User Profile
astranahan
Product Team
Joined 6 years ago
User Widgets
Contributions
Research Release Highlight - VMware ESXi 7.0 SEoL Update
Summary Tenable is updating the VMware ESX / ESXi Unsupported Version Detection plugin (56997) to track the vendor's End of General Support (EoGS) date rather than the End of Technical Guidance (EoTG) date. Change Before this update, Plugin 56997 determined unsupported status for VMware vSphere/ESXi 7.0 using the vendor's End of Technical Guidance (EoTG) date of April 2, 2027. EoTG marks the point at which the vendor's support becomes best-effort only; it does not reflect when the vendor actually stops shipping security patches. After this update, Plugin 56997 will use the vendor's End of General Support (EoGS) date instead, which is when the vendor discontinues security patches and critical bug fixes. This date for VMware vSphere/ESXi 7.0 EoGS is October 2, 2025. Impact Customers running VMware vSphere/ESXi 7.0 outside of the EoGS support window will now see a correct “unsupported” finding from Plugin 56997. This will introduce new critical findings into scan results for customers who have the unsupported version. Hosts that had previously been identified as unsupported should see no change to those findings. Detection plugins 56997 - VMware ESX / ESXi Unsupported Version Detection Target Release Date November 2, 2026Research Release Highlight – "Fully Scan Operational Technology" Default Setting Change
Summary The "Fully Scan Operational Technology" (OT) preference controls whether Nessus actively scans OT/ICS devices during a scan. This setting is intended to be disabled by default to avoid unintended disruption to sensitive operational technology environments. A long-standing setting in the Do not scan operational technology devices plugin caused this preference to default to enabled in a Basic Network Scan when the discovery type is not set to Custom. Change The default value for "Fully Scan Operational Technology" preference has been corrected from yes to no. Impact This fix will affect existing Basic Network scans automatically upon the next feed update — no scan recreation is required. Customers using Basic Network Scan policies with a non-custom discovery scan type will see the following behavioral change: Before change: "Fully Scan Operational Technology" was silently enabled, meaning OT devices may have been actively scanned. After change: "Fully Scan Operational Technology" will correctly default to disabled. Customers who intentionally want to scan OT devices should explicitly enable the "Fully Scan Operational Technology" preference by switching their scan policy's discovery type to Custom, which will expose the preference in the UI and allow it to be toggled on. Affected products: Tenable Security Center (SC), Tenable Vulnerability Management (TVM), and Nessus Target Release Date July 13, 2026Release Highlight - Large Differential Feed Update Notification
Summary Due to integration of new binaries into the plugin feed, there will be a larger than normal differential plugin feed update. Potential Impacts: The addition of the binaries is expected to add approximately 37MB of new content to the plugin feed. The impact is expected to be minimal for Nessus customers. SC customers will see the biggest impact of approximately 230MB due to how the differential feed updates are built. The differential update does not apply to Nessus agents as the binaries were not added there. For Tenable Security Center customers, you can configure the plugins to update on a schedule or switch to manual updates for an optimal time window. Target Release Date March 4, 2026Tenable Post-Quantum Cryptography Inventory Support
Summary The advent of quantum computing presents a significant threat to current cryptographic algorithms. Organizations worldwide are beginning the critical transition to post-quantum cryptography (PQC) resistant algorithms to ensure long-term data security. Government mandates, such as the U.S. National Security Memorandum 10 (NSM-10), outlines deadlines for PQC migration and specific actions agencies must take to migrate vulnerable systems. Our PQC support is designed to help customers inventory use of TLS and SSH quantum-resistant and vulnerable algorithms within their infrastructure using remote Nessus-based scans. Cipher Inventory and Reporting Post-Quantum Cipher Plugins Two remote-based scan informational reporting plugins for TLS and SSH protocols inform customers of their transition posture according to NIST Post-Quantum Encryption Standards. Services Using Post Quantum Cryptography: Reports on services equipped with at least one post-quantum cipher. It will specify which post-quantum ciphers were discovered, reporting by port and protocol. Services Not Using Post Quantum Cryptography: Reports on services that support no post-quantum ciphers. These plugins will be enabled by default and included in existing scans. Cryptographic Inventory Plugin Reporting To enable a JSON-based inventory of each target by service and cipher, enable through either a preference on your Advanced Network Scan or by running the Cryptographic Inventory scan template. These preferences will initially be supported in Nessus and Tenable Vulnerability Management. They are planned to be added to Tenable Security Center at a later date. Warning: Enabling this preference through the Advanced Network Scan is expected to increase the overall size of the plugin output per target and resulting Nessus database size. If you do not need to produce this inventory at all or on your regular scan cadence, it’s recommended to instead run the Cryptographic Inventory scan template to decrease the potential impact to your normal scan results. Options to Enable Inventory Reporting Advanced Scan Preference Post Quantum Cryptography Scan Template Cryptographic Inventory Plugin Details The plugin enabled with the preference or scan template is an information plugin called Target Cipher Inventory. Within the output of this plugin, you will find a JSON structure containing the TLS and SSH inventories for the scanned target. You can export this inventory based on plugin output using the Tenable API if needed. For TLS, the structure contains: Attribute Definition Encaps Protocol encapsulation employed such as TLSv1, TLSv2, TLSv3 Port Port used for TLS communication Curve Group Encryption method Ciphersuite Algorithm used to secure the TLS connection For SSH, the structure contains: Attribute Definition Proto Protocol of SSH Port Port used for SSH communication Name Algorithm used to secure the protocol Type Use of the named algorithm such as “message auth” Release Date Tenable Vulnerability Management and Tenable Nessus: December 8, 2025 Tenable Security Center: - December 8, 2025 for the informational plugins - Cryptographic Inventory scan template release to be determinedAzure Cloud Infrastructure Scanning for Government
