<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>Tenable Blog</title>
    <link>https://www.tenable.com/</link>
    <description/>
    <language>en</language>
    <atom:link href="https://www.tenable.com/blog/feed" rel="self" type="application/rss+xml"/>
    
    <item>
  <title>Why a cryptographic inventory is key for addressing the quantum computing threat</title>
  <link>https://www.tenable.com/blog/why-a-cryptographic-inventory-is-key-for-addressing-the-quantum-computing-threat</link>
  <description>&lt;p&gt;When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest now, decrypt later" tactic. Discover why building a comprehensive cryptographic inventory and executing a phased operational strategy are critical for protecting your data against quantum computing attacks.&lt;/p&gt;&lt;div class="blog-see-also"&gt;&lt;div class="col-sm-12"&gt;&lt;h2&gt;Key takeaways&lt;/h2&gt;&lt;ol&gt;&lt;li data-list-item-id="eb2ad56e4e8763170933e93c18a4221a4"&gt;Quantum computing risks are an operational threat today due to "harvest now, decrypt later" (HNDL) tactics, in which adversaries actively harvest and store encrypted data to decrypt it retroactively once quantum capabilities mature.&lt;/li&gt;&lt;li data-list-item-id="ef90c14bb462e5fd54d633e54172d9390"&gt;When run on a quantum computer that’s powerful enough, Shor’s Algorithm will break foundational asymmetric infrastructure like the RSA, ECC, and Diffie-Hellman algorithms, although symmetric encryption standards like AES-256 are expected to remain secure against quantum attacks.&lt;/li&gt;&lt;li data-list-item-id="e10340d8443735b42083b000132d88c12"&gt;Globally, more regulatory bodies are starting to mandate a comprehensive cryptographic inventory, making absolute visibility across the digital environment a prerequisite for an orderly post-quantum migration.&lt;/li&gt;&lt;li data-list-item-id="e9a5eb81ce9c6fdac9169b7ce3d4c843d"&gt;Transitioning to quantum-resistant cryptography requires a phased operational strategy spanning discovery, prioritization, remediation, and verification.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;/div&gt;&lt;h2&gt;The quantum threat to modern security architecture&lt;/h2&gt;&lt;p&gt;Future quantum computers will represent a threat to the foundational security architecture that protects digital data.&amp;nbsp;&lt;/p&gt;&lt;p&gt;For decades, the global economy, national security apparatus, and critical infrastructure have relied on asymmetric cryptography, specifically &lt;a href="https://en.wikipedia.org/wiki/RSA_cryptosystem"&gt;RSA&lt;/a&gt; and &lt;a href="https://en.wikipedia.org/wiki/Elliptic-curve_cryptography"&gt;elliptic curve cryptography (ECC)&lt;/a&gt;, to secure data in transit, authenticate identities, and protect digital signatures. The mathematical difficulty of factoring large integers or solving discrete logarithm problems has long provided a robust shield against cyber attacks launched using conventional computing capabilities.&lt;/p&gt;&lt;p&gt;However, the rapid maturation of quantum computing represents an existential threat to these algorithms. A fully fault-tolerant, &lt;a href="https://media.defense.gov/2021/Aug/04/2002821837/-1/-1/1/Quantum_FAQs_20210804.PDF"&gt;cryptographically relevant quantum computer&lt;/a&gt; (CRQC) capable of instantly shattering current encryption standards is still several years away. However, organizations need to migrate to quantum-resistant algorithms now. The reason? Adversaries are using "&lt;a href="https://labs.cloudsecurityalliance.org/research/ai-infrastructure-post-quantum-harvest-now-decrypt-later-v1/"&gt;harvest now, decrypt later&lt;/a&gt;" (HNDL) tactics. They steal data encrypted with algorithms vulnerable to quantum computing attacks, and save it, hoping to decrypt it in the future once quantum capabilities mature.&lt;/p&gt;&lt;h2&gt;The impact of Executive Order 14412&lt;/h2&gt;&lt;p&gt;Recognizing the immediacy of this threat, regulatory agencies have responded accordingly. The White House recently issued &lt;a href="https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/"&gt;Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,&lt;/a&gt;” which mandates that executive-branch federal agencies pay immediate operational and engineering attention to &lt;a href="https://www.nist.gov/cybersecurity-and-privacy/what-post-quantum-cryptography"&gt;post-quantum cryptography&lt;/a&gt; (PQC) readiness.