tenable security center
45 TopicsImprovement To Plugin 142960 “HSTS Missing From HTTPS Server (RFC 6797)”
Summary Plugin 142960 now validates the identity of an HTTPS service in line with the current RFC 9525 as opposed to the obsolete RFC 6125. When a service's TLS certificate contains Subject Alternative Name (SAN) entries, the plugin compares the target hostname against those SANs only and no longer considers the certificate's Common Name (CN). If the certificate has no SANs, the plugin falls back to using the CN, so coverage for legacy certificates is unchanged. Background Plugin 142960 checks whether a detected web server supports HTTP Strict Transport Security (HSTS). Before it evaluates the service, the plugin must confirm that the service's TLS certificate covers the identity of the host. This confirms that the server is authorized to answer for that host, and that the finding describes the target host and not whichever service happened to respond on its behalf. If the identity check fails, the plugin cannot evaluate the service. Until now, the plugin performed this check by comparing the resolvable hostname against the CN of the certificate presented on the relevant port. If the CN covered the hostname, the service was evaluated for HSTS. RFC 9525, which supersedes the identity-matching guidance in RFC 6125 (which allowed for the checking of CNs) states that when a certificate carries one or more SAN entries, hostname identity must be validated against those SANs only. The CN must not be used for this purpose, even if it matches the hostname. The RFC gives several reasons: the CN is ambiguous, it cannot hold multiple identifiers, and its use leads to security and parsing inconsistencies. This change was prompted by a case in which a host's service could only be identified through the SAN of its certificate and not through the CN. Research into that case led to RFC 9525, and the update follows its guidance. Changes Service identity validation in plugin 142960 now works as follows: If SANs were enumerated from the service's TLS certificate, the hostname is compared against the SANs only. The CN is not used, even when it matches the hostname. If no SANs were enumerated from the certificate, the plugin uses the CN to validate the service identity, as it did before. Impact For services whose certificates include SANs, the outcome of the identity check depends only on the SAN values. A service whose SANs cover the hostname but whose CN does not will now be validated and evaluated for HSTS. A service whose CN matches the hostname but whose SANs do not will no longer pass validation, so the plugin will not evaluate it. Services with certificates that have no SANs are evaluated as before. Affected Plugins 142960 - HSTS Missing From HTTPS Server (RFC 6797) Targeted Release Date Monday, October 12, 2026Tenable Product Update Newsletter - September 2026
Welcome to your monthly round-up of the latest Tenable product updates, platform enhancements, and community news. This month, we’re bringing frontier AI reasoning into exposure management, deepening cloud and vulnerability visibility, and expanding how the community vets AI agents before deployment. Tenable One - Platform updates Claude Mythos 5 is coming to Tenable One with Adversary View Attackers don’t exploit systems in isolation. They chain together scattered, low-signal evidence like netstat entries, cached accounts, and active connections that traditional rules engines can’t connect, and that your team doesn’t have time to piece together manually. This is where frontier AI models shine. Tenable One Adversary View, launching this September, brings the power of Anthropic’s Claude Mythos 5 directly into the Tenable One Exposure Management Platform. Built on the Project Glasswing collaboration between Tenable and Anthropic, Adversary View applies advanced cyber reasoning to your existing exposure data, uncovering hidden vulnerability chains, visualizing how an attacker would actually move through your environment, and surfacing evidence-backed fixes to break those chains before attackers exploit them — all within an agentic harness that keeps the AI’s reasoning controlled and auditable. Take advantage of Claude Mythos 5 to tackle complex exposure management challenges. Cut through the noise with a ranked, prioritized list of the vulnerability chains that matter most, backed by evidence and specific remediation guidance. Move at the speed of adversaries by pairing Claude Mythos 5’s advanced reasoning with the exposure intelligence you already have in Tenable One — no new tools required. Read the blog post Explore the guided demo 3 new connectors bring GitHub and GitLab findings into Tenable One Tenable One connectors combine your third-party security tools with Tenable’s native sensor data for one view of risk across your attack surface. Three new connectors extend that coverage, pulling static application security testing (SAST), software composition analysis (SCA), and secret scanning findings straight into Tenable One. GitHub Code Scanning: Consolidates SAST and secret scanning findings, covering both vulnerable code and exposed credentials, into the same risk view as every other exposure you track. GitHub Dependabot: Brings SCA alerts on vulnerable dependencies, so a flawed package deep in your supply chain gets prioritized against everything else exposing you. GitLab Connector: Covers SAST, SCA, and Secret Detection findings in one connector, consolidating what’s otherwise split across multiple tools into a single risk view. Requires GitLab Ultimate to ingest findings. All three are native connectors; add the connector, and findings start showing up in Tenable One. Set up GitHub Code Scanning Set up GitHub Dependabot Set up GitLab Connector CyberAgents Exchange Exchange Inspector vets AI agents before they reach your environment Tenable and OpenAI unveiled the CyberAgents Exchange AI Inspector, which pairs OpenAI’s GPT cyber models with Tenable One AI Exposure and expert researcher review to screen AI agents, skills, MCP servers, and multi-agent playbooks for prompt injection, PII exposure, and supply-chain risks before they’re deployed. Combines OpenAI GPT cyber models, Tenable One AI