Summary As CISA BOD 25-01: Implementing Secure Practices for Cloud Services is being implemented, Tenable customers need a method to scan their cloud configuration for compliance. Tenable has enabled the ability to authenticate against the US Government national cloud in Microsoft Azure. Authentication Environment To accomplish the scanning of national clouds in Microsoft Azure, the Microsoft Azure credential has been enhanced to include the Authentication Environment preference. This preference has the default value of "Global", with an added value of "US-Gov". To use the credential in the US Government national cloud, Tenable customers will need access to the cloud being specified and have setup application access to the instance by following the procedures in Configure Azure for a Compliance Scan. Tenable Plugins 79357 - Microsoft Azure Compliance Checks Target Release Date ImmediateFind & Unzip Execution Options Summary Instead of...
Find & Unzip Execution Options Summary Instead of running native OS commands of “find” and “unzip”, plugins will use binaries included within the plugin feed for agent-based scanning. This allows CPU consumption to be controlled for the Tenable Nessus Agent for the ‘find’ command. This change will not affect or limit memory consumption. An additional benefit is that if ‘find’ or ‘unzip’ are not found natively on the OS, using from the feed allows full plugin execution with these commands to continue. What is the impact? The change should be transparent to customers and no action is required to be taken except for new scans if you’d like to opt-in to this feature. New Scans Be aware if you have adjusted the Agent CPU settings of Scan Performance to a setting other than the default, which is High, the resulting scan findings may be different than previous scans with the same configuration. This is because the scan may experience timeouts in finding files due to the lower CPU resources. See the next section for how to opt-in to the change, if desired. Existing Scans This change will not apply. The native OS binaries will continue to be used and not subject to Tenable Nessus Agent CPU control settings. PCI-DSS Scans This change will not apply. The native OS binaries will continue to be used and not subject to Tenable Nessus Agent CPU control settings. Due to the PCI-DSS standard requirements, the most complete scan results are required for reporting. Audits Due to the need for thorough and complete results, Audits do not leverage the find or unzip binaries from the Tenable feed. How do I opt-in to the change? An advanced setting within the scan configuration will allow customers to opt-in to using the binaries from the feed. By default, native OS commands will run for ‘find’ and ‘unzip’ as before. Please note, these commands are not subject to agent CPU constraints. For PCI scanning and existing scans, the scan template setting will be not visible and the scanning behavior will be equivalent to opting-out. What are the affected plugins? At the time of this release highlight publication, the following plugins are leveraging find or unzip: Find 142023 - Apache Cassandra Installed (Linux) 133766 - Apache Maven Installed (Linux / Unix) 135172 - Oracle NoSQL Database Installed (Linux) 117706 - MagniComp SysInfo Installed (Linux/UNIX) 111679 - FasterXML Jackson Databind Detection for Linux/UNIX 112063 - Kubernetes Installed (Linux) 136340 - nginx Installed (Linux/UNIX) 131566 - Atlassian Jira Installed (Unix / Linux) 147817 - Java Detection and Identification (Linux / Unix) 132771 - Palo Alto Cortex XSOAR Installed (Unix / Linux) 132872 - Foxit Reader Installed (Linux) 174788 - SQLite Local Detection (Linux) 151883 - Libgcrypt Installed (Linux/UNIX) 99671 - Apache Struts Detection for Linux/UNIX 156000 - Apache Log4j Installed (Linux / Unix) 141394 - Apache HTTP Server Installed (Linux) 71642 - Oracle Installed Software Enumeration (Linux / Unix) 156551 - Oracle MySQL Enterprise Monitor Installed (macOS) 124276 - Oracle Tuxedo Installed (Linux/UNIX) 73913 - Oracle WebLogic Server Detection 133962 - Sophos Anti-Virus Installed (Linux) 186361 - VMWare Tools or Open VM Tools Installed (Linux) 187057 - OwnCloud OwnCloud Installed (Linux) 70349 - Adobe Acrobat Installed (Mac OS X) 72202 - JBoss Detection 147022 - SAP Adaptive Server Enterprise (ASE) Installed (Linux) 163488 - Terraform Configuration Detection for Linux/UNIX 77028 - IBM Installation Manager Detection (Linux / Unix) 145032 - IBM WebSphere eXtreme Scale (Linux) 144633 - IBM MQ Server and Client Installed (Linux) 136341 - Dell EMC Data Protection Central Installed (Linux) 133964 - SELinux Status Check 159273 - Dockerfile Detection for Linux/UNIX 174164 - Google Protobuf Go Module Installed (Linux/UNIX) 158567 - Citrix Workspace App Installed (nix) 55420 - Adobe Reader Installed (Mac OS X) Unzip 193884 - CrushFTP Server Installed (Linux / Unix) 130175 - Apache Tomcat Local Detection 166230 - Apache Commons Text JAR Detection 176069 - Potix ZK Framework Installed (Linux) 130595 - Jenkins Installed (Linux) 123005 - Spring Framework JAR Detection 156000 - Apache Log4j Installed (Linux / Unix) 192571 - Fortra FileCatalyst Direct Server Installed (Linux / Unix) 72202 - JBoss Detection 134049 - Spring Projects Linux Detection 185488 - IBM WebSphere Application Server Liberty Installed (Linux / Unix) 170106 - TIBCO JasperReports Library JAR Detection Target Release Date July 9, 2024 - Tenable Vulnerability Management and Nessus July 15, 2024 - Tenable Security CenterSolutions Improvements: Cross Branch, OS and Product What...
