tenable
Tenable Research Advisory: Multiple ICS Vulnerabilities in Schneider Modicon Quantum PLC
blogs_tenable·2018-11-27
Tenable Research Advisory: Multiple ICS Vulnerabilities in Schneider Modicon Quantum PLC
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Research Advisory: Multiple ICS Vulnerabilities in Schneider Modicon Quantum PLC
blogs_tenable·2018-11-27·CVSS 9.8
[CRITICAL] Tenable Research Advisory: Multiple ICS Vulnerabilities in Schneider Modicon Quantum PLC
Blog / Research
Subscribe
# Tenable Research Advisory: Multiple ICS Vulnerabilities in Schneider Modicon Quantum PLC
Tenable Research
November 27, 2018
4 Min Read
Tenable Research discovered multiple vulnerabilities in Schneider’s Modicon Quantum programmable logic controller. Schneider has recommended mitigations for impacted end users.
### Background
While examining a Schneider Modicon Quantum programmable logic controller (PLC) Tenable Research discovered several vulnerabilities.
The Modicon Quantum is used for complex process control, safety and infrastructure in industrial settings like manufacturing. Industrial control systems typically include a computer called a programmable logic controller (PLC). PLCs connect directly to instruments, for example valve and pump actuators a
Tenable
Adobe Issues Out-of-Band Patch for Critical Flash Player Vulnerability (CVE-2018-15981)
blogs_tenable·2018-11-21·CVSS 9.8
[CRITICAL] Adobe Issues Out-of-Band Patch for Critical Flash Player Vulnerability (CVE-2018-15981)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Adobe Issues Out-of-Band Patch for Critical Flash Player Vulnerability (CVE-2018-15981)
blogs_tenable·2018-11-21·CVSS 9.8
CVE-2018-15981 [CRITICAL] Adobe Issues Out-of-Band Patch for Critical Flash Player Vulnerability (CVE-2018-15981)
Blog / Cyber Exposure Alerts
Subscribe
# Adobe Issues Out-of-Band Patch for Critical Flash Player Vulnerability (CVE-2018-15981)
Satnam Narang
November 21, 2018
2 Min Read
Adobe has released an out-of-band patch for a critical Flash Player vulnerability. Users are encouraged to upgrade as soon as possible.
### Background
On November 20, Adobe released APSB18-44, an out-of-band (OOB) security bulletin to address a zero day vulnerability in Adobe Flash Player versions 31.0.0.148 and earlier for Windows, macOS, Linux and Chrome OS.
This bulletin arrived seven days after Adobe released APSB18-39, it’s monthly security bulletin for November 2018. On the very same day, November 13, researcher Gil Dabah published a blog discussing his discovery of CVE-2018-15981.
It may not seem like a c
Tenable
Popular WordPress ‘AMP for WP’ Plugin Vulnerable to Privilege Escalation Attacks
blogs_tenable·2018-11-15
Popular WordPress ‘AMP for WP’ Plugin Vulnerable to Privilege Escalation Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15·CVSS 5.6
[MEDIUM] 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Blog / Research
Subscribe
# 5W1H: Speculative Side Channel Vulnerabilities De-mystified
Pablo Ramos
November 15, 2018
5 Min Read
The classes of vulnerabilities that brought us Meltdown and Spectre are not going away anytime soon. Here’s what you need to know about Speculative Execution vulnerabilities, with our guidance on steps you can take to reduce your risk.
Spectre and Meltdown generated a lot of confusion and discussion in the security world when they first hit the news. Understanding the risks associated with speculative execution vulnerabilities will help organizations prioritize and communicate effectively about their exposure. In this post, we present what it is known, how it affects companies and ways to stay ahead in the game.
## Start from the beginning…
Speculative Ex
Tenable
5W1H: Speculative Side Channel Vulnerabilities De-mystified
blogs_tenable·2018-11-15
5W1H: Speculative Side Channel Vulnerabilities De-mystified
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Popular WordPress ‘AMP for WP’ Plugin Vulnerable to Privilege Escalation Attacks
blogs_tenable·2018-11-15
Popular WordPress ‘AMP for WP’ Plugin Vulnerable to Privilege Escalation Attacks
Blog / Cyber Exposure Alerts
Subscribe
# Popular WordPress ‘AMP for WP’ Plugin Vulnerable to Privilege Escalation Attacks
Ryan Seguin
November 15, 2018
2 Min Read
The ‘AMP for WP – Accelerated Mobile Pages’ plugin for WordPress is vulnerable to a privilege escalation attack. Updating the plugin to version ‘0.9.97.20’ fixes the flaw.
Updated November 19: The original posting of this blog credited WebARX security with the discovery of the vulnerability. This was incorrect as this initial discovery was made by plugin developer Sybre Waaijer. The text below has been corrected, and the reference links now include the wpvulndb page.
#### Background
Following the discovery of a critical vulnerability in the WP GDPR Compliance Plugin, another critical WordPress plugin vulnerability was dis
Tenable
Adobe Patches Incomplete Fix for NTLM Credential Leaking Bug (CVE-2018-15979)
blogs_tenable·2018-11-14·CVSS 7.5
CVE-2018-15979 [HIGH] Adobe Patches Incomplete Fix for NTLM Credential Leaking Bug (CVE-2018-15979)
Blog / Cyber Exposure Alerts
Subscribe
# Adobe Patches Incomplete Fix for NTLM Credential Leaking Bug (CVE-2018-15979)
Satnam Narang
November 14, 2018
2 Min Read
Researchers have reported an incomplete fix for CVE-2018-4993, an NTLM credential leaking vulnerability that was supposed to be patched in May 2018. Adobe has now released a complete fix.
### Background
On November 13, Adobe published its monthly security bulletins as part of its monthly release cycle in conjunction with Microsoft’s Patch Tuesday. The November security bulletins include a fix for a vulnerability that was believed to have been patched in May 2018’s security bulletins. However, security researchers at EdgeSpot discovered that the May 2018 fix was incomplete.
### Vulnerability details
Researchers at Check Po
Tenable
Adobe Patches Incomplete Fix for NTLM Credential Leaking Bug (CVE-2018-15979)
blogs_tenable·2018-11-14·CVSS 7.5
[HIGH] Adobe Patches Incomplete Fix for NTLM Credential Leaking Bug (CVE-2018-15979)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
blogs_tenable·2018-11-12·CVSS 8.8
[HIGH] VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
New WordPress Privilege Escalation Flaw In WP GDPR Compliance Plugin
blogs_tenable·2018-11-12
New WordPress Privilege Escalation Flaw In WP GDPR Compliance Plugin
Blog / Cyber Exposure Alerts
Subscribe
# New WordPress Privilege Escalation Flaw In WP GDPR Compliance Plugin
Ryan Seguin
November 12, 2018
2 Min Read
A privilege escalation flaw in WordPress’ popular WP GDPR Compliance plugin has led to exploitation of numerous WordPress sites. Site owners and administrators are encouraged to upgrade to the latest version of the affected plugin.
#### Background
WordPress plugin "WP GDPR Compliance" versions before 1.4.3 are vulnerable to a privilege escalation attack. The attack doesn’t require authentication, and Sucuri.net reports that attackers have already exploited a number of sites. Exploited sites had their siteurls changed to "hxxp://erealitatea[.]net".
#### Impact assessment
As of Noon ET on November 12, a curated Google search shows app
Tenable
New WordPress Privilege Escalation Flaw In WP GDPR Compliance Plugin
blogs_tenable·2018-11-12
New WordPress Privilege Escalation Flaw In WP GDPR Compliance Plugin
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
blogs_tenable·2018-11-12·CVSS 8.8
CVE-2018-6981 [HIGH] VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
Blog / Cyber Exposure Alerts
Subscribe
# VMware Issues Security Advisory for Guest-to-Host Escape Vulnerability (CVE-2018-6981)
Satnam Narang
November 12, 2018
2 Min Read
VMware issued an advisory about two uninitialized stack memory usage bugs and has released patches and updates for some versions of the affected software.