Exposure, and expert researcher review to vet AI agents before deployment. Screens AI agents, skills, MCP servers, and multi-agent playbooks for prompt injection, PII exposure, and supply-chain risks. Gives practitioners insight into production-ready AI agents and CISOs the confidence to approve their use. The Exchange Inspector builds on the CyberAgents Exchange registry, which has already drawn more than 100 AI listings. Exchange Inspector is expected to be available in September. Read the technical blog Read the press release Tenable One Vulnerability Management Visualize your security trends over time You can finally see exactly where your security metrics are heading, not just where they stand today. With newly added Trending Widgets, you can track your asset data and findings as daily line charts, giving you the historical context you need to accurately monitor your progress. Data collection begins the moment you set up a widget. To get started, you can: Build custom views: Add up to five unique trend lines per widget, tailoring the dataset, entity type, and filters for each. Deploy pre-built charts: Search trending in the widget library to drop ready-to-use visualizations right onto your dashboard. Check out the Trending Widget documentation Release notes for the full details Tenable One Cloud Exposure Expanded Kubernetes and container topology in Tenable One Cloud Exposure A comprehensive overview of Kubernetes and container topology is essential for risk-based prioritization because you have to see the whole picture of the resources, workloads, and clusters a vulnerability touches to know what’s actually risky. Now, the “graph” tab in Tenable One Cloud Exposure gives you the full structural layout of a Kubernetes cluster, all the way down to a vulnerable container image, in one interactive view. What’s new: Guided relationship picker: By expanding any node in the graph, it now surfaces a categorized menu (Compute, IAM, Kubernetes, Containers, Management, Network, Risk) so you can choose which connection to explore next. Full Kubernetes depth: Namespaces, roles, role bindings, service accounts, configuration maps, and workloads all surface as first-class nodes, whether the cluster is EKS, AKS, GKE, or self-managed. The Kubernetes graph provides a holistic view of cluster contents, namespaces, and resource relationships, while allowing you to effortlessly navigate from clusters to underlying virtual machines and specific workloads, such as business-critical services. It also enables you to explore vulnerability instances linked to container images, ensuring they have complete context for risk prioritization and informed decision-making. View the demo Check out the product documentation Tenable Nessus Nessus reliability and performance updates We have released several Tenable Nessus updates recently, with a mix of new capabilities as well as improvements related to performance and security. Scanner reliability fixes: Resolved SSL connection issues that could cause scanners to appear offline and stop receiving plugin updates. Kerberos authentication fix: Corrected an issue blocking plugins from retrieving host FQDNs, causing authentication failures. Tenable Security Center performance: Fixed timeout errors when processing large volumes of Tenable Nessus agent reports. Certificate handling: Resolved an issue in PostgreSQL client authentication. Review Nessus documentation Read the Plugin Release Notes Take Tenable University training Training and product education Tenable Patch Management training Upgrade your skills with the refreshed, free on-demand Introduction to Tenable Patch Management course in Tenable University. Modernized with interactive elements, real-time knowledge checks, and step-by-step video demonstrations, this self-paced web training gives you hands-on practice to efficiently secure both your SaaS and on-premises environments. Through this updated course, you will learn to: Understand core architecture: Master essential server and client components, operating system coverage, and fundamental patching logic. Optimize configuration and strategy: Configure locations and business units while implementing proven patching strategies across your enterprise. Execute global operations: Swiftly respond to critical threats using the Emergency Kit. Eliminate blind spots: Monitor real-time compliance health and identify hidden vulnerabilities using dynamic performance widgets and interactive dashboards. Access this free course today in Tenable University to strengthen your remediation workflows and keep your organization secure. Learn more Tenable events and webinars Customer office hours Customer office hours are recurring ask-me-anything sessions for Tenable Security Center, Tenable One Vulnerability Management, Tenable One Cloud Exposure, Tenable One Identity Exposure, and Tenable One OT Exposure. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa), and Asia-Pacific. Learn more and register Virtual events Tenable customer update - October 2026: Join the next quarterly customer update session at 11 a.m. ET / 4 p.m. BST / 5 p.m. CEST Oct. 20. This informative, fast-paced overview will explore how to better secure your expanding attack surface and consolidate critical security data. Products covered include Tenable One, Tenable One Vulnerability Management, Tenable Security Center, and Tenable Patch Management. Register here See all upcoming live and on-demand webinars TenableTalk Live: How Mythos will change cyber defenses forever: Join us at 11 a.m. ET, Thursday, Sept. 24, on LinkedIn as we dive into what happens when frontier AI reasoning gets built directly into the tools defenders use, and how teams can prepare for these new capabilities. Attend on LinkedIn Tenable Professional Services Tenable Hexa AI enablement workshop Confidently adopt Tenable Hexa AI and the Tenable Hexa AI Model Context Protocol (MCP) Server with expert, hands-on guidance tailored to your environment. Delivered by Tenable Professional Services as a custom Statement of Work (SOW) engagement, this new workshop equips your team with practical skills to maximize your AI-driven exposure management capabilities. Through this custom engagement, you will: Explore enterprise AI capabilities: Analyze your internal AI tool usage and complete a technical overview of Tenable Hexa AI. Build practical expertise: Receive hands-on instruction to effectively operate Tenable Hexa AI and integrate the Tenable MCP Server into your tech stack. Design custom workflows: Develop tailored operational workflows and implement proven best practices to accelerate risk reduction. To scope a custom workshop for your organization, contact your Tenable representative or email [email protected]. Read Tenable documentation.653Views0likes0CommentsTenable product update: Standardizing Tenable risk scoring
At Tenable, we are committed to providing the most accurate, defensible, and actionable view of organizational risk. To achieve this, we must continually refine the intelligence that powers your prioritization. On July 1, 2026, we are implementing a series of foundational updates to our risk scoring engines. As part of this update, you may see changes to your risk scores, depending on the Tenable product(s) you own. These changes simplify your workflow by standardizing scoring on a single, high-fidelity model for vulnerability and asset risk. The new standard for VPR For the past several months, many of you have utilized VPR (Beta) to gain deeper insights into exploitability. We are excited to announce that on July 1, this model will be promoted to the primary Vulnerability Priority Rating (VPR) across the Tenable platform. By standardizing on this advanced model, we are retiring legacy VPR scoring to ensure every customer benefits from our most sophisticated threat intelligence. The new version of VPR incorporates more threat intelligence and vulnerability metadata so that you can focus on the 1.6% of vulnerabilities that actually matter. Better context through enhanced asset classification Alongside the VPR update, we are enhancing our asset classification engine. This update improves how we identify the function and importance of assets across your entire attack surface, including Cloud, OT, and third-party devices. As a result, customers with access to Asset Criticality Ratings (ACR) for VM assets will see these scores more accurately reflect real-world business risk. What this means for you These are backend enhancements designed to provide immediate value with zero manual configuration. On July 1, your dashboards, reports, and APIs will automatically reflect these updated metrics. Because both VPR and ACR serve as inputs to Cyber Exposure Score (CES) and Asset Exposure Score (AES), customers using these scores may see changes that reflect a more accurate understanding of exposure. Customer FAQ What happens to the VPR (Beta) score in the Tenable UI? The Beta label will be removed. The high-fidelity model you’ve been previewing will become the standard VPR. The legacy version of VPR will be retired to ensure a single, unified source or truth. Do I need to rewrite my custom API scripts using VPR? No. For customers using APIs, updated values will be mapped into legacy VPR fields on the back end to ensure compatibility and a smooth transition for your scripts and third-party tools. How does this affect my SLAs? Because many organizations use VPR as their operational prioritization layer, your SLA statistics and remediation tracking will now reflect the more precise scoring model. This helps ensure your team is meeting response goals for the vulnerabilities that pose the highest actual risk. How does Enhanced Asset Classification affect my scores? The system now automatically identifies the function and criticality of assets across Cloud, OT, and third-party sources. This improved context leads to more accurate Asset Criticality Rating (ACR) adjustments. For customers with access to ACR, this ensures your most critical business assets are effectively prioritized. What actions does my team need to take, and when will the changes be reflected in my container? These updates will occur automatically within your Tenable console. Depending on the size of your environment, it may take time for score recalculations to be fully reflected across your console. For a detailed guide on our enhanced VPR, check out this FAQ. Want to see the why behind our scoring? View our scoring explained.6.9KViews9likes13CommentsArcon Converged Identity (CI) Platform
Summary Tenable One Vulnerability Management and Tenable Security Center now fully support the Arcon Converged Identity (CI) PAM solution. Using the existing Arcon PAM authentication type alongside Digital Vault API configuration, customers with Arcon CI-PAM can seamlessly retrieve credentials during scans. Change No new scan configuration fields or credential types are required. Customers using Arcon CI-PAM should configure the Authentication URL and Engine URL to point to the Digital Vault API base path (e.g. dv/api/sdk), as with Arcon DV deployments. Impact No changes to existing scan configurations are required. Customers currently using the legacy Arcon PAM API path are unaffected. Release Date 8 September 2026 for Tenable One Vulnerability Management, Nessus and Tenable Security CenterVMware Integration vSphere 9.0 Compatibility
Summary We are pleased to announce that Tenable's VMware integration for vulnerability scanning now supports VMware vSphere 9.0 (ESXi 9.0 and vCenter Server 9.0). These updates will be available in Tenable Vulnerability Management, Nessus, and Tenable Security Center. Change Tenable has updated its VMware integration to support VMware ESXi 9.0 and VMware vCenter Server 9.0. Authenticated vulnerability scans can now be performed on these targets without the need for additional credential setup. VMware vSphere 9.0 compatibility covers the following scenarios: VMware ESX SOAP API authenticated scans against ESXi 9.0 hosts VMware vCenter API authenticated scans against vCenter Server 9.0 VMware vCenter auto-discovery flows for 9.0 hosts For more information see our user documentation: Welcome to Tenable for VMware Impact No impact to current scans are expected; existing ESXi 8.x and earlier vCenter scans continue to work as before. If customers encounter issues with this integration, please open a ticket with Technical Support. Tenable will engage with VMware as needed to identify and resolve any issues. Release Date Available Immediately (May 27, 2026) for Tenable Vulnerability Management, Nessus, and Tenable Security Center Note: TDB for updates to enable VMware ESXi 9.0 and VMware vCenter Server 9.0 compatibility with Compliance and Audit scanning.Tenable Product Update Newsletter — August 2026