&lt;/p&gt;&lt;p&gt;This directive introduces critical pillars that redefine enterprise security strategies:&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="e6e04dce42130ceae3f57517a41146ede"&gt;&lt;strong&gt;Accelerated migration timelines:&lt;/strong&gt; Moving aggressively ahead of prior federal benchmarks, the EO sets a deadline of Dec. 31, 2030, for transitioning high-value assets to PQC for key establishment, and Dec. 31, 2031, for digital signatures.&amp;nbsp;&lt;/li&gt;&lt;li data-list-item-id="e9c8ec1eb386eba7d18ed848fe16ba512"&gt;&lt;strong&gt;Supply chain and contractor mandates:&lt;/strong&gt; The EO directs the Federal Acquisition Regulatory (FAR) Council to require covered federal contractors to meet strict post-quantum &lt;a href="https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved"&gt;Federal Information Processing Standards (FIPS)&lt;/a&gt; from the &lt;a href="https://csrc.nist.gov/publications/fips"&gt;National Institute of Standards and Technology (NIST)&lt;/a&gt; by the end of 2030.&lt;/li&gt;&lt;li data-list-item-id="ee357e9e5817c4492c9085c26a130f551"&gt;&lt;strong&gt;Cryptographic weakness as an active vulnerability:&lt;/strong&gt; In a significant shift for &lt;a href="https://www.tenable.com/solutions/vulnerability-management"&gt;vulnerability management&lt;/a&gt;, contractors’ &lt;a href="https://www.cisa.gov/resources-tools/programs/coordinated-vulnerability-disclosure-program"&gt;vulnerability disclosure programs&lt;/a&gt; (VDPs) must explicitly treat the absence of encryption or the use of non-FIPS-approved algorithms as reportable cryptographic vulnerabilities, effectively redefining crypto-hygiene from a passive audit finding to an active risk-mitigation item.&lt;/li&gt;&lt;li data-list-item-id="e129857606d761b7e055f69042f16e397"&gt;&lt;strong&gt;The mandate for cryptographic bills of materials (CBOMs):&lt;/strong&gt; To achieve the complete visibility required for this transition, current and forthcoming frameworks, like &lt;a href="https://cyclonedx.org/use-cases/cryptographic-algorithm/"&gt;CycloneDX&lt;/a&gt;, emphasize automated discovery of cryptographic assets across all software, firmware, and hardware dependencies.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;In this high-stakes regulatory environment, visibility has emerged as the primary currency of defense. Organizations cannot migrate what they cannot see. Consequently, governments and regulatory bodies worldwide, from the White House and the &lt;a href="https://www.nsa.gov/Cybersecurity/Post-Quantum-Cybersecurity-Resources/"&gt;U.S. National Security Agency (NSA)&lt;/a&gt; to the &lt;a href="https://european-union.europa.eu/index_en"&gt;European Union&lt;/a&gt; and the &lt;a href="https://www.mas.gov.sg/-/media/mas-media-library/regulation/circulars/trpd/mas-quantum-advisory/mas-quantum-advisory.pdf"&gt;Monetary Authority of Singapore&lt;/a&gt;, have synchronized their directives around a single, non-negotiable requirement: the establishment of a comprehensive cryptographic inventory. Organizations must identify, catalog, and assess every cryptographic asset within their environment to facilitate an orderly transition to PQC.&lt;/p&gt;&lt;h2&gt;The collapse of asymmetric cryptography&lt;/h2&gt;&lt;p&gt;Current &lt;a href="https://www.idmanagement.gov/university/pki/"&gt;public-key infrastructure&lt;/a&gt; (PKI) relies on the computational intractability of specific mathematical problems. RSA encryption relies on the difficulty of integer factorization, while Diffie-Hellman and ECC rely on the discrete logarithm problem. It would take billions of years for a classical supercomputer to crack a 2048-bit RSA key.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Quantum computers utilize qubits, which can exist in a state of superposition, representing both 0 and 1 simultaneously. This property, combined with quantum entanglement, allows for massive parallelism in calculation.&amp;nbsp;&lt;/p&gt;&lt;p&gt;In 1994, mathematician Peter Shor developed &lt;a href="https://en.wikipedia.org/wiki/Shor%27s_algorithm"&gt;Shor’s Algorithm&lt;/a&gt;, which theoretically demonstrated that a quantum computer with sufficiently stable qubits could solve both integer factorization and discrete logarithm problems in polynomial time versus problems in exponential time on a classical computer. In other words, a problem that would take an impossibly long time for any real-world computer problem to solve can now be solved in a usefully short amount of time.&lt;/p&gt;&lt;p&gt;The implications are catastrophic for current standards:&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="ed46417806a59266de8e4c16c99940777"&gt;&lt;strong&gt;RSA-2048 and RSA-4096:&lt;/strong&gt; Completely broