# Tenable Blog

The leader in exposure management and AI security, Tenable cybersecurity solutions reduce cyber risk across IT, OT, cloud, identity & hybrid attack surfaces.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

DevFeed: [Oracle September 2026 Critical Security Patch Update addresses 672 CVEs](<https://devfeed.tech/articles/oracle-september-2026-critical-security-patch-update-addresses-672-cves-26926.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/oracle-september-2026-critical-security-patch-update-addresses-672-cves>)

Author: Research Special Operations

Published: 2026-09-15T21:00:28Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Network](<https://devfeed.tech/topics/network.md>)

Tags: [cves](<https://devfeed.tech/tags/cves.md>), [network](<https://devfeed.tech/tags/network.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Oracle's September 2026 Critical Security Patch Update fixes 672 unique CVEs through 673 security updates across 17 Oracle product families. It includes 104 critical patches, with Oracle E-Business Suite receiving the most patches.

### Source excerpt

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patches Background On September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 672 unique CVEs in 673 security updates across 17 Oracle product families. Out of the 673 security updates published, 15.5% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 74.7%, followed by critical severity patches at 15.5%. This month's update includes 104 critical patches across 104 CVEs. SeverityIssues PatchedCVEsCritical104104High503503Medium5958Low77Total673672 Analysis This month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 159, accounting for 23.6% of the total patches, followed by Oracle Fusion Middleware at 153 patches, which accounted for 22.7% of the total patches. A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication. Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle E-Business Suite15919Oracle Fusion Middleware15378Oracle Hyperion10250Oracle Siebel CRM6326Oracle Analytics508Oracle Communications3123Oracle Commerce2716Oracle Supply Chain195Oracle Virtualization191Oracle PeopleSoft164Oracle Database Server115

## Australia's Essential Eight replacement shifts cybersecurity compliance toward continuous exposure management

DevFeed: [Australia's Essential Eight replacement shifts cybersecurity compliance toward continuous exposure management](<https://devfeed.tech/articles/australia-is-replacing-the-essential-eight-with-a-new-cyber-framework-here-s-how-exposure-management-can-help-you-get-ahead-of-it-26585.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/australia-essential-eight-replacement-compliance-exposure-management>)

Author: Ben Mudie

Published: 2026-09-15T13:32:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Exposure Management](<https://devfeed.tech/topics/exposure-management.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [australia](<https://devfeed.tech/tags/australia.md>), [ciso](<https://devfeed.tech/tags/ciso.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [essential-eight](<https://devfeed.tech/tags/essential-eight.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [identity](<https://devfeed.tech/tags/identity.md>), [operational](<https://devfeed.tech/tags/operational.md>), [organization](<https://devfeed.tech/tags/organization.md>)

### AI overview

The article describes Australia's replacement of the Essential Eight with an outcomes-focused cybersecurity framework covering enterprise IT, cloud, operational technology, and potentially agentic AI. It argues that organizations will need continuous evidence of their security posture, and presents exposure management as a way to identify and prioritize weaknesses and support current posture validation.

### Source excerpt

Australia's move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture. Key takeaways The Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI. The Essential Eight itself only ever covered on-premises enterprise IT, built around eight named technical controls, such as application control and patching. It never extended to the security of cloud, identity, or OT. The shift challenges the traditional checklist approach to cybersecurity, where organizations demonstrate compliance through periodic assessments and point-in-time reports. In dynamic environments spanning IT, cloud, identity, and OT, security posture can change quickly and repeatedly between assessments. Exposure management can help organizations continuously understand where they are exposed, prioritize the most critical weaknesses, and provide evidence of their current security posture. ASD's strategic shift to active security posture validation Can you prove your security posture is solid, right now, on demand? That's the question the Australian Signals Directorate (ASD) has effectively put in front of every Australian organization's board, CISO, and C-suite. ASD's decision to retire the Essential Eight signals a fundamental move away from point-in-time, checklist-based security toward an outcomes-focused model where organizations will need to demonstrate continuous compliance. It's no longer enough to show that your organization had a control in place at the time of the last assessment. In a technology environment that changes continuously across IT, cloud, identity, and operational technology (OT), organizations must be able to answer a much more immediate question: Ho

## The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails

DevFeed: [The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails](<https://devfeed.tech/articles/the-agentic-harness-for-tenable-hexa-ai-how-tenable-prevents-ai-agents-from-going-off-the-rails-8264.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/how-agentic-harness-works-tenable-hexa-ai>)

Author: Raj Agrawal

Published: 2026-09-10T13:00:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Large Language Model](<https://devfeed.tech/topics/llm.md>), [agent observability](<https://devfeed.tech/topics/agent-observability.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [ai-agents](<https://devfeed.tech/tags/ai-agents.md>), [audit-trail](<https://devfeed.tech/tags/audit-trail.md>), [llms](<https://devfeed.tech/tags/llms.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Tenable describes an agentic-AI harness that constrains model context and tool use, validates actions, requires human approval, and records activity to protect production security environments.