Welcome to your monthly round-up of the latest Tenable product updates, platform enhancements, and community news. This month, we’re focused on agentic automation, quantum-readiness, and sharper visibility across your attack surface. Tenable One Platform Updates Tenable Hexa AI now supports Routines and Agent Center in Tenable One Introducing the next major evolution in agentic security: an always-on workforce powered by Tenable Hexa AI Routines, Agent Center, and a new Jamf integration directly within the Tenable One platform. Moving past conversational search and one-off actions, mobilize an autonomous fleet that runs in the background to seamlessly coordinate multi-step security tasks across your entire exposure landscape. Routines: Define an exposure workflow once and set a schedule. Hexa reasons through fresh context on every run and automatically delivers actionable results. Agent Center: A central workspace to track all routines to get clear visibility into what’s running, completed, queued, or awaiting user input. Jamf integration: Fetch Jamf-managed Mac context on demand and push patch policies directly back to Jamf without ever leaving Tenable One. Available now. Get started by navigating to Agent Center > Create a Routine or the Routines tab in Hexa AI. Get more details in the release notes CyberAgents Exchange CyberAgents Exchange and SWARM event recap The CyberAgents Exchange, powered by Tenable, is an open-source, vendor-agnostic hub where security practitioners and CISOs can discover, share, and collaborate on AI agents, skills, MCP servers, and playbooks built for cybersecurity. This free-to-use community infrastructure allows defenders to scale their capabilities, eliminate development silos, and outpace AI-generated threats without vendor lock-in. In conjunction with the CyberAgents Exchange launch, Tenable hosted SWARM, a hands-on cybersecurity agentic AI build event at Black Hat USA 2026 in Las Vegas. Real-world solutions: Sponsored by AWS and presented with support from Anthropic, the event challenged security practitioners to build open-source components that automate real-world security workflows. Winners: Congratulations to our first-, second-, and third-place winning teams! Your incredible builds are now on the CyberAgents Exchange for the global security community to adopt and build upon. Explore the CyberAgents Exchange today, and check out our official press release and SWARM recap blog post for complete details. Explore the CyberAgents Exchange Read the SWARM recap blog Read the press release Tenable One Vulnerability Management Accelerate software discovery and compliance reporting in Explore Seamlessly track software inventory and isolate compliance checks directly within Tenable One Vulnerability Management. The new Software and Host Audit tabs in Explore deliver dedicated views to eliminate UI clutter, track deployed application footprints, and speed up audit reporting. Use these views to: Pinpoint software exposure: Search installed software, versions, and vendors alongside risk metrics like ACR and AES to maximize SBOM value. Isolate compliance findings: Separate CIS benchmark and hardening checks from general vulnerability noise without building complex filters. Export audit evidence: Instantly group and export targeted software inventories or configuration results for internal teams and external auditors. Read the full post on Tenable Connect Tenable One AI Exposure Now covering all major AI platforms and developer tools AI adoption is outpacing most teams’ ability to govern it, and every new LLM, agent, or IDE plugin adds another blind spot to the attack surface. Tenable One AI Exposure closes that gap further, adding support for Google Gemini and extending coverage across the tools where AI actually gets used inside your environment. Expanded coverage and capabilities include: Full LLM coverage: Monitor prompts, responses, and usage patterns across Google Gemini, Anthropic Claude, OpenAI ChatGPT Enterprise, and Microsoft Copilot, with policy enforcement and detection of risky or unauthorized activity. Broader shadow AI visibility: Discover sanctioned and unsanctioned AI use across Model Context Protocol (MCP) deployments, AI-native IDEs like Cursor, Windsurf, and Trae, and AI-enabled browser extensions. Faster remediation workflows: Route policy violations straight into Jira or ServiceNow, or trigger automated alerts over email, Slack, or Teams, so issues get worked instead of just logged. Read the Tenable One AI Exposure press release Tenable One Cloud Exposure Identify non-compliant post-quantum cryptography cloud resources Encrypted traffic captured today can be stored and decrypted later, once quantum computing matures, a threat known as harvest-now-decrypt-later (HNDL). Organizations relying on outdated Transport Layer Security (TLS) configurations or non-quantum-safe encryption are exposed to this risk without even knowing it. Tenable One Cloud Exposure now helps customers identify non-compliant post-quantum cryptography (PQC) cloud resources to support future compliance regulations. We’ve added four new properties to the Network Endpoint profile for HTTPS-supported endpoints. The enhancement allows teams to: Get visibility into quantum readiness: See which endpoints already support post-quantum cryptography and which don’t, so you can prioritize upgrades ahead of emerging compliance mandates. Get all non-PQC-compliant resources listed in one query. Identify weak encryption faster: Surface outdated TLS versions and vulnerable cipher suites across your environment without manual audits or separate scanning tools. Reduce HNDL exposure: Proactively harden key exchange methods and ciphers before intercepted traffic becomes a future liability. Gain compliance evidence: Customers in regulated industries, such as healthcare and financial services, can easily prove