## Background
On November 9, VMware published a security advisory to address a Guest-to-Host Escape vulnerability affecting VMware ESXi, Workstation and Fusion. The vulnerability was discovered and released by a security researcher at GeekPwn 2018, an annual security conference in Shanghai, China which took place in late October 2018. The researcher reported the vulnerability to VMware through GeekPwn.
Source: @ChaitinTech on Twitter.
## Vulnerability details
Tenable
APT Malware Activity Detected Exploiting a Patched ColdFusion Vulnerability (CVE-2018-15961)
blogs_tenable·2018-11-08·CVSS 9.8
[CRITICAL] APT Malware Activity Detected Exploiting a Patched ColdFusion Vulnerability (CVE-2018-15961)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
APT Malware Activity Detected Exploiting a Patched ColdFusion Vulnerability (CVE-2018-15961)
blogs_tenable·2018-11-08·CVSS 9.8
CVE-2018-15961 [CRITICAL] APT Malware Activity Detected Exploiting a Patched ColdFusion Vulnerability (CVE-2018-15961)
Blog / Cyber Exposure Alerts
Subscribe
# APT Malware Activity Detected Exploiting a Patched ColdFusion Vulnerability (CVE-2018-15961)
Ryan Seguin
November 8, 2018
2 Min Read
Researchers at Volexity have identified multiple groups exploiting CVE-2018-15961 in unpatched, web-facing Adobe ColdFusion servers. Users are urged to upgrade to the latest version of ColdFusion.
## Background
On November 8, Volexity reported Advanced Persistent Threat (APT) and hacktivist groups have been targeting web-facing instances of Adobe ColdFusion that haven’t patched for CVE-2018-15961. Adobe released APSB18-33 to address the vulnerability on September 11, 2018.
## Impact assessment
The researchers at Volexity identified two separate and unrelated attacks on a number of web-facing ColdFusion servers
Tenable
Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
blogs_tenable·2018-11-05·CVSS 9.8
CVE-2016-1000031 [CRITICAL] Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
Blog / Cyber Exposure Alerts
Subscribe
# Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
Satnam Narang
November 5, 2018
2 Min Read
Apache Software Foundation announces a security update for Apache Struts to address a vulnerability in the Commons FileUpload library that could lead to remote code execution. We recommend updating now.
## Background
On November 5, the Apache Software Foundation (ASF) published a security announcement to Apache Struts project administrators about CVE-2016-1000031, a vulnerability in the Commons FileUpload library originally reported by Tenable’s Research team in 2016. This library ships as part of Apache Struts 2 and is used as the default mechanism for file uploads. The ASF reports that Apache Struts 2.
Tenable
Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
blogs_tenable·2018-11-05·CVSS 9.8
[CRITICAL] Apache Struts Patches Remote Code Execution Vulnerability in FileUpload Library (CVE-2016-1000031)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cisco ASA and Firepower Being Exploited in the Wild - Apply Mitigations ASAP
blogs_tenable·2018-11-01
Cisco ASA and Firepower Being Exploited in the Wild - Apply Mitigations ASAP
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cisco ASA and Firepower Being Exploited in the Wild - Apply Mitigations ASAP
blogs_tenable·2018-11-01
Cisco ASA and Firepower Being Exploited in the Wild - Apply Mitigations ASAP
Blog / Cyber Exposure Alerts
Subscribe
# Cisco ASA and Firepower Being Exploited in the Wild - Apply Mitigations ASAP
Paul Davis
November 1, 2018
3 Min Read
Cisco advised that the Adaptive Security Appliance (ASA) and Firepower systems are being exploited in the wild with a Session Initiation Protocol (SIP) vulnerability. Limited patches are available.
### Background
Cisco posted an advisory on October 31 warning users that their popular Adaptive Security Appliance (ASA) and Firepower Threat Defense Software are vulnerable to a Session Initiation Protocol (SIP) handling bug currently being exploited in the wild. As of November 1 10:00 a.m. (EST), there was no patch or workaround available. Cisco has provided mitigation guidance.
Updated November 9: Cisco has started releasing updat
Tenable
Buffer Overflow Vulnerability in Apple iOS and macOS Devices Disclosed
blogs_tenable·2018-10-31
Buffer Overflow Vulnerability in Apple iOS and macOS Devices Disclosed
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Buffer Overflow Vulnerability in Apple iOS and macOS Devices Disclosed
blogs_tenable·2018-10-31·CVSS 8.8
[HIGH] Buffer Overflow Vulnerability in Apple iOS and macOS Devices Disclosed
Blog / Cyber Exposure Alerts
Subscribe
# Buffer Overflow Vulnerability in Apple iOS and macOS Devices Disclosed
Satnam Narang
October 31, 2018
2 Min Read
A researcher has disclosed a buffer overflow vulnerability in Apple’s XNU operating system kernel that allows attackers on a local network to reboot Apple’s iOS and macOS devices and could potentially lead to remote code execution.
### Background
On October 30, researcher Kevin Backhouse of Semmle published a blog on his discovery of a buffer overflow vulnerability in Apple’s XNU operating system kernel (CVE-2018-4407). Specifically, the vulnerability exists in the networking code for XNU for how packets are handled. The vulnerability affects OS X, macOS and iOS devices. Backhouse released a proof of concept (PoC) video demonstrati
Tenable
DemonBot Malware Targets Apache Hadoop Servers Using Available Exploit Code
blogs_tenable·2018-10-30
DemonBot Malware Targets Apache Hadoop Servers Using Available Exploit Code
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
DemonBot Malware Targets Apache Hadoop Servers Using Available Exploit Code
blogs_tenable·2018-10-30
DemonBot Malware Targets Apache Hadoop Servers Using Available Exploit Code
Blog / Cyber Exposure Alerts
Subscribe
# DemonBot Malware Targets Apache Hadoop Servers Using Available Exploit Code
Satnam Narang
October 30, 2018
2 Min Read
New DemonBot malware uses Apache Hadoop exploit also used by XBash to launch exploitation attempts at a rate of one million a day to facilitate widespread DDoS.
### Background
Researchers at Radware recently blogged about the discovery of a new piece of malware, dubbed DemonBot, used by attackers targeting Apache Hadoop servers. These servers are vulnerable to a Yet Another Resource Negotiator (YARN) exploit that was first reported in 2016. Exploit code has been publicly available since March 2018, and attackers have leveraged it to implant Xbash malware in September 2018.
### Impact assessment
Radware’s Threat Research Cent
Tenable
Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
blogs_tenable·2018-10-26·CVSS 6.6
[MEDIUM] Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
blogs_tenable·2018-10-26·CVSS 6.6
CVE-2018-14665 [MEDIUM] Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
Blog / Cyber Exposure Alerts
Subscribe
# Tweetable Exploit for X.org Server Local Privilege Escalation (CVE-2018-14665) Released
Paul Davis
October 26, 2018
3 Min Read
A researcher has published a local privilege escalation exploit that fits in a single tweet for xorg-x11-server. Vendors are rolling out fixes and mitigation advice.
### Background
On October 25, a tweetable proof-of-concept (PoC) exploit for a newly discovered local privilege escalation (LPE) vulnerability in xorg-x11-server was released.
Not surprisingly, exploitable scripts were quickly available on the web due to the trivial nature of this exploit.
### Impact assessment
This vulnerability allows Linux and Unix hosts running xorg-server in setuid (privileged) mode to have files overwritten via the -logfile and -
Tenable
Microsoft Data Sharing Service Zero-Day Exploit Released on Twitter (CVE-2018-8584)
blogs_tenable·2018-10-24·CVSS 7.8
CVE-2018-8584 [HIGH] Microsoft Data Sharing Service Zero-Day Exploit Released on Twitter (CVE-2018-8584)
Blog / Cyber Exposure Alerts
Subscribe
# Microsoft Data Sharing Service Zero-Day Exploit Released on Twitter (CVE-2018-8584)
Satnam Narang
October 24, 2018
2 Min Read
Researcher discloses privilege escalation zero-day in Microsoft’s Data Sharing Service on Twitter and provides a proof-of-concept that could be used to deploy attacks in the wild.