### Source excerpt

Learn why Tenable treats agentic LLMs as untrusted insiders, and how we've made sure you can control and monitor the AI agents making changes in your production security environment Key takeaways AI models can quickly understand data, but not your business. While modern AI models are great at reasoning, they don't automatically understand your unique environment or who is allowed to do what. The "harness" is the custom-built layer that translates AI intelligence into safe, controlled actions specific to your organization. AI requires a supervisor. Tenable treats our AI agents like untrusted insiders. Instead of relying on the AI to police itself, the harness strictly limits what the AI can see and do, and ensures a human reviews and approves any changes before they happen in your environment. Trust requires proof. The harness ensures that every action AI proposes or takes is fully recorded, giving you an audit trail to confidently hand off real work to AI without losing control. Every security vendor has an AI agent. The demos are good. They are supposed to be good, because a demo runs against data that nobody minds breaking. The questions worth asking a vendor about their AI agents are the ones that come after the demo: What happens when the agent is wrong? What happens when someone feeds the agent a prompt designed to manipulate it? If the agent changes something in our environment, what evidence exists afterward about what it did and who authorized its action? When developing Tenable Hexa AI, the agentic AI engine of the Tenable One Exposure Management Platform, we tackled a difficult and critical problem that often gets overlooked: building the underlying infrastructure, the governance layer that safely turns the AI's decisions into actual changes without putting your production data at risk. We call this layer the harness: the runtime control environment in which the model operates. The harness decides: What context the model can see Which tools it can call Wha

## Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI

DevFeed: [Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI](<https://devfeed.tech/articles/introducing-the-cyberagents-exchange-ai-inspector-rigorous-review-for-community-built-ai-8261.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/ai-agent-security-openai-tenable-cyberagents-exchange-inspector>)

Author: Mark Beblow

Published: 2026-09-09T13:00:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Securing AI](<https://devfeed.tech/topics/securing-ai.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [open-source-security](<https://devfeed.tech/topics/open-source-security.md>), [Model Context Protocol (MCP)](<https://devfeed.tech/topics/model-context-protocol-mcp.md>)

Tags: [agentic-ai](<https://devfeed.tech/tags/agentic-ai.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [mcp](<https://devfeed.tech/tags/mcp.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openai](<https://devfeed.tech/tags/openai.md>), [review](<https://devfeed.tech/tags/review.md>), [securing-ai](<https://devfeed.tech/tags/securing-ai.md>)

### AI overview

Tenable introduces the CyberAgents Exchange AI Inspector, a security-review process for submissions to its registry of AI agents, skills, MCP servers, and multi-agent playbooks. It combines GPT Cyber models, Tenable security expertise, and human oversight to apply deeper review to higher-risk submissions.

### Source excerpt

Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That's why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector. Key takeaways The Exchange Inspector combines Tenable's exposure detection with OpenAI's GPT Cyber models and with human oversight to rigorously vet submissions made to the CyberAgents Exchange. Securing AI agents requires analyzing a broad attack surface that includes LLM instructions, tool-chaining permissions, and prompt injection risks, going far beyond traditional software security. The CyberAgents Exchange inspection process dynamically matches the appropriate AI model tier to each submission's risk level, ensuring comprehensive vetting without excessive computational overhead. Recently at OpenAI's "Intelligence at Work: Cyber Summit," Tenable and OpenAI announced a groundbreaking review process to vet the security of open-source AI agents, skills, MCP servers, and multi-agent playbooks, building on our June partnership. The new CyberAgents Exchange AI Inspector, which is built into our CyberAgents Exchange registry, will help security teams adopt agentic AI quickly and confidently. Powered by Tenable, the CyberAgents Exchange is a purpose-built, cybersecurity-native registry for AI agents, skills, MCP servers, and multi-agent playbooks. Launched in August as an open source and vendor-agnostic registry, the CyberAgents Exchange has already grown to host more than 100 AI listings, including a wave of contributions created at Tenable's SWARM build event at Black Hat USA. From the CyberAgents Exchange's inception, we understood the importance of a rigorous, comprehensive review process for agents submitted by contributors. Every submission to the CyberAgents Exchange gets a baseline review prior to being listed. Now, we are further strengt

## Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

DevFeed: [Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)](<https://devfeed.tech/articles/microsoft-s-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880-8267.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880>)

Author: Research Special Operations

Published: 2026-09-08T18:07:55Z

Content type: news

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [cve-2026-85880](<https://devfeed.tech/topics/cve-2026-85880.md>), [.NET](<https://devfeed.tech/topics/net.md>), [ASP.NET](<https://devfeed.tech/topics/aspnet.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [Visual Studio Code](<https://devfeed.tech/topics/visual-studio-code.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [asp-net-core](<https://devfeed.tech/tags/asp-net-core.md>), [cve-2026-81963](<https://devfeed.tech/tags/cve-2026-81963.md>), [cve-2026-85880](<https://devfeed.tech/tags/cve-2026-85880.md>), [github-copilot](<https://devfeed.tech/tags/github-copilot.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net](<https://devfeed.tech/tags/net.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [update](<https://devfeed.tech/tags/update.md>), [updates](<https://devfeed.tech/tags/updates.md>), [visual-studio](<https://devfeed.tech/tags/visual-studio.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft's September 2026 Patch Tuesday release addresses 964 CVEs, including two zero-days exploited in the wild. The release rates 104 vulnerabilities as critical and 860 as important.

### Source excerpt

104Critical 860Important 0Moderate 0Low Microsoft addresses 964 CVEs, smashing July's release as the largest Patch Tuesday release. This month's updates include patches for two zero-days that were exploited in the wild. Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important. This month's update includes patches for: .NET .NET and Visual Studio ASP.NET Core Active Directory Certificate Services (AD CS) Active Directory Domain Services Active Directory Federation Services (AD FS) Audio Video Control Transport Protocol Azure Arc Azure CycleCloud Azure HDInsights BranchCache Connected Devices Platform Service (Cdpsvc) Data Sharing Service Client GitHub Copilot and Visual Studio Code Graphic Fonts HID class driver IP Helper Internet Storage Name Service Kernel Streaming WOW Thunk Service Driver Microsoft Account Microsoft Authenticator Microsoft Azure Attestation service and Device Health Attestation Service Microsoft Azure CLI Microsoft COM for Windows Microsoft Dynamics 365 Microsoft Exchange Server Microsoft Graphics Component Microsoft Install Service Microsoft JScript Microsoft Local Security Authority Server (lsasrv) Microsoft Office Microsoft Office Access Microsoft Office Excel Microsoft Office Outlook Microsoft Office PowerPoint Microsoft Office Publisher Microsoft Office SharePoint Microsoft Office Word Microsoft Standard XPS Microsoft Teams for Android Microsoft Trace Data Helper Microsoft UxTheme Library (uxtheme.dll) Microsoft WDAC OLE DB provider for SQL Microsoft WebP Image Extension Microsoft Windows Codecs Library Microsoft Windows Media Foundation Microsoft Windows PDF Microsoft Windows SCSI Class System File Microsoft Windows Search Component Microsoft Windows Speech OpenSSH for Windows Power Automate Push Message Routing Service RPC Runtime Reliable Multicast Transport Driver (RMCAST) Remote Desktop Client Remote Desktop Gateway Service Role: DNS Server Role: Windows Fax Serv

## Claude Mythos 5 is coming to Tenable One, powering the new "Adversary View"

DevFeed: [Claude Mythos 5 is coming to Tenable One, powering the new "Adversary View"](<https://devfeed.tech/articles/claude-mythos-5-is-coming-to-tenable-one-powering-the-new-adversary-view-8273.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/tenable-one-claude-mythos-5-adversary-view-ai-exposure-management>)

Author: Eric Doerr

Published: 2026-09-08T17:21:00Z

Content type: release

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Claude](<https://devfeed.tech/topics/claude.md>), [anthropic](<https://devfeed.tech/topics/anthropic.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [ai](<https://devfeed.tech/tags/ai.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [claude](<https://devfeed.tech/tags/claude.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [reasoning](<https://devfeed.tech/tags/reasoning.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Tenable announces plans to integrate Claude Mythos 5 into Tenable One. Its planned Adversary View capability is intended to help security teams identify vulnerability chains, model attacker progression, and prioritize actions across exposure management.