compliance as quantum computing matures. To find these resources in your cloud environment, go to Tenable One Cloud Exposure and filter or query “non-ready PQC resources” using the Network Endpoint page or Explorer. Check out other recent releases in the product documentation Tenable One OT Exposure Deeper IT/OT visibility for every corner of your environment Our latest release of Tenable One OT Exposure 4.7 expands visibility for grid operators and disconnected environments, and introduces a variety of productivity enhancements. OT agents for isolated networks: Get asset visibility and vulnerability coverage in air-gapped and disconnected environments (no sensors or live connectivity required) with offline scan profiles and a local agent UI for field technicians. Power substation anomaly detection: Passively monitors GOOSE streams and flags anomalous activity, such as configuration revision changes, giving utilities and grid operators critical visibility. Yokogawa DCS activity detection: Surfaces critical operational changes on Yokogawa Centum VP systems, so you can spot engineering activity that may signal unauthorized access. Centralized subnet management: Define CIDR boundaries and toggle monitoring across all ICPs from a single interface in Enterprise Manager, eliminating per-site configuration. Saved Views: Save, name, and reuse custom filter combinations across asset and findings views, cutting down repetitive setup during investigations. Asset side panel: Review asset details without leaving the findings or asset grid, for faster pivoting during investigations. Upgrade today to put these new capabilities to work in your environment. Explore the release notes Tenable Security Center Sharper visibility, streamlined operations The latest release of Tenable Security Center 6.9 brings several upgrades to help you accelerate your self-hosted vulnerability management program. Updated vulnerability findings interface: Rich filtering options (severity, asset, plugin, IP-based) and surfaced Vulnerability Priority Rating (VPR) insights help you zero in on what matters most, faster. Tenable Nessus scanner support via Sensor Proxy: Link Tenable Nessus scanners through the Sensor Proxy service for more flexible deployments and horizontal scaling across large enterprise and Tenable Enclave Security environments. Windows LAPS credential support: Dynamic credential retrieval from Active Directory (AD) strengthens scan security and reduces the admin burden of credential management. Expanded PAM Kerberos authentication: Support across BeyondTrust, Delinea, and CyberArk integrations gives you tighter credential control. One-click diagnostic bundle upload: Submit diagnostic files directly to Tenable Support from within your console, so we can resolve your cases faster. (Requires a valid Tenable Nessus feed license. Not supported in air-gapped environments.) Trending data moves to PostgreSQL: A lighter disk footprint and better performance for your trend reporting. Explore the release notes Tenable Nessus Stability fixes and continued security hardening with the latest Tenable Nessus releases Tenable Nessus 10.12.2 and 10.12.3 are now available, resolving a scanner connectivity issue and rounding out a batch of stability fixes: Your scanners stay online and up to date: We’ve addressed a bug where scanners could drop offline and stop receiving plugin updates after an upgrade, so you get consistent scan coverage without needing to manually check scanner status. Fewer stuck or incomplete agent scans: Cluster-based agent scans will finish reliably, so you will not need to re-run them. More accurate reporting on linked agents: You can always trust what you see in the console (requires Tenable Agent 11.2.0 or later). Want to see Tenable Nessus in action or level up your team’s skills? View a Tenable Nessus demo or purchase our on-demand training course. What these updates mean for you: If you were experiencing scanners going offline or missing plugin updates, updating to 10.12.3 will solve it. Tenable Agent customers should update to v11.2.0 or later to get the linked-agent plugin reporting fix. Review the release notes Tenable Nessus Professional data sheet Tenable Nessus Expert data sheet Tenable Patch Management Instant patch verification and expanded Linux support This latest update focuses on saving you time and verifying your fixes faster. Instantly verify patches: Automatically trigger a Nessus Agent scan the moment a patch finishes installing. You get immediate proof of CVE remediation without waiting for your next scheduled scan window. Natively patch EPEL packages: Update community-maintained add-on software across your Enterprise Linux distributions on the exact same schedule as your core OS, eliminating the need for custom scripts. Stronger security and faster performance: Benefit from upgraded AES-GCM encryption, easier TLS certificate management directly from your console, faster dashboard load times, and fixes that keep your maintenance windows accurate to prevent unwanted reboots. Read the full details on Tenable Connect Training and Product Education Tenable One Cloud Exposure Specialist Training refreshed in Tenable University The instructor-led Tenable One Cloud Exposure Specialist product training in Tenable University is rebuilt with modernized content and hands-on lab exercises. All labs and course content now reflect the latest user interface and recent feature releases. Learn more Buy instructor-led training Tenable Events and Webinars Virtual events Tenable customer update, July 2026: Watch the most recent quarterly customer update session. This informative, fast-paced overview explores how to better secure your expanding attack surface and consolidate critical security data. Products covered include Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, and Tenable Security Center. Watch the July customer update Live from SWARM: An announcement to shift the future of agentic AI security. Watch the replay of a special 15-minute session streaming directly from SWARM, our exclusive agentic AI build event at Black Hat USA 2026. The session dives into the realities of AI-augmented exposure management and a special announcement that will change how the infosec community collaborates on AI security. Watch on LinkedIn --- Read Tenable documentation.805Views1like0CommentsIntroducing Tenable Security Center 6.9.0