Solutions Improvements: Cross Branch, OS and Product What are patch chains? A patch chain is a sequence of patches that roll up to a top-level patch. Applying the top-level patch should remediate all findings within the patch chain. What’s happening? Tenable is releasing an update for the data underlying the Solutions feature in order to increase accuracy of the recommended solutions. More accurate solutions will empower teams to make efficient and complete updates to remediate the active vulnerabilities by focusing on the latest fix. The specific changes we are implementing are : Better handling of branch-specific product checks to ensure that recommended solutions are constrained to the specific branch of the product that was detected Better handling of platform-specific checks to ensure that recommended solutions are specific to the platform the software is running on, where applicable Removal of deprecated plugins from recommended solutions Separating NNM plugins into separate chains Cross Branch Example: A solution to remediate a vulnerability in Apache Tomcat 10.x may not be the same as a solution for Apache Tomcat 9.x. These would require separate patch chains. Cross OS Example: Office for Mac and Office for Windows would be broken into separate patch chains with their corresponding solutions. Why is this necessary? The same solution may not apply across branches of the same software or different operating systems. These would represent separate patch chains in order to remediate all vulnerabilities. It was also determined that deprecated plugins could show up in the patch chain either as a plugin within the chain or a top level solution on a chain. Finally, it was determined that in order to maximize the accuracy of the chains for Nessus findings it was necessary to break NNM plugins up into their own chains. How does this update affect me? Customers with findings from plugins for different branches, OS or products may be broken up into two or more chains. While this does potentially create multiple recommended solutions, each of these solutions will be more accurate and will avoid scenarios where applying the top level solution does not remove that finding. When is Tenable releasing the update? The target release date is June 17, 2024. What products does this change affect? Any Tenable product that uses the Solutions view. This includes: Tenable Security Center Tenable Lumin This data is also used by the Remediation Summary tool within Security Center. What changes do I need to make? For SC customers, ensure both the plugin feed and SC feed has been updated from the date June 18, 2024 or later. For Lumin customers, no action is required. After the update, the patch chains would be updated on your next scan. Does Tenable anticipate making additional changes to the patch chains? We will continue to evaluate the accuracy of the patch chains and make improvements where necessary. Share feedback with your Tenable Customer Success Manager (CSM) if you have concerns or encounter any issues. Future updates will be announced via the same communication channels as this update.Hashicorp Vault LDAP Secrets Engine Authentication Summary...
Hashicorp Vault LDAP Secrets Engine Authentication Summary Tenable has added the ability to authenticate using Hashicorp Vault and the LDAP secrets engine. Change The “Vault Type” drop-down menu which previously contained KV1, KV2 and AD has been extended to include a fourth option, LDAP. The LDAP secrets engine works similarly to the AD engine. The AD engine has been deprecated by Hashicorp and customers can use the LDAP engine as a replacement. See the following screenshot for an example of Windows credential configuration within Nessus: Release Immediate for Nessus and VM, TBD for SC.BeyondTrust Password Safe Cloud Integration Summary...
BeyondTrust Password Safe Cloud Integration Summary Tenable has verified the existing PAM integration with BeyondTrust Password Safe works with both the on-premises version and the cloud. Change No changes have been made to the integration in order to work with Password Safe Cloud. The documentation has been updated to note that Tenable now supports Password Safe Cloud. More details may be found about the integration within the product documentation for Tenable Vulnerability Management, Tenable Security Center and Tenable Nessus. Impact If you have issues with the integration, please open a ticket with Technical Support. Tenable will engage with BeyondTrust as needed to identify and resolve the issue. Release Date Immediate