### Source excerpt

Tenable is bringing Anthropic's Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks. Key takeaways Claude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for research and evaluation, Tenable will now incorporate it within Tenable One, giving defenders access to frontier cyber reasoning to tackle complex exposure management challenges. Tenable One Adversary View is the first innovation we'll deliver to our customers. Adversary View will use Claude Mythos 5 to help security teams uncover hidden vulnerability chains, see their environments from an attacker's perspective, and identify the actions that can disrupt attacker progression. Adversary View is just the beginning. Combining Claude Mythos 5's advanced cyber reasoning with the breadth and depth of Tenable One sets up a new generation of AI-powered capabilities across exposure management. Bringing Claude Mythos 5 into Tenable One Security teams face more findings than they can possibly triage using conventional methods. Add cloud, operational technology (OT), shadow AI, and identity data to the attack surface, and the volume of signals keeps growing while the time to act keeps shrinking. Finding exposures is no longer the hardest part. The challenge is understanding which combinations of exposures create the greatest risk, how an attacker could exploit them, and what to fix first. While leveraging frontier models for improving security defenses is still relatively new, bringing those models into customer-facing products is at the leading edge. Today, we are sharing how Tenable is combining Claude Mythos 5 with the exposure intelligence in Tenable One. Mythos 5 provides frontier-scale a

## StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

DevFeed: [StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day](<https://devfeed.tech/articles/stylesmuggler-cve-2026-75650-frequently-asked-questions-about-adobe-commerce-and-magento-zero-day-8271.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/stylesmuggler-cve-2026-75650-frequently-asked-questions-about-adobe-commerce-and-magento-zero>)

Author: Satnam Narang

Published: 2026-09-08T14:00:43Z

Content type: news

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [PHP](<https://devfeed.tech/topics/php.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [authentication](<https://devfeed.tech/tags/authentication.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [payload](<https://devfeed.tech/tags/payload.md>), [php](<https://devfeed.tech/tags/php.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The article explains StyleSmuggler (CVE-2026-75650), an actively exploited, unauthenticated remote-code-execution vulnerability affecting Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. It describes injection of PHP code through style properties and execution during rendering of a transactional email template.

### Source excerpt

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication. Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns. Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable detection plugins will be published as they become available. Background Tenable's Research Special Operations Team (RSO) has compiled this blog to answer Frequently Asked Questions (FAQ) regarding CVE-2026-75650, a zero-day remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that has been actively exploited in the wild. FAQ When was CVE-2026-75650 first disclosed? On September 5, 2026, the Sansec Forensics Team published research detailing an actively exploited zero-day vulnerability in Magento and Adobe Commerce that it named StyleSmuggler. What is CVE-2026-75650? CVE-2026-75650 is a remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary code on a vulnerable server. CVE-2026-75650 carries a CVSSv3 score of 10.0, the highest possible rating. Additionally, its scope is changed, meaning exploitation can impact resources beyond the vulnerable component itself. CVEDescriptionCVSSv3CVE-2026-75650Adobe Commerce and Magento Open Source Remote Code Execution10.0 The following products and versions are affected: ProductAffected versionsAdobe Commerce2.4.4 through 2.4.9Adobe Commerce B2B1.3.3 through 1.5.3Magento Open Source2

## Why a cryptographic inventory is key for addressing the quantum computing threat

DevFeed: [Why a cryptographic inventory is key for addressing the quantum computing threat](<https://devfeed.tech/articles/why-a-cryptographic-inventory-is-key-for-addressing-the-quantum-computing-threat-8275.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/why-a-cryptographic-inventory-is-key-for-addressing-the-quantum-computing-threat>)

Author: Christopher Day

Published: 2026-08-28T14:01:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [migration](<https://devfeed.tech/topics/migration.md>), [Security Attacks](<https://devfeed.tech/topics/security-attacks.md>)

Tags: [algorithms](<https://devfeed.tech/tags/algorithms.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [migration](<https://devfeed.tech/tags/migration.md>), [post-quantum](<https://devfeed.tech/tags/post-quantum.md>), [quantum](<https://devfeed.tech/tags/quantum.md>), [quantum-computing](<https://devfeed.tech/tags/quantum-computing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains how a cryptographic inventory and phased migration to quantum-resistant cryptography can address the risk that future quantum computers pose to public-key algorithms. It highlights harvest-now, decrypt-later attacks, the vulnerability of RSA, ECC, and Diffie-Hellman to Shor's Algorithm, and the expected resilience of AES-256.