We're excited to announce that Tenable Security Center 6.9.0 is now globally available. This release delivers a modernized vulnerability findings UI, expanded scanning flexibility, and stronger security foundations — built on feedback from our customer community. What's new? Explore Findings — A modernized vulnerability query interface with expanded filtering (severity, asset, plugin, IP-based) and VPR key driver fields right in the findings detail panel. The legacy Analysis view is still available alongside it. Nessus Scanners via Sensor Proxy — Link Tenable Nessus scanners through the Sensor Proxy service for more flexible deployments and horizontal scaling in large enterprise and Tenable Enclave Security environments. Diagnostic Bundle Auto-Upload — Submit Security Center diagnostic files straight to Tenable Support from the console — no more manual download/re-upload. (Requires a valid Tenable Nessus feed license; not supported in air-gapped environments.) Windows LAPS Credential Support — Scan credentials can now be retrieved dynamically from Active Directory via Windows Local Administrator Password Solution. PAM Kerberos Target Authentication — Kerberos Target Authentication is now supported for Windows and SSH credentials across integrations including BeyondTrust Password Safe, Delinea Secret Server, and CyberArk. FIPS 140-3 — SC 6.9.0 integrates OpenSSL 3.5 with the FIPS provider, moving toward full FIPS 140-3 compliance (currently undergoing NIST validation). Other notable enhancements Trending Data Migration to PostgreSQL — Trending data now lives in PostgreSQL instead of legacy file storage, reducing disk usage and paving the way for expanded trending capabilities. Existing trend data carries over automatically. Note: trend charts modified/created on 6.9.0+ will start their trend history from the edit/creation date. Freeze Window Rollover Scan Control — New option to suppress automatic rollover scan creation during freeze windows, preventing backlog buildup after large maintenance windows. Section 508 Accessibility — Improvements to screen reader support and keyboard navigation. Overall performance and stability improvements, plus 60+ customer-reported bug fixes. Upgrade considerations Upgrades are supported from Security Center version 6.5 and above. This release includes [R1] Security Center Version 6.9.0 Fixes Multiple Vulnerabilities. 8GB RAM is now a requirement — upgrades/installs will not proceed below this. Upgrade time from version 6.7+ depends heavily on the number of trending charts in your Reports; consoles with hundreds/thousands of trend components may take several hours. Running the RPM installer from a separate /tmp partition requires 10GB free space. Resources Release notes User guides Download Tenable Security Center 6.9.0 Have a question? Leave a comment below or contact your Tenable representative.945Views0likes0Comments[GA Release] Tenable App for Splunk v6.1.1 and Tenable Add-on for Splunk v8.0.3 Now Live!
Hi everyone! Tenable App for Splunk v6.1.1 and Tenable Add-on for Splunk v8.0.3 are officially GA and available now on Splunkbase! Release Date: July 27, 2026 Download: Tenable App for Splunk on Splunkbase Tenable Add-on for Splunk on Splunkbase Docs & User Guide: Tenable App for Splunk Documentation Tenable Add-on for Splunk Documentation What’s New? Bumped the minimum required Python version to 3.13 as per Splunk standards. Compatibility Matrix: Browser: Google Chrome, Mozilla Firefox OS: Platform Independent Splunk Enterprise version: 10.2.x, 10.0.x, 9.4.x and 9.3.x Supported Splunk Deployment: Splunk Cluster, Splunk Standalone, and Distributed Deployment Questions or Feedback? If you have feedback or questions, we’d love to hear from you! - Tenable Ecosystem Product Management102Views0likes0CommentsTenable Product Update Newsletter — July 2026
Check out our July newsletter to learn about the latest product and research updates, events, and educational content. Plus, this month we’re featuring the launch of the CyberAgents Exchange, powered by Tenable. Keep reading to read more about the new open-source AI exchange! Tenable One - Platform updates Integrate application security data into Tenable One for code-to-runtime security Your codebase is growing faster than your security program, and in the age of AI, developers are introducing security findings at 10 times the rate of their peers. It is critical to see code as part of your entire attack surface. Application security data now integrates directly into Tenable One to further close visibility gaps and ensure secure code development in the AI era. Whether code is human- or machine-written, you can now integrate application security risks, like those from Snyk, Claude Security, or any other application security tool via Tenable One Connectors — directly alongside your existing exposure data. What this means for you: Achieve full code-to-runtime visibility by bringing application security risks together with the rest of your exposure data in one place. Fix code flaws before they become incidents by identifying your most business-critical code flaws and fixing them early in the development lifecycle. Measure organizational exposure and transform technical static code vulnerabilities into clear risk metrics on business resilience. Read the blog post Explore the guided demo Check out Open Connector documentation and Snyk Connector documentation Improved workflow orchestration capabilities in Tenable One Vulnerability Management and Tenable One New enhancements to Tenable's workflow orchestration capabilities are now generally available. This release streamlines remediation workflows and improves operational efficiency with the following key updates: Plugin output in tickets: You can now attach Plugin Output directly to tickets, providing immediate context and critical information while eliminating the need for further navigation. Tenable Hexa AI for ServiceNow: You can now leverage Tenable Hexa AI for ServiceNow incident and initiative creation to match already available Jira functionality. Review