### Background
On October 23, a privilege escalation zero-day vulnerability in Microsoft’s Data Sharing Service (dssvc.dll), a broker for sharing data between applications, was published to Twitter. The researcher who published this vulnerability also released a zero-day exploit in Microsoft’s Windows Task Scheduler on Twitter in August 2018. As with the Task Scheduler vulnerability disclosed previously, the researcher shared a proof-of-conce
Tenable
Microsoft Data Sharing Service Zero-Day Exploit Released on Twitter (CVE-2018-8584)
blogs_tenable·2018-10-24·CVSS 7.8
[HIGH] Microsoft Data Sharing Service Zero-Day Exploit Released on Twitter (CVE-2018-8584)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
jQuery File Upload Plugin Leaves Web Servers Vulnerable to Unauthenticated File Upload Attacks
blogs_tenable·2018-10-19
jQuery File Upload Plugin Leaves Web Servers Vulnerable to Unauthenticated File Upload Attacks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
jQuery File Upload Plugin Leaves Web Servers Vulnerable to Unauthenticated File Upload Attacks
blogs_tenable·2018-10-19·CVSS 9.8
[CRITICAL] jQuery File Upload Plugin Leaves Web Servers Vulnerable to Unauthenticated File Upload Attacks
Blog / Cyber Exposure Alerts
Subscribe
# jQuery File Upload Plugin Leaves Web Servers Vulnerable to Unauthenticated File Upload Attacks
Ryan Seguin
October 19, 2018
2 Min Read
Akamai disclosed that the popular jQuery File Upload plugin has been vulnerable to an unauthenticated file upload flaw since November 2010.
## Background
Akamai’s Security Intelligence Response Team (SIRT) recently disclosed that the popular jQuery File Upload plugin -- the second most-starred plugin on Github in the jQuery project -- has been vulnerable to an unauthenticated file upload flaw (CVE-2018-9206) on Apache web servers since November 2010.
## Impact assessment
Larry Cashdollar, a security researcher for Akamai's SIRT, said in an interview with ZDNet that he’s seen active exploitation of this vulne
Tenable
libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
blogs_tenable·2018-10-17·CVSS 9.1
CVE-2018-10933 [CRITICAL] libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
Blog / Cyber Exposure Alerts
Subscribe
# libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
Satnam Narang
October 17, 2018
2 Min Read
A newly announced vulnerability in libssh, a multiplatform library that supports the Secure Shell (SSH) protocol, allows attackers to bypass authentication and gain full control over vulnerable servers.
## Background
On October 16, the libssh team published an important security update for a vulnerability in libssh versions 0.6 and above. libssh is a multiplatform library written in C that supports the SSH protocol and can be used to implement client and server applications. The security update addresses CVE-2018-10933, an authentication bypass vulnerability. Tenable confirms our products are not vulnerable to CVE-2018-10933.
## Impact asses
Tenable
libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
blogs_tenable·2018-10-17·CVSS 9.1
[CRITICAL] libssh Vulnerable to Authentication Bypass (CVE-2018-10933)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Process-Led Deployment: How to Maximize Your Cyber Technology Investments
blogs_tenable·2018-10-16
Process-Led Deployment: How to Maximize Your Cyber Technology Investments
Blog / Company
Subscribe
# Process-Led Deployment: How to Maximize Your Cyber Technology Investments
Todd Kisaberth
October 16, 2018
3 Min Read
Taking a process-led approach to your cyber technology deployments is critical to your organization’s ability to reduce risk. Too often, organizations focus on solution features and not on driving the appropriate security outcomes.
When making an investment in a cybersecurity solution, or really any IT solution for that matter, you are looking for just that – a solution to a problem. Too often we get hung up on this feature or that function. The reality is you have a business problem and are looking for a solution to solve said business problem.
Successfully deploying the solution is as critical as selecting the right solution to address you
Tenable
Process-Led Deployment: How to Maximize Your Cyber Technology Investments
blogs_tenable·2018-10-16
Process-Led Deployment: How to Maximize Your Cyber Technology Investments
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Public Exploit Modules Available for Cisco Prime Infrastructure Vulnerability
blogs_tenable·2018-10-12·CVSS 9.8
CVE-2018-15379 [CRITICAL] Public Exploit Modules Available for Cisco Prime Infrastructure Vulnerability
Blog / Cyber Exposure Alerts
Subscribe
# Public Exploit Modules Available for Cisco Prime Infrastructure Vulnerability
Ryan Seguin
October 12, 2018
2 Min Read
Users of Cisco Prime Infrastructure Software are urged to update to the latest version to address one of two vulnerabilities that, when chained, could lead to remote code execution with system-level permissions.
## Background
Cisco released an advisory for CVE-2018-15379, an arbitrary file upload and command execution vulnerability for its Cisco Prime Infrastructure (CPI) software. The CPI management software is designed to allow businesses to manage their network device configurations all in one place, rather than individually by device. CPI also offers integration with Cisco Identity Services Engine (ISE) and location-based
Tenable
Public Exploit Modules Available for Cisco Prime Infrastructure Vulnerability
blogs_tenable·2018-10-12
Public Exploit Modules Available for Cisco Prime Infrastructure Vulnerability
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Research Advisory: Multiple HPE iMC Vulnerabilities Could Lead to Remote Code Execution or Denial of Service
blogs_tenable·2018-10-11
Tenable Research Advisory: Multiple HPE iMC Vulnerabilities Could Lead to Remote Code Execution or Denial of Service
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Research Advisory: Multiple HPE iMC Vulnerabilities Could Lead to Remote Code Execution or Denial of Service
blogs_tenable·2018-10-11
Tenable Research Advisory: Multiple HPE iMC Vulnerabilities Could Lead to Remote Code Execution or Denial of Service
Blog / Research
Subscribe
# Tenable Research Advisory: Multiple HPE iMC Vulnerabilities Could Lead to Remote Code Execution or Denial of Service
Ryan Seguin
October 11, 2018
2 Min Read
Tenable Research discovered multiple vulnerabilities in the HPE Intelligent Management Center. HPE is currently working to fix the issues and plans to release patches on Nov. 30.
- What you need to know: Multiple vulnerabilities were found in HPE iMC, ranging from denial-of-service (DoS) to remote code execution.
- What’s the attack vector? Multiple listening ports related to HPE iMC.
- What’s the business impact? Potential DoS, information disclosure, and asset takeover.
- What’s the solution? There are no patches or workarounds currently. HPE plans to release a patch on or around Nov. 30.
## Backgro
Tenable
MikroTik RouterOS Vulnerabilities: There’s More to CVE-2018-14847
blogs_tenable·2018-10-10·CVSS 9.1
CVE-2018-14847 [CRITICAL] MikroTik RouterOS Vulnerabilities: There’s More to CVE-2018-14847
Blog / Research
Subscribe
# MikroTik RouterOS Vulnerabilities: There’s More to CVE-2018-14847
Tenable Research
October 10, 2018
4 Min Read
In the course of preparing his Derbycon 8.0 presentation on RouterOS vulnerabilities, Tenable Researcher Jacob Baines discovered more to CVE-2018-14847 than originally known. Here’s how it could allow an unauthenticated remote attacker to gain access
to the underlying operating system of MikroTik routers.