### Source excerpt

When quantum computers become generally available, they'll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why building a comprehensive cryptographic inventory and executing a phased operational strategy are critical for protecting your data against quantum computing attacks. Key takeaways Quantum computing risks are an operational threat today due to "harvest now, decrypt later" (HNDL) tactics, in which adversaries actively harvest and store encrypted data to decrypt it retroactively once quantum capabilities mature. When run on a quantum computer that's powerful enough, Shor's Algorithm will break foundational asymmetric infrastructure like the RSA, ECC, and Diffie-Hellman algorithms, although symmetric encryption standards like AES-256 are expected to remain secure against quantum attacks. Globally, more regulatory bodies are starting to mandate a comprehensive cryptographic inventory, making absolute visibility across the digital environment a prerequisite for an orderly post-quantum migration. Transitioning to quantum-resistant cryptography requires a phased operational strategy spanning discovery, prioritization, remediation, and verification. The quantum threat to modern security architecture Future quantum computers will represent a threat to the foundational security architecture that protects digital data. For decades, the global economy, national security apparatus, and critical infrastructure have relied on asymmetric cryptography, specifically RSA and elliptic curve cryptography (ECC), to secure data in transit, authenticate identities, and protect digital signatures. The mathematical difficulty of factoring large integers or solving discrete logarithm problems has long provided a robust shield against cyber attacks launched using conventional computing capabilities. However, the rapid mat

## How to build an exposure management program the business trusts: Lessons from Tenable's CSO

DevFeed: [How to build an exposure management program the business trusts: Lessons from Tenable's CSO](<https://devfeed.tech/articles/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenable-s-cso-8265.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenables-cso>)

Author: Robert Huber

Published: 2026-08-27T14:30:00Z

Content type: tutorial

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [data](<https://devfeed.tech/topics/data.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [exposure-management](<https://devfeed.tech/tags/exposure-management.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [security](<https://devfeed.tech/tags/security.md>), [tools](<https://devfeed.tech/tags/tools.md>), [visualization](<https://devfeed.tech/tags/visualization.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Tenable's article explains how an exposure management program can reduce security tool sprawl, unify fragmented security data, improve visibility across the attack surface, and connect cyber-risk metrics with business priorities. It also discusses the challenges of maintaining security and speed while organizations rapidly adopt AI.

### Source excerpt

Discover how Tenable's shift to an AI-driven exposure management program helped Tenable's CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand. Key takeaways Security tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations' cyber risk. An exposure management program consolidates fragmented security data into a single unified view of cyber risk across the entire attack surface. Aided by exposure management, CISOs can align security metrics with business priorities and quantify risk for key revenue-generating business units, answering the board's main question: "Are we secure?" What is trust in cybersecurity? And more importantly, how do you earn it? Here's a hint: It's not easy, especially in this AI era. As the Chief Security Officer at Tenable, my mandate is to ensure our organization operates securely, but with the speed required to succeed in a very competitive business environment. In recent years, achieving this delicate balance -- an agile yet cyber secure business -- had become progressively more difficult, as we grappled with increasingly fragmented data, siloed teams, and security tool sprawl. In this blog, I'll explain how exposure management helped my team: Tackle security tool sprawl Bridge operational and data silos Take a more proactive approach to security Attain visibility and control over Tenable's attack surface Continuously and precisely assess our cyber risk posture The operational impact of security data silos and tool sprawl For years, the cybersecurity industry's answer to every new threat or policy mandate was simple: Buy another tool, which in many -- maybe most -- organizations resulted in a bad case of tool sprawl. A typical large enterprise might juggle 70 or more security technology vendors, each promising to so

## Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter

DevFeed: [Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter](<https://devfeed.tech/articles/edge-infrastructure-under-siege-what-two-independent-datasets-reveal-about-who-s-exploiting-your-perimeter-8262.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/edge-infrastructure-under-siege>)

Author: Research Special Operations

Published: 2026-08-26T13:00:00Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [china](<https://devfeed.tech/tags/china.md>), [complexity](<https://devfeed.tech/tags/complexity.md>), [containers](<https://devfeed.tech/tags/containers.md>), [datasets](<https://devfeed.tech/tags/datasets.md>), [edge](<https://devfeed.tech/tags/edge.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [iran](<https://devfeed.tech/tags/iran.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

A joint Tenable-SentinelOne analysis finds state-sponsored and criminal actors converging on the same edge vulnerabilities. It compares exposure and remediation patterns across vendors and recommends faster patching, attack-surface reduction, and endpoint protection.