the exposure management release notes Review the Tenable Vulnerability Management release notes Tenable unified scoring is now live Tenable has unified its risk prioritization standard, moving the high-fidelity Vulnerability Priority Rating (VPR) model out of beta to become the sole standard. To sharpen your prioritization, an updated asset classification engine also delivers more accurate Asset Criticality Ratings (ACR) for your assets. Because VPR and ACR feed directly into your Cyber Exposure Score (CES) and Asset Exposure Score (AES), your console will automatically update to reflect a precise understanding of your exposure. These recalculations occur automatically, though completion times depend on the size of your environment. To prevent errors in your saved views, you must manually update any filters or combinations that still use VPR v1. No data migration is required. Visit Tenable Connect for more details Learn more about Tenable One scoring The CyberAgents Exchange, powered by Tenable Tenable launches the industry’s first open-source AI exchange (and we want your agents on it) Security teams are building AI agents in isolation, reinventing the wheel with no neutral place to share what actually works. The CyberAgents Exchange, powered by Tenable, is the only purpose-built, cybersecurity-native registry for AI agents, skills, MCP servers, and multi-agent playbooks in the current market. Built by defenders. For defenders: Purpose-built for security teams to solve the exposure problems practitioners actually face. Collective defense for the agentic era: Anyone can contribute; everyone benefits. Agents and skills are shared under open licenses with no fees or gates. Trust through transparency: Every agent links directly to its source repository, so there are no bundled binaries or black boxes. Build your reputation. Elevate your craft: Contributing is career capital. We give practitioners a platform to earn validation and build an undeniable resume. Join the community, build your reputation, and start automating risk reduction. Explore the directory and submit your builds Tenable One Cloud Exposure Tenable One Cloud Exposure achieves FedRAMP High authorization Tenable is committed to being the trusted partner of choice for the public sector, providing the advanced protection required for the U.S. government’s most sensitive environments. We are proud to announce that Tenable One Cloud Exposure has achieved FedRAMP High and Impact Level 5 (IL5) authorization. Purpose-built for sensitive government cloud environments, this high-level authorization delivers: Unified visibility: Gain a single view across infrastructure, identities, and workloads — even in air-gapped environments. Zero-trust enforcement: Leverage advanced identity analytics to enforce least privilege principles and align with DoW CIO mandates. Blast radius reduction: Map the Web of Risk to see how vulnerabilities connect to identities and sensitive data, stopping problems before they snowball. Cost reduction: Support fiscal modernization by eliminating tool sprawl and reducing costs without compromising security. Read the press release Learn more about our FedRAMP High solutions Take control of your sensitive data When data classification engines scan the cloud, they often flag false positives, like internal test data, mock databases, or benign corporate email domains, as critical risks. With Tenable’s new data classification exclusions, customers can fine-tune their data scans to get to the bottom of what’s actually sensitive. Exclude by resource scope: Narrow exclusions to specific data types or resources using user-friendly Explorer-based queries. Exclude specific values: Filter out known text patterns or regex strings (like internal email domains). Target precise locations: Use OR logic to pinpoint exact databases, schemas, tables, file extensions, or object paths. Learn how to create a data classification exclusion Read about the recent releases here Tenable One Web App Scanning Authenticate web app scans with OAuth 2.0 You can now scan protected applications and APIs using OAuth 2.0 authentication within Tenable One Web App Scanning. Configure these options under your scan credential settings using three supported flows: Authorization code: For user-driven logins, with optional PKCE and Selenium scripting for complex identity providers. Client credentials: For machine-to-machine API scans without user interaction. Device code: For headless and device-style authentication. To prevent scans from silently losing access, authorization verification continuously validates your session via response patterns, headers, or HTTP status codes across all credential types. Integrate these capabilities immediately through your existing credentials API without changing endpoints. You can call the List Credential Types endpoint to programmatically discover the new fields. Review the documentation Review the release notes Tenable One OT Exposure Extended OT visibility for grid operators and disconnected environments Our latest Tenable One OT Exposure release expands visibility for grid operators and disconnected environments, and introduces productivity and performance enhancements to accelerate analyst workflows. OT agent for disconnected environments: Secure air-gapped and isolated networks without deploying sensors or requiring live connectivity, featuring offline scan profiles, a local agent interface tailored for field technicians, and centralized Network Areas to resolve duplicate IP conflicts across distributed sites. Power substation anomaly detection: Passively monitor GOOSE streams and alert on anomalous activity (e.g., code revision changes) to protect utility and grid operations from unauthorized modifications or replay attacks. Yokogawa DCS activity detection: Get deep visibility into engineering activities on Yokogawa Centum VP systems to detect changes to critical operations and unauthorized access, including controller start/stop, code edits, function block changes, tag writes/deletes, and more. Simplified enterprise management: Manage all ICP subnets from a single Enterprise Manager interface — define CIDR boundaries, toggle monitoring per-site, and eliminate