While preparing for his Oct. 7 Derbycon 8.0 presentation on RouterOS vulnerabilities, Tenable Researcher Jacob Baines discovered more to
CVE-2018-14847 than originally known, and the new findings elevate the severity of the vulnerability to critical. Baines also found multiple other vulnerabilities unrelated to CVE-2018-14847 in RouterOS, MikroTi
Tenable
MikroTik RouterOS Vulnerabilities: There’s More to CVE-2018-14847
blogs_tenable·2018-10-10·CVSS 9.1
[CRITICAL] MikroTik RouterOS Vulnerabilities: There’s More to CVE-2018-14847
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Research Advisory: Popular TP-Link Router is Vulnerable to Remote Exploitation
blogs_tenable·2018-10-02
Tenable Research Advisory: Popular TP-Link Router is Vulnerable to Remote Exploitation
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Tenable Research Advisory: Popular TP-Link Router is Vulnerable to Remote Exploitation
blogs_tenable·2018-10-02·CVSS 9.8
[CRITICAL] Tenable Research Advisory: Popular TP-Link Router is Vulnerable to Remote Exploitation
Blog / Research
Subscribe
# Tenable Research Advisory: Popular TP-Link Router is Vulnerable to Remote Exploitation
Satnam Narang
October 2, 2018
3 Min Read
Tenable Research has discovered multiple vulnerabilities in the TP-Link TL-WRN841N, a popular consumer router, one of which could be used by an attacker to remotely take over the device.
- What do you need to know? Multiple vulnerabilities in TP-Link's popular TL-WRN841N router were discovered by Tenable Research.
- What’s the attack vector? Targeting unauthenticated users of the TL-WRN841N router’s web server.
- What’s the business impact? An attacker can obtain full control over the router, uploading a new configuration file that will change the admin credentials as well as enable remote access to control the device remotely.
-
Tenable
Tenable Research Advisory: Advantech WebAccess Remote Command Execution Still Exploitable
blogs_tenable·2018-09-10·CVSS 9.8
CVE-2017-16720 [CRITICAL] Tenable Research Advisory: Advantech WebAccess Remote Command Execution Still Exploitable
Blog / Research
Subscribe
# Tenable Research Advisory: Advantech WebAccess Remote Command Execution Still Exploitable
Ryan Seguin
September 10, 2018
2 Min Read
Tenable Researcher Chris Lyne discovered that Advantech WebAccess versions 8.3, 8.3.1 and 8.3.2 are still vulnerable to remote command execution CVE-2017-16720, which was originally disclosed by ZDI in January 2018 and has a public exploit.
## Background
Tenable Research’s Chris Lyne has discovered that Advantech WebAccess remains unprotected against a public exploit several months after a patch was released. Vulnerable WebAccess instances remain susceptible to an unauthenticated remote code execution (RCE) attack (CVE-2017-16720). WebAccess versions 8.3, 8.3.1 and 8.3.2 are affected.
On January 4, 2018, ICS-CERT released IC
Tenable
Tenable Research Advisory: Advantech WebAccess Remote Command Execution Still Exploitable
blogs_tenable·2018-09-10
Tenable Research Advisory: Advantech WebAccess Remote Command Execution Still Exploitable
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Underminer Exploit Kit: How Tenable Can Help
blogs_tenable·2018-07-31
Underminer Exploit Kit: How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
July Vulnerability of the Month: Two Zero-Days Caught in Development
blogs_tenable·2018-07-31·CVSS 8.8
[HIGH] July Vulnerability of the Month: Two Zero-Days Caught in Development
Blog / Research
Subscribe
# July Vulnerability of the Month: Two Zero-Days Caught in Development
Tenable Research
July 31, 2018
3 Min Read
An Adobe Reader double free vulnerability on Windows and macOS systems earns the nod for its interesting discovery and patch story.
Novelty, sophistication or just plain weirdness are some of the potential criteria we use to select the Tenable vulnerability of the month. We collect nominations from our 70+ research team members, shortlist the finalists and give the entire team the chance to vote -- combining the total experience and knowledge of Tenable Research to identify the vulnerability of the month.
## Background
This month, Tenable Research highlights CVE-2018-4990, an Adobe Reader double free vulnerability on Windows and macOS systems. C
Tenable
July Vulnerability of the Month: Two Zero-Days Caught in Development
blogs_tenable·2018-07-31
July Vulnerability of the Month: Two Zero-Days Caught in Development
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Underminer Exploit Kit: How Tenable Can Help
blogs_tenable·2018-07-31
Underminer Exploit Kit: How Tenable Can Help
Blog / Cyber Exposure Alerts
Subscribe
# Underminer Exploit Kit: How Tenable Can Help
Tenable Research
July 31, 2018
2 Min Read
The “Underminer” exploit kit is having widespread impact in Asian countries, particularly Japan. Thankfully, mitigation is relatively simple and involves patching and other well-known security best practices.
Contrary to popular belief, the exploit kit is not dead yet. “Underminer,” an exploit kit named and discovered by Trend Micro, is having widespread impact in Asian countries, particularly Japan. Its nefarious bootkit affects the system’s boot sectors and delivers the coin mining payload named Hidden Mellifera.
While the continued decline of Adobe Flash has led to a reduction in the prevalence of Exploit Kits, enterprises need to remember this attack ve
Tenable
Maintain Your &%$#* Systems! A Mantra for IT Professionals in the Wake of Equifax
blogs_tenable·2017-09-22
Maintain Your &%$#* Systems! A Mantra for IT Professionals in the Wake of Equifax
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Maintain Your &%$#* Systems! A Mantra for IT Professionals in the Wake of Equifax
blogs_tenable·2017-09-22
Maintain Your &%$#* Systems! A Mantra for IT Professionals in the Wake of Equifax
Blog /
Subscribe
# Maintain Your &%$#* Systems! A Mantra for IT Professionals in the Wake of Equifax
Amit Yoran
September 22, 2017
2 Min Read
Once again, we have a basic failure in cyber hygiene causing a massive data breach. This one affects potentially half of the U.S. population and compromises particularly sensitive personal information that can be used by criminals to wreak havoc on people’s bank accounts, credit scores and identities.
I’m referring, of course, to the Equifax breach. What I find particularly disturbing is that criminals took advantage of a known vulnerability for which a patch had been available for two months. Let that sink in for a moment -- two months is an eternity of exposure to hostile internet actors when efficient systems management and compensating cont
Tenable
Cyber Exposure: The Next Frontier for Security
blogs_tenable·2017-07-23
Cyber Exposure: The Next Frontier for Security
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Cyber Exposure: The Next Frontier for Security
blogs_tenable·2017-07-23
Cyber Exposure: The Next Frontier for Security
Blog / Company
Subscribe
# Cyber Exposure: The Next Frontier for Security
Jennifer Johnson
July 23, 2017
6 Min Read
The stakes have never been higher when it comes to cybersecurity. Global cyber attacks such as the recent WannaCry ransomware attack is a sobering reminder that cybersecurity is the existential threat of this generation. A new report from Lloyd’s of London estimates a serious cyber attack could cost the global economy more than $120 billion - as much as catastrophic natural disasters such as Hurricane Katrina and Sandy. According to the report, the most likely scenario is a malicious hack that would take down a cloud service provider at an estimated loss of $53 billion. With all of the attention and the hundreds of vendors in the security industry, why are we still here
Tenable
Web Services Indicator Dashboard
blogs_tenable·2017-04-05
Web Services Indicator Dashboard
Blog / News and Views
Subscribe
# Web Services Indicator Dashboard
Megan Daudelin
April 5, 2017
5 Min Read
The same services we use to connect our networks to the vast resources of the internet can be used against us if not properly secured. Many of the most effective exploits leverage vulnerabilities in common web services, making our jobs more difficult because connectivity is synonymous with exposure. Finding the balance between easy access to resources and securing the network against exploitation is a major challenge that every organization faces, but one that Tenable can help overcome. With the Web Services Indicator dashboard in Tenable.io™, the information you need to earn leadership support to strengthen network defenses against web service exploitation is at your fingertips.
