Securing Financial Data in the Cloud: How Tenable Can Help
Preventing data loss, complying with regulations, automating workflows and managing access are four key challenges facing financial institutions. Learn how Tenable can help.Imagine a bustling bank,...
View ArticleContext Is King: From Vulnerability Management to Exposure Management
Vulnerability management remains a cornerstone of preventive cybersecurity, but organizations still struggle with vulnerability overload and sophisticated threats. Tenable’s new Exposure Signals gives...
View ArticleCybersecurity Snapshot: CISA Warns of Global Spear-Phishing Threat, While...
CISA is warning about a spear-phishing campaign that spreads malicious RDP files. Plus, OWASP is offering guidance about deepfakes and AI security. Meanwhile, cybercriminals have amplified their use of...
View ArticleMicrosoft’s November 2024 Patch Tuesday Addresses 87 CVEs (CVE-2024-43451,...
4Critical82Important1Moderate0LowMicrosoft addresses 87 CVEs and one advisory (ADV240001) in its November 2024 Patch Tuesday release, with four criticalvulnerabilitiesand four zero-day vulnerabilities,...
View ArticleWho’s Afraid of a Toxic Cloud Trilogy?
The Tenable Cloud Risk Report 2024 reveals that nearly four in 10 organizations have workloads that are publicly exposed, contain a critical vulnerability and have excessive permissions. Here’s what to...
View ArticleCybersecurity Snapshot: Five Eyes Rank 2023’s Most Frequently Exploited CVEs,...
Check out the CVEs attackers targeted the most last year, along with mitigation tips. Plus, a new guide says AI system audits must go beyond check-box compliance. Meanwhile, a report foresees stronger...
View ArticleThe Dark Side of Domain-Specific Languages: Uncovering New Attack Techniques...
Check out our deep dive into both new and known techniques for abusing infrastructure-as-code and policy-as-code tools. You’ll also learn how to defend against them in this blog post which expands on...
View ArticleNew AWS Control Policy on the Block
AWS has released an important new feature that allows you to apply permission boundaries around resources at scale called Resource Control Policies (RCPs). Read on to learn what RCPs are all about and...
View ArticleCVE-2024-0012, CVE-2024-9474: Zero-Day Vulnerabilities in Palo Alto PAN-OS...
Palo Alto Networks confirmed two zero-day vulnerabilities were exploited as part of attacks in the wild against PAN-OS devices, with one being attributed to Operation Lunar Peek.BackgroundOn November...
View ArticleVolt Typhoon: U.S. Critical Infrastructure Targeted by State-Sponsored Actors
Volt Typhoon, a state-sponsored actor linked to the People’s Republic of China, has consistently targeted U.S. critical infrastructure with the intent to maintain persistent access. Tenable Research...
View ArticleVolt Typhoon: What State and Local Government Officials Need to Know
Increased activity from the state-sponsored threat group Volt Typhoon raises concerns about the cybersecurity of U.S. critical infrastructure. Here’s how you can identify potential exposures and attack...
View ArticleFive Cyber Agencies Sound Alarm About Active Directory Attacks: Beyond the...
A landmark global report emphasizes 17 attack techniques against Microsoft Active Directory and cautions organizations to step up protections. In the second of our two-part series, we take you beyond...
View ArticleActive Directory Under Attack: Five Eyes Guidance Targets Crucial Security Gaps
A landmark global report from cybersecurity agencies emphasizes 17 attack techniques against Microsoft Active Directory and cautions organizations to step up protections. In the first of our two-part...
View ArticleCybersecurity Snapshot: Prompt Injection and Data Disclosure Top OWASP’s List...
Don’t miss OWASP’s update to its “Top 10 Risks for LLMs” list. Plus, the ranking of the most harmful software weaknesses is out. Meanwhile, critical infrastructure orgs have a new framework for using...
View ArticleWalking the Walk: How Tenable Embraces Its "Secure by Design" Pledge to CISA
As a cybersecurity leader, Tenable was proud to be one of the original signatories of CISA’s “Secure by Design" pledge earlier this year. Our embrace of this pledge underscores our commitment to...
View ArticleCybersecurity Snapshot: AI Security Roundup: Best Practices, Research and...
In this special edition, we’ve selected the most-read Cybersecurity Snapshot items about AI security this year. ICYMI the first time around, check out this roundup of data points, tips and trends about...
View ArticleIf You Only Have 3 Minutes: Key Elements of Effective Exposure Response
Learned helplessness and lack of prioritization are two vulnerability management pitfalls cybersecurity teams face. Here’s how an exposure response program can help.In today’s complex cybersecurity...
View ArticleIf You Only Have 2 Minutes: Best Practices for Setting Exposure Response SLAs
Keeping vulnerability management efforts focused on achievable goals is key to avoiding cybersecurity team burnout. Here’s how exposure response workflows and SLAs can help.As organizations grow in the...
View ArticleIf You Only Have 1 Minute: Quick Tips for Effective Exposure Response
Comprehensive, action-oriented workflows and key metrics are the cornerstones of a successful exposure response program. Here’s what you need to know.In today’s fast-paced digital landscape, managing...
View ArticleMaking Zero Trust Architecture Achievable
How NIST is working with Tenable and other private sector stakeholders to better enable zero trust implementation.Trust no one. Verify everything. All the time. When it comes to cybersecurity and...
View Article