### Source excerpt

A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge -- not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Key Takeaways Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) -- well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch. Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers. The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months. Leverage multiple d

## Frequently asked questions about the active threat to Siemens S7 Series PLCs

DevFeed: [Frequently asked questions about the active threat to Siemens S7 Series PLCs](<https://devfeed.tech/articles/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs-8263.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs>)

Author: Research Special Operations

Published: 2026-08-20T14:01:58Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Critical Infrastructure](<https://devfeed.tech/topics/critical-infrastructure.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>), [Script](<https://devfeed.tech/topics/script.md>), [Networks](<https://devfeed.tech/topics/networks.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [critical-infrastructure](<https://devfeed.tech/tags/critical-infrastructure.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [networks](<https://devfeed.tech/tags/networks.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

This FAQ explains an active threat targeting internet-exposed or insufficiently segmented Siemens S7 Series PLCs. It describes how threat actors use AI-generated exploitation scripts for reconnaissance and capability building, and outlines mitigations including removing direct internet exposure, segmenting OT from IT networks, and hardening access controls.

### Source excerpt

A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors. Key Takeaways Unattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs. The attackers are leveraging AI to build and refine exploit scripts faster than manual development would allow. AI use lowers the technical bar for ICS attacks in a way defenders haven't had to plan for before. There is no single patch, because there is no single flaw. Mitigation depends on removing Siemens S7 Series PLCs from direct internet exposure, segmenting OT from IT networks and hardening access controls. Background On August 19, 2026, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE) and the Environmental Protection Agency (EPA) released a joint Cybersecurity Advisory (AA26-231A) warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The activity spans the S7-200, S7-300, S7-400, S7-1200 and S7-1500 series and most heavily affects the Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture and Commercial Facilities sectors, with potential exposure in the Defense Industrial Base as well. According to the authoring agencies, threat actors are using AI-generated exploitation scripts, disguised as legitimate operational technology (OT) monitoring tools, to conduct reconnaissance and build capability against exposed PLCs. The Tenable Research Special Operations Team (RSO) has put together this frequently asked questions (FAQ) blog to help security and OT

## Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs

DevFeed: [Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs](<https://devfeed.tech/articles/oracle-august-2026-critical-security-patch-update-addresses-925-cves-8269.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/oracle-august-2026-critical-security-patch-update-cspu-addresses-925-cves>)

Author: Research Special Operations

Published: 2026-08-19T00:41:38Z

Content type: article

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [oracle](<https://devfeed.tech/tags/oracle.md>), [security](<https://devfeed.tech/tags/security.md>), [update](<https://devfeed.tech/tags/update.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Oracle's August 2026 Critical Security Patch Update addresses 925 unique CVEs through 943 security updates across 23 product families, including 154 critical patches. The release is substantially larger than the June CSPU and includes a high concentration of high-severity issues, with Oracle Fusion Middleware receiving the most patches.

### Source excerpt

Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates. Key Takeaways The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates 154 issues (16.3% of all patches) were assigned a critical severity rating Oracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patches Background On August 18, Oracle released its Critical Security Patch Update (CSPU) for August 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 925 unique CVEs in 943 security updates across 23 Oracle product families, a nearly fourfold increase in patch volume compared to the June 2026 CSPU, which addressed 243 CVEs in 245 patches across 11 product families. To put that in context against the quarterly CPUs: the April 2026 CPU contained 481 patches across 241 CVEs, and the July 2026 CPU, the largest CPU release of 2026, contained 1,449 patches across 1,235 CVEs. August's CSPU at 943 patches sits well above the April CPU and represents roughly 65% of July's quarterly volume, a striking figure for what is nominally a targeted between-cycle release. The expansion to 23 product families (up from 11 in June) further blurs the line between CSPU and CPU in terms of scope. Out of the 943 security updates published, 16.3% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 59%, followed by medium severity patches at 21%. This month's update includes 154 critical patches across 151 CVEs. SeverityIssues PatchedCVEsCritical154151High556541Medium198198Low3535Total943925 Analysis This month's update saw the Oracle Fusion Middleware product family contain the highest number of patches at 262, acc