Tenable
Web Services Indicator Dashboard
blogs_tenable·2017-04-05
Web Services Indicator Dashboard
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Prioritize Hosts Dashboard
blogs_tenable·2017-03-22
Prioritize Hosts Dashboard
Blog / Products
Subscribe
# Prioritize Hosts Dashboard
David Schwalenberg
March 22, 2017
5 Min Read
What systems on your network need attention now? With all the administrative work you need to have done by yesterday, how do you prioritize mitigation efforts to deal with host vulnerabilities? The enhanced vulnerability detection capabilities of Tenable.io™ can help you make the best prioritization decisions for keeping your network secure. The Prioritize Hosts dashboard presents several lists of hosts requiring immediate attention, such as top hosts infected with malware and top hosts with exploitable vulnerabilities, to help you decide which hosts should be prioritized first.
### Top priority assets to secure
The Top Hosts Infected with Malware table displays the top hosts on the n
Tenable
Prioritize Hosts Dashboard
blogs_tenable·2017-03-22
Prioritize Hosts Dashboard
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Vulnerabilities by Common Ports Dashboard
blogs_tenable·2017-03-07
Vulnerabilities by Common Ports Dashboard
Blog / Products
Subscribe
# Vulnerabilities by Common Ports Dashboard
Josef Weiss
March 7, 2017
6 Min Read
Vulnerabilities within network services may result in data loss, denial of services, or allow attackers to facilitate attacks against other devices. Checking for insecure or non-essential services is critical to reducing risk on the network. By identifying open ports along with their associated services, you can ensure said services are necessary and the associated risks are mitigated accordingly. Leveraging Tenable.io™ enhanced vulnerability management capabilities provides an effective way to detect port and service related vulnerabilities, and provides insight into hidden security risks, enabling you to make better informed decisions to protect your organization.
The vast maj
Tenable
Vulnerabilities by Common Ports Dashboard
blogs_tenable·2017-03-07
Vulnerabilities by Common Ports Dashboard
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Vulnerability Management Dashboard
blogs_tenable·2017-02-22
Vulnerability Management Dashboard
Blog / Products
Subscribe
# Vulnerability Management Dashboard
Stephanie Dunn
February 22, 2017
5 Min Read
Along with traditional assets, dynamic assets such as mobile devices, containers, and cloud-based solutions are changing the way organizations deal with vulnerability management. To manage these effectively, you need a streamlined way to assess your organization’s existing security posture. Leveraging Tenable.io™ enhanced vulnerability management capabilities provides a more effective way to manage assets and their vulnerabilities, and provides insight into hidden security risks enabling you to make better informed decisions to protect your organization.
### Managing vulnerabilities
Tenable.io enhanced vulnerability management capabilities provides a more effective way to manag
Tenable
Vulnerability Management Dashboard
blogs_tenable·2017-02-22
Vulnerability Management Dashboard
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Network Monitoring: A Vital Component of Your Security Program
blogs_tenable·2016-08-04·CVSS 7.8
[HIGH] Network Monitoring: A Vital Component of Your Security Program
Blog / Products
Subscribe
# Network Monitoring: A Vital Component of Your Security Program
Dick Bussiere
August 4, 2016
0 Min Read
Despite the many advances in information security, organizations are still experiencing breaches. Whether the root of an attack is human error or system weakness, network monitoring can help detect suspicious behavior and measure security configurations.
Network monitoring for information security has a long history. In a recent series in CSO, Dick Bussiere details the history of cybersecurity countermeasures, the current state of affairs, and trends in network monitoring. Read Network Monitoring: Past Present and Future for a fascinating perspective.
Read the full article
### Dick Bussiere
Dick is a seasoned technical architect with over 20 years of e
Tenable
Network Monitoring: A Vital Component of Your Security Program
blogs_tenable·2016-08-04
Network Monitoring: A Vital Component of Your Security Program
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Reduce Exposure Through Immediate Threat Identification and Fast Response
blogs_tenable·2016-06-13
Reduce Exposure Through Immediate Threat Identification and Fast Response
Blog / Products
Subscribe
# Reduce Exposure Through Immediate Threat Identification and Fast Response
Diane Garey
June 13, 2016
4 Min Read
At Tenable, we have long been champions of continuous monitoring. Constantly collecting and interpreting data from multiple sources, including active and agent scans, network traffic, events, log data, and via integrations with other systems and applications gives you continuous visibility into what’s happening on your network as well as the critical context you need to take decisive action.
This continuous flow of security information also helps solve some very specific security challenges, including what happens when a high visibility threat or vulnerability makes the news.
### High visibility threats and vulnerabilities
High visibility threat
Tenable
Reduce Exposure Through Immediate Threat Identification and Fast Response
blogs_tenable·2016-06-13
Reduce Exposure Through Immediate Threat Identification and Fast Response
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Comprehensive Vulnerability Management for a Changing IT Landscape
blogs_tenable·2016-05-25
Comprehensive Vulnerability Management for a Changing IT Landscape
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Comprehensive Vulnerability Management for a Changing IT Landscape
blogs_tenable·2016-05-25
Comprehensive Vulnerability Management for a Changing IT Landscape
Blog /
Subscribe
# Comprehensive Vulnerability Management for a Changing IT Landscape
Diane Garey
May 25, 2016
4 Min Read
A comprehensive vulnerability management program is the foundation for effective security. Yet, many organizations find it challenging to run an effective program where vulnerabilities are quickly identified and remediated. And for many organizations, not fixing vulnerabilities has consequences. In their Market Overview: Vulnerability Management report published in April 2015, Forrester Research noted that 53% of external attacks are carried out by hackers exploiting software vulnerabilities.
Many organizations find it challenging to run an effective program where vulnerabilities are quickly identified and remediated
There are many reasons why vulnerability manag
Tenable
3 Myths That Impede the Shift Towards Continuous Compliance
blogs_tenable·2015-12-03
3 Myths That Impede the Shift Towards Continuous Compliance
Blog /
Subscribe
# 3 Myths That Impede the Shift Towards Continuous Compliance
Robert Kral
December 3, 2015
4 Min Read
This is the second installment in my Drifting Out of Compliance series, taking a closer look at organizational approaches to compliance and the challenges of shifting from a point-in-time compliance mentality to a continuous compliance one. Although a security first, compliance second approach is best, many organizations still struggle to attain the baseline level of security documented in compliance requirements.
In the first installment of this series, I pointed out that the point-in-time compliance mentality is commonplace in the marketplace today and manifests itself in several ways:
- The project mindset: setting up a team to demonstrate compliance at a point i
Tenable
3 Myths That Impede the Shift Towards Continuous Compliance
blogs_tenable·2015-12-03
3 Myths That Impede the Shift Towards Continuous Compliance
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
System Misconfigurations Can Put Your Data at Risk
blogs_tenable·2015-10-06
System Misconfigurations Can Put Your Data at Risk
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
System Misconfigurations Can Put Your Data at Risk
blogs_tenable·2015-10-06
System Misconfigurations Can Put Your Data at Risk
Blog / Products
Subscribe
# System Misconfigurations Can Put Your Data at Risk
Diane Garey
October 6, 2015
5 Min Read
While many organizations focus on their vulnerability management programs to find critical vulnerabilities like the highly-publicized Shellshock, Poodle and Ghost, it’s equally important to validate system build and configuration change management processes, as these activities can also leave your systems and data at risk. Kelly Prevett and I addressed this topic last week in a Tenable webcast where we shared some interesting misconfiguration examples, discussed how to coordinate people, processes and technology to avoid misconfigurations, and explained how Nessus configuration audits can help.
### How can system misconfigurations leave you vulnerable?
A good example
Tenable
Why Periodic Security Scans Aren’t Good Enough in Today’s Threat Environment
blogs_tenable·2014-11-13
Why Periodic Security Scans Aren’t Good Enough in Today’s Threat Environment
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Why Periodic Security Scans Aren’t Good Enough in Today’s Threat Environment
blogs_tenable·2014-11-13·CVSS 7.8
[HIGH] Why Periodic Security Scans Aren’t Good Enough in Today’s Threat Environment
Blog / Products
Subscribe
# Why Periodic Security Scans Aren’t Good Enough in Today’s Threat Environment
Ron Gula
November 13, 2014
1 Min Read
In a recent post in Wired’s Innovation Insights blog, Ron Gula explains why continuous monitoring is needed as preventive healthcare to protect today’s IT landscape.
