Tenable blog
Cybersecurity Snapshot: SharePoint Attacks Trigger Urgent Patching Calls, While U.S. Gov’t Unveils AI Innovation Plan

إذا كان لديك ٣ دقائق فقط:العناصر الأساسية للاستجابة الفعالة للمخاطر
Learned helplessness and lack of prioritization are two vulnerability management pitfalls cybersecurity teams face. Here’s how an exposure response program can help....
Cybersecurity Snapshot: ملخص أمن الذكاء الاصطناعي: أفضل الممارسات والأبحاث والرؤى
In this special edition, we’ve selected the most-read Cybersecurity Snapshot items about AI security this year. ICYMI the first time around, check out this roundup of data points, tips and trends about secure AI deployment; shadow AI; AI threat detection; AI risks; AI governance; AI cybersecurity us...
اتباع النهج: كيف تفي شركة Tenable بتعهدها "بالتصميم الآمن" تجاه وكالة الأمن السيبراني وأمن البنية التحتية (CISA)
As a cybersecurity leader, Tenable was proud to be one of the original signatories of CISA’s “Secure by Design" pledge” earlier this year. Our embrace of this pledge underscores our commitment to security-first principles and reaffirms our dedication to shipping robust, secure products that our user...
Cybersecurity Snapshot: Prompt Injection and Data Disclosure Top OWASP’s List of Cyber Risks for GenAI LLM Apps
Don’t miss OWASP’s update to its “Top 10 Risks for LLMs” list. Plus, the ranking of the most harmful software weaknesses is out. Meanwhile, critical infrastructure orgs have a new framework for using AI securely. And get the latest on the BianLian ransomware gang and on the challenges of protecting ...
Active Directory تحت الهجوم: إرشادات "العيون الخمس" تستهدف ثغرات أمنية بالغة الأهمية
A landmark global report from cybersecurity agencies emphasizes 17 attack techniques against Microsoft Active Directory and cautions organizations to step up protections. In the first of our two-part series, we offer five steps you can take today to shore up your AD defenses....
خمس وكالات سيبرانية تدق ناقوس الخطر بشأن هجمات Active Directory: تجاوز الأساسيات
A landmark global report emphasizes 17 attack techniques against Microsoft Active Directory and cautions organizations to step up protections. In the second of our two-part series, we take you beyond the basics to highlight three key areas to focus on....
Volt Typhoon: ما الذي يجب على مسؤولي الحكومة المحلية والولاية معرفته
Increased activity from the state-sponsored threat group Volt Typhoon raises concerns about the cybersecurity of U.S. critical infrastructure. Here’s how you can identify potential exposures and attack paths....
Volt Typhoon: الولايات المتحدةالبنية التحتية الحيوية المستهدفة من قبل الجهات التي ترعاها الدولة
Volt Typhoon, a state-sponsored actor linked to the People’s Republic of China, has consistently targeted U.S. critical infrastructure with the intent to maintain persistent access. Tenable Research examines the tactics, techniques and procedures of this threat actor....
CVE-2024-0012, CVE-2024-9474: استغلال الثغرات الأمنية الأولية المباغتة في Palo Alto PAN-OS غير المكتشفة
Palo Alto Networks confirmed two zero-day vulnerabilities were exploited as part of attacks in the wild against PAN-OS devices, with one being attributed to Operation Lunar Peek....