the need for per-ICP configuration for monitoring different network areas. Analyst workflow improvements: Reuse investigations with Saved Views, review Assets and Findings details faster with a quick-access side panel, and secure syslog transport with TLS support. Explore the user guide Review the release notes Tenable Security Center Reimagined vulnerability analysis, flexible deployment, and streamlined operations Tenable Security Center 6.9, now available in early access, modernizes vulnerability analysis and expands enterprise deployment flexibility with a reimagined query experience and deeper PAM and credential integrations. Explore Findings: A redesigned vulnerability query interface with expanded filtering and VPR key drivers surfaced directly in the findings detail panel. Tenable Nessus scanners via Tenable Sensor Proxy: Deploy Tenable Nessus scanners through Tenable Sensor Proxy for flexible, scalable enterprise and Tenable Enclave Security environments. Windows LAPS and PAM Kerberos support: Dynamically retrieve scan credentials via Windows LAPS and Kerberos Target Authentication across all supported PAM integrations. Performance improvements: Submit diagnostic bundles directly to Tenable Support, suppress rollover scans during freeze windows, and benefit from a modernized data architecture that reduces disk usage. Explore the user guide Download the early access release Tenable Ecosystem Now available: PyTenable 26.6.1 PyTenable 26.6.1 has officially been released, introducing a new temporal versioning scheme (YEAR.MONTH.PATCH) to better align with rapid API changes and enable critical updates to older modules. Marshmallow v4 support: Resolved issues preventing the use of newer Marshmallow versions. APA export: Added support in the current Tenable One package. Streamlined testing: Refactored workflow processes mean you no longer need Act and Docker installed just to run the test suite. Bug fixes: Addressed various minor issues introduced by recent API changes. Moving forward, support will be provided for the current month minus three releases, so we highly recommend pinning your software to a specific release and testing against the latest. Visit the PyTenable GitHub repository Training and product education Tenable One Exposure Management Platform introduction course includes CTEM This introductory course in Tenable University now incorporates the foundations of the Continuous Threat Exposure Management (CTEM) framework to identify exposures, prioritize remediations, and reduce risk across your modern attack surface. Practitioners and partners will learn the fundamentals of continuous hybrid asset discovery, risk-based scoring, and validating critical attack paths to effectively manage security posture. This no-cost course serves as the essential primer and recommended prerequisite for the Specialist tier. Access the course on demand in Tenable University On-demand Tenable One Exposure Management Platform Specialist course now available This brand-new paid Tenable University training course provides comprehensive Continuous Threat Exposure Management (CTEM) lifecycle training across the entire Tenable One architecture. The Specialist-level course delivers deep technical coverage of the Tenable One Exposure Management Platform, including: Tenable One Vulnerability Management Tenable One Attack Surface Management Tenable One Identity Exposure Tenable One OT Exposure Tenable One Cloud Exposure Tenable One Web App Scanning Practitioners will gain proficiency in third-party data integration, advanced asset tagging, and context-aware analytics (such as Attack Path Analysis and Exposure Signals) to drive risk-based prioritization and deliver actionable executive dashboards. Eligible for Continuing Education (CE) credit. Learn more and purchase online Tenable events and webinars Customer office hours These are recurring ask-me-anything sessions for Tenable Security Center, Tenable One Vulnerability Management, Tenable One Cloud Exposure, Tenable One Identity Exposure, and Tenable One OT Exposure. Time-zone-appropriate sessions are available for the Americas, Europe (including the Middle East and Africa), and Asia-Pacific (APAC). Learn more and register Virtual events Now on demand — Tenable customer update, July 2026: Watch the most recent quarterly customer update session. This informative, fast-paced overview explores how to better secure your expanding attack surface and consolidate critical security data. Products covered include: Tenable One, Tenable One AI Exposure, Tenable One Vulnerability Management, and Tenable Security Center. Watch on demand See all upcoming live and on-demand webinars Read Tenable documentation.677Views2likes0CommentsResearch Release Highlight – "Fully Scan Operational Technology" Default Setting Change
Summary The "Fully Scan Operational Technology" (OT) preference controls whether Nessus actively scans OT/ICS devices during a scan. This setting is intended to be disabled by default to avoid unintended disruption to sensitive operational technology environments. A long-standing setting in the Do not scan operational technology devices plugin caused this preference to default to enabled in a Basic Network Scan when the discovery type is not set to Custom. Change The default value for "Fully Scan Operational Technology" preference has been corrected from yes to no. Impact This fix will affect existing Basic Network scans automatically upon the next feed update — no scan recreation is required. Customers using Basic Network Scan policies with a non-custom discovery scan type will see the following behavioral change: Before change: "Fully Scan Operational Technology" was silently enabled, meaning OT devices may have been actively scanned. After change: "Fully Scan Operational Technology" will correctly default to disabled. Customers who intentionally want to scan OT devices should explicitly enable the "Fully Scan Operational Technology" preference by switching their scan policy's discovery type to Custom, which will expose the preference in the UI and allow it to be toggled on. Affected products: Tenable Security Center (SC), Tenable Vulnerability Management (TVM), and Nessus Target Release Date July 13, 2026