> An annual medical exam is routine for most of us, and something we usually do when we are feeling relatively well. But imagine a scenario where, rather than starting at a place of health, your systems are under constant attack. A periodic check-up isn’t good enough to monitor weakened defenses. It’s the same situation with networks. And it’s even more complex since networks now encompass virtual, cloud and mobile environments as well as on-premises systems. Traditional defensive
Tenable
Blaming Victims
blogs_tenable·2014-11-07
Blaming Victims
Blog /
Subscribe
# Blaming Victims
Marcus J. Ranum
November 7, 2014
3 Min Read
At a recent conference, I heard a security practitioner blame a couple of users for being dummies who click on everything. He then said, “At a certain point, it's reasonable to blame the user. It's just like when someone parks a car with the keys in it, in a known bad neighborhood. You have to take ownership of your actions.” Well, yes and no. I'd like to use that bit of wisdom as a platform for talking about “blame” versus “victimization” and “being foolish.” In security, we often blame the victim and I think that's a bad idea — it just victimizes them doubly.
### Expectations
Expecting users to do the right thing is not the same as expecting car owners to not park and leave their keys in known bad neigh
Tenable
Blaming Victims
blogs_tenable·2014-11-07
Blaming Victims
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Continuous Monitoring for the New IT Landscape
blogs_tenable·2014-08-06
Continuous Monitoring for the New IT Landscape
Blog / Products
Subscribe
# Continuous Monitoring for the New IT Landscape
Marcus J. Ranum
August 6, 2014
4 Min Read
The landscape of IT security is changing and the rash of recent data breaches has targeted a fatal flaw in the way organizations have approached security over the last two decades. When it comes to security practices, organizations are going to have to adapt: older techniques simply won’t cut it anymore.
Defensive technologies like firewalls, antivirus, patching systems and security event management have failed to prevent successful attacks because they are frequently not aligned with a unified security policy or business practice.
Continuous monitoring manages the automated discovery and security assessment of traditional IT servers and desktops, mobile users, virtua
Tenable
Continuous Monitoring for the New IT Landscape
blogs_tenable·2014-08-06
Continuous Monitoring for the New IT Landscape
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
How Gaps in Pen Testing and Intrusion Detection Paved the Path to Continuous Monitoring
blogs_tenable·2014-08-05
How Gaps in Pen Testing and Intrusion Detection Paved the Path to Continuous Monitoring
Blog / Products
Subscribe
# How Gaps in Pen Testing and Intrusion Detection Paved the Path to Continuous Monitoring
Ron Gula
August 5, 2014
4 Min Read
Last week I had my annual physical, with the goal of checking the big things—heart, cholesterol, blood pressure. I also had an ache in my foot that had caused me some trouble running, but which I had largely ignored. My doctor recommended a foot x-ray. The diagnosis--a bone fracture. Had I kept running, the fracture would have worsened, I would have stopped exercise altogether, which undoubtedly would have hurt my ability to protect the big things—heart, cholesterol, blood pressure.
An annual trip to the doctor is my norm. But imagine a scenario where, rather than starting at a place of health, your systems are under constant attack. T
Tenable
How Gaps in Pen Testing and Intrusion Detection Paved the Path to Continuous Monitoring
blogs_tenable·2014-08-05
How Gaps in Pen Testing and Intrusion Detection Paved the Path to Continuous Monitoring
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Nessus Now Audits Huawei VRP Configurations
blogs_tenable·2014-07-08
Nessus Now Audits Huawei VRP Configurations
Blog / Products
Subscribe
# Nessus Now Audits Huawei VRP Configurations
Paul Asadoorian
July 8, 2014
2 Min Read
As part of Tenable's Continuous Monitoring Solution, Nessus, Nessus Enterprise and Nessus Enterprise Cloud users can now perform configuration audits against Huawei devices running the Versatile Routing Platform (VRP).
Huawei (pronounced "wah-way") is a manufacturer of several different types of networking and telecommunications hardware and software. Huawei products are more popular in Asia and Europe than in the U.S. This new plugin supports devices running Huawei Versatile Routing Platform VRP (R) software. The 'display version' command can be run on the target to obtain the release information and determine if it’s supported by the Nessus audit files.
### Scan Configur
Tenable
Nessus Now Audits Huawei VRP Configurations
blogs_tenable·2014-07-08
Nessus Now Audits Huawei VRP Configurations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Detecting Credit Cards, SSNs and other Sensitive Data on UNIX/Linux Systems
blogs_tenable·2014-06-16
Detecting Credit Cards, SSNs and other Sensitive Data on UNIX/Linux Systems
Blog / Products
Subscribe
# Detecting Credit Cards, SSNs and other Sensitive Data on UNIX/Linux Systems
Paul Asadoorian
June 16, 2014
3 Min Read
Nessus, Nessus Enterprise and Nessus Enterprise Cloud users can now remotely scan UNIX and Linux systems for the presence of sensitive information such as credit/debit card numbers, SSNs, company confidential information, and more.
### What Can I Discover?
New configuration auditing capabilities have been added for Nessus users to remotely check UNIX and Linux systems for the presence of sensitive information. This capability has been available on Windows systems for some time; you can refer to the blog post titled "Detecting Credit Cards, SSNs and other Sensitive Data at rest with Nessus" for additional information. The Windows sensitive f
Tenable
Detecting Credit Cards, SSNs and other Sensitive Data on UNIX/Linux Systems
blogs_tenable·2014-06-16
Detecting Credit Cards, SSNs and other Sensitive Data on UNIX/Linux Systems
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
The Move Beyond Point Scanning
blogs_tenable·2014-02-20
The Move Beyond Point Scanning
Blog / Products
Subscribe
# The Move Beyond Point Scanning
Paul Crutchfield
February 20, 2014
6 Min Read
A few weeks back, I was visiting with a customer to update them on current release information and roadmap features. A lot of the discussion revolved around their current vulnerability management process, and potential improvement areas based on SecurityCenter Continuous View. We talked about how many people they had using SecurityCenter and how they utilized the analytics and dashboards, but it turned out there were only a handful doing this, and they were mainly using SC to automate their weekly scanning, report creation, and distribution process. This is not uncommon, and SC can certainly streamline most manual cycles. However, when I mentioned they really needed to look at movi
Tenable
The Move Beyond Point Scanning
blogs_tenable·2014-02-20
The Move Beyond Point Scanning
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Introduction to new and now available SecurityCenter 4.6 and PVS 3.8
blogs_tenable·2012-12-04·CVSS 7.8
[HIGH] Introduction to new and now available SecurityCenter 4.6 and PVS 3.8
Blog / Products
Subscribe
# Introduction to new and now available SecurityCenter 4.6 and PVS 3.8
Jack Daniel
December 4, 2012
1 Min Read
Note: Tenable SecurityCenter is now Tenable.sc. To learn more about this application and its latest capabilities, visit the Tenable.sc web page.
Tenable Network Security has released SecurityCenter 4.6 and PVS 3.8. These new and now available updates to SecurityCenter and the Passive Vulnerability Scanner include several new features and enhancements.
Adding to the long-standing IPv6 capabilities of Nessus, both SecurityCenter and PVS now support IPv6. Combined, these create the only truly comprehensive IPv6 vulnerability assessment and management suite in the industry, and expand SecurityCenter CV’s continuous monitoring capabilities to include IP
Tenable
Introduction to new and now available SecurityCenter 4.6 and PVS 3.8
blogs_tenable·2012-12-04
Introduction to new and now available SecurityCenter 4.6 and PVS 3.8
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Is that System Managed?
blogs_tenable·2011-11-02
Is that System Managed?
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Is that System Managed?
blogs_tenable·2011-11-02
Is that System Managed?
Blog /
Subscribe
# Is that System Managed?
Ron Gula
November 2, 2011
4 Min Read
IT auditors, penetration testers, and incident responders often ask if a system they are analyzing is managed. A managed system is one that is being looked after, updated and maintained by an IT staff of some sort. An unmanaged system is one that is on the network, but perhaps has been forgotten, isn’t authorized or has some other reason for it not to be there or updated by anyone else.
Security findings for managed systems and unmanaged systems are reported differently. For an unmanaged system, the recommendation is to make the system managed and bring it into a secured state. For security issues with managed systems, the recommendation is to alter the current management processes to make them more secur
Tenable
Marcus Ranum PaulDotCom Interview on Penetration Testing
blogs_tenable·2008-12-14·CVSS 7.8
[HIGH] Marcus Ranum PaulDotCom Interview on Penetration Testing
Blog / Company
Subscribe
# Marcus Ranum PaulDotCom Interview on Penetration Testing
Ron Gula
December 14, 2008
0 Min Read
Tenable's CSO, Marcus Ranum, was recently interviewed on the PaulDotCom Security Weekly podcast. They discussed a wide range of topics regarding penetration testing, secure coding, Marcus's "6 Dumbest Ideas" in computer security and much more.
- Full PaulDotCom show notes.
- Direct link to the show's MP3 audio recording.
- Tenable podcast and slides on Marcus's "6 Dumbest Ideas in Computer Security" presentation from from 2006.
- Very cool image of Marcus Ranum demonstrating cutting edge computer security practices.
## Related articles
March 17, 2026
## FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word
An N-day vulnerability in Microsoft Word exposes n
Tenable
Marcus Ranum PaulDotCom Interview on Penetration Testing
blogs_tenable·2008-12-14
Marcus Ranum PaulDotCom Interview on Penetration Testing
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
PCI Configuration Audits with Nessus
blogs_tenable·2007-07-03
PCI Configuration Audits with Nessus
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
PCI Configuration Audits with Nessus
blogs_tenable·2007-07-03
PCI Configuration Audits with Nessus
Blog / Products
Subscribe
# PCI Configuration Audits with Nessus
Ron Gula
July 3, 2007
2 Min Read
Tenable's Research group has produced two Nessus PCI configuration .audit files for both the Windows and Linux operating systems. These configuration checks are derived from specific recommendations and audit requirements based on the PCI 1.1 standard.
These checks go above and beyond the PCI requirements of performing vulnerability and patch auditing and makes it very easy to audit and analyze system configurations against specific PCI items. These new audits also makes it easy to perform a single scan of one or more PCI hosts and accomplish a vulnerability, patch and configuration audit.
For the Windows PCI policy, configuration audits are available to ensure that a host firewall is e
Tenable
CIS Certification for Nessus Red Hat audits
blogs_tenable·2007-06-22
CIS Certification for Nessus Red Hat audits
Blog /
Subscribe
# CIS Certification for Nessus Red Hat audits
Ron Gula
June 22, 2007
3 Min Read
Tenable was recently awarded certification to perform Center For Internet Security (CIS) audits of Red Hat systems with the Nessus 3 scanner and Security Center. This blog entry discusses what the audit files look for, how customers should obtain the audit files and how this impacts PCI audits.
CIS Red Hat ES4 Audit Policy
A new .audit file for both Nessus Direct Feed and the Security Center named redhat_es4_cis.audit, is available on the Tenable Support Portal. This .audit file implements configuration checks and settings recommended in version 1.0.5 of the CIS Red Hat Benchmark.
Audit checks include:
- Correct logging levels
- Secure configuration of SSH
- Banners for FTP, logins and
Tenable
CIS Certification for Nessus Red Hat audits
blogs_tenable·2007-06-22
CIS Certification for Nessus Red Hat audits
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
New Keywords and APIs for UNIX Compliance Checks
blogs_tenable·2007-05-29
New Keywords and APIs for UNIX Compliance Checks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
New Keywords and APIs for UNIX Compliance Checks
blogs_tenable·2007-05-29
New Keywords and APIs for UNIX Compliance Checks
Blog / Products
Subscribe
# New Keywords and APIs for UNIX Compliance Checks
Ron Gula
May 29, 2007
9 Min Read
Tenable has recently added several new APIs to the UNIX compliance checks. This blog entry discusses the new checks with several examples. These APIs are available to Direct Feed and Security Center users who have recently updated their plugins. Many of these checks will work for any UNIX operating system, however several of them are specific to RedHat Linux and its derivatives such as Fedora.
New File Based Keywords and APIs
Checking File Attributes
This 'attr' keyword can now be used in conjunction with the FILE_CHECK and FILE_CHECK_NOT APIs to audit the file attributes associated with a file. Here is a short example:
type : FILE_CHECK
file : "/bin/sh"
md5 : "d4228cff8f
Tenable
CIS "Best Practices" Certification For Nessus Audits
blogs_tenable·2007-05-21
CIS "Best Practices" Certification For Nessus Audits
Blog / Products
Subscribe
# CIS "Best Practices" Certification For Nessus Audits
Ron Gula
May 21, 2007
4 Min Read
Tenable was recently awarded certification to perform three different Center For Internet Security (CIS) Windows Domain Controller audits with the Nessus 3 scanner and Security Center. This blog entry discusses CIS, what the audit files look for, how customers should obtain the audit files and how this impacts PCI audits.
Center for Internet Security
The CIS is a non-profit organization that produces "best practice" guides for securing a wide variety of IT infrastructure such as operating systems, applications and network devices. The consortium takes input from operators, operating system vendors, governments and security experts to produce a set of "best practices" doc
Tenable
CIS "Best Practices" Certification For Nessus Audits
blogs_tenable·2007-05-21
CIS "Best Practices" Certification For Nessus Audits
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
NIST Audit Policies for Nessus 3
blogs_tenable·2007-04-30
NIST Audit Policies for Nessus 3
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
NIST Audit Policies for Nessus 3
blogs_tenable·2007-04-30
NIST Audit Policies for Nessus 3
Blog / Products
Subscribe
# NIST Audit Policies for Nessus 3
Ron Gula
April 30, 2007
3 Min Read
Tenable has released our first batch of audit policies which can test Windows 2000, 2003 and XP Pro systems for compliance with NIST best practice configuration standards.
These ".audit" checks are currently available on Tenable's Support Portal (available to Tenable customers) and can be downloaded to any Nessus 3 Direct Feed scanner or SecurityCenter.
NIST SCAP Program
The US National Institute of Science and Technology has many different groups which keep track of and publish guides for a wide variety of standards, including several for computer security. The NIST Secure Content Automation Program (SCAP), offers content which can be used to automate security testing. The end result of
Tenable
Detection of Non Disclosure Agreements with Nessus
blogs_tenable·2007-04-06·CVSS 7.8
[HIGH] Detection of Non Disclosure Agreements with Nessus
Blog / Products
Subscribe
# Detection of Non Disclosure Agreements with Nessus
Ron Gula
April 6, 2007
1 Min Read
Modern business attempt to put in place "Non Disclosure Agreements" with each other. These agreements dictate the rules for use for knowledge gained through interaction with each other.
Tenable's research group recently added a .audit content policy file to search for NDAs in Adobe and Word documents. The expected location for an NDA would be in your legal department. However, discovering NDAs on public web servers, on public network folders or on mobile sales laptops may indicate that unauthorized people have access.
The .audit file performs some keyword searches. This could also be extended with specific names of competitors or business partners to be more exact in what
Tenable
Detection of Non Disclosure Agreements with Nessus
blogs_tenable·2007-04-06
Detection of Non Disclosure Agreements with Nessus
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Enterprise Sensitive Data Monitoring
blogs_tenable·2007-04-02
Enterprise Sensitive Data Monitoring
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Enterprise Sensitive Data Monitoring
blogs_tenable·2007-04-02
Enterprise Sensitive Data Monitoring
Blog / Products
Subscribe
# Enterprise Sensitive Data Monitoring
Ron Gula
April 2, 2007
3 Min Read
Note: This blog entry was originally posted in April, 2007 and was updated on May 28, 2009
The SecurityCenter can be used to manage multiple Nessus scanners and Passive Vulnerability Scanners for continuous monitoring of sensitive data at rest and data in motion. This blog entry discusses various deployment scenarios that can be used to effectively perform data leakage detection.
Active and Passive Detection Methods
In March 2007, Tenable released the ability for Nessus ProfessionalFeed and SecurityCenter users to scan Windows hosts for sensitive data such as credit cards, employee information and even things like source code. This technology works as part of the regular vulnerability
Tenable
New Nessus Configuration Auditing Features for Windows Servers
blogs_tenable·2007-03-27
New Nessus Configuration Auditing Features for Windows Servers
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
New Nessus Configuration Auditing Features for Windows Servers
blogs_tenable·2007-03-27
New Nessus Configuration Auditing Features for Windows Servers
Blog / Products
Subscribe
# New Nessus Configuration Auditing Features for Windows Servers
Ron Gula
March 27, 2007
6 Min Read
Tenable has added several new types of configuration and security audits that can be performed by Nessus 3 against Windows servers. This blog post explains the new items.
New Auditing Options
There are four new types of audit types available for Windows:
- GROUP_MEMBERS_POLICY
- FILE_AUDIT
- REGISTRY AUDIT
- SERVICE_AUDIT
The new types allow for close analysis of file, registry and service audit policies as well as which specific users are members of of a group.
GROUP_MEMBERS_POLICY
If you would like to perform audits of a Windows server and make sure that there is a specific list of users present in one or more groups, it is now very trivial to accomplis
Tenable
Detecting Change -- Part II
blogs_tenable·2007-03-13
Detecting Change -- Part II
Blog / Products
Subscribe
# Detecting Change -- Part II
Ron Gula
March 13, 2007
5 Min Read
Tenable has previously bloged about how change can be detected through log analysis. Network change can be detected many other ways, including scanning and passive network monitoring. This blog entry will discuss why detecting change is important to security and compliance, the different types of change that can occur on the network and how they can be detected with Tenable solutions.
Types of Network Change
You might think of a network as always being in motion. There are different users logged on, different traffic loads and over time, new services are supported by the network. Having discrete methods to detect certain types of change is extremely useful. Consider the following lists of pote
Tenable
Detecting Change -- Part II
blogs_tenable·2007-03-13
Detecting Change -- Part II
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Automated audit policy creation for UNIX Nessus compliance checks
blogs_tenable·2007-02-27
Automated audit policy creation for UNIX Nessus compliance checks
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Automated audit policy creation for UNIX Nessus compliance checks
blogs_tenable·2007-02-27
Automated audit policy creation for UNIX Nessus compliance checks
Blog / News and Views
Subscribe
# Automated audit policy creation for UNIX Nessus compliance checks
Ron Gula
February 27, 2007
16 Min Read
Many UNIX applications and system settings are contained in proprietary text configuration files. Auditing these for unauthorized changes or configurations can be very cumbersome and time consuming. Nessus 3 Direct Feed and Security Center users have the ability to audit UNIX servers against a configuration policy without an agent. Being able to automatically prove that all remote systems and applications have a certain configuration setting or that they have not changed from a known good configuration has tremendous value for compliance monitoring and system management.
Today, Tenable released a UNIX utility named "Configuration to Audit" (c2a) w
Tenable
Enhanced Windows Compliance Auditing
blogs_tenable·2007-02-24
Enhanced Windows Compliance Auditing
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Enhanced Windows Compliance Auditing
blogs_tenable·2007-02-24
Enhanced Windows Compliance Auditing
Blog / Products
Subscribe
# Enhanced Windows Compliance Auditing
Ron Gula
February 24, 2007
3 Min Read
The Nessus 3 Direct Feed was updated today with enhanced functionality for Windows compliance checks. This blog entry discusses the new features and has example .audit text to illustrate them, including a test case for the recent Microsoft update for 2007 Daylight Savings Time. These changes only effect Windows audits.
Multiple Potential Compliance Values for AUDIT_POLICY Items
Both the "value" and "value_data" keywords can now accept multiple values within an "AUDIT_POLICY" context. If any of these values are present in the audited system, then the system passes the audit. Values are separated with "|" characters. Here is an example for a simple built-in test as well as a custom i
Zscaler
Zscaler protects against 9 new vulnerabilities | 02-10-2026
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler protects against 9 new vulnerabilities | 02-10-2026
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Tenable
Blog
blogs_tenable
Blog
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Wiz
CVE-2026-21514 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.8
CVE-2026-21514 [HIGH] CVE-2026-21514 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21514 :
vulnerability analysis and mitigation
Reliance on untrusted inputs in a security decision in Microsoft Office Word allows an unauthorized attacker to bypass a security feature locally.
Source : NVD
## 7.8
Score
Published February 10, 2026
Severity HIGH
CNA Score 7.8
Has Public Exploit Yes
Has CISA KEV Exploit Yes
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 90.2
Exploitation Probability (EPSS) 5.4
Sources
NVD
## Get a CVE risk assessment
Get a prioritized view of CVEs in your cloud—so you can focus on what's exploitable, not just what's listed.
Free Vulnerability Assessment
## Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your ri
Recorded Future
February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
blogs_recorded_future·CVSS 7.7
[HIGH] February 2026 CVE Landscape: 13 Critical Vulnerabilities Mark 43% Drop from January
# February 2026 CVE Landscape:13 Critical Vulnerabilities Mark 43% Drop from January
February 2026 saw a 43% decrease in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 13 vulnerabilities requiring immediate remediation, down from 23 in January 2026. All 13 carried a ‘Very Critical’ Recorded Future Risk Score.
What security teams need to know:
- Microsoft dominates: Six of 13 vulnerabilities affected Microsoft products, accounting for 46% of February's findings; all were added to CISA's KEV catalog on the same day
- Supply-chain attack on Notepad++: Lotus Blossom, a suspected China state-sponsored threat actor, exploited CVE-2025-15556 to hijack Notepad++'s update channel and deliver a Cobalt Strike Beacon and the Chrysalis backdoor
- APT28 exploits MSHTML
Tenable
Blog
blogs_tenable·CVSS 7.8
[HIGH] Blog
# Tenable blog
Subscribe
Featured
March 17, 2026
## Operation Epic Fury: Why exposure data changes everything about Iran's cyber-kinetic campaign
Iran's retaliatory campaign following Operation Epic Fury has collapsed the boundary between physical and digital warfare. Tenable's exposure data analysis across seven target countries reveals that the largest exploitable attack surface isn't the headline threat, it's a Microsoft Word N-day affecting nearly 14 million assets.
Robert Huber
March 17, 2026
## FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word
An N-day vulnerability in Microsoft Word exposes nearly 14 million assets. Attackers can exploit this flaw to bypass security prompts, enabling deployment of malware and establishing persistent access without triggering user w
Sophos
February’s Patch Tuesday assumes battle stations
blogs_sophos
February’s Patch Tuesday assumes battle stations
Share This
Microsoft on Tuesday released 58 patches affecting 15 product families. Five of the addressed issues, all involving Azure, are considered by Microsoft to be of Critical severity, though only two require urgent attention (more on that below). Fifteen have a CVSS base score of 8.0 or higher, including two with a 9.8 base score. Six are known to be under active exploit in the wild, and three are publicly disclosed (including one not yet known to be under exploit).
At patch time, five CVEs are judged more likely to be exploited in the next 30 days by the company’s estimation, in addition to the six already detected to be so. Various of this month’s issues are amenable to direct detection by Sophos protections, and we include information on those in a table below. The release also
2026-02-10
Published
2026-02-10
Added to CISA KEV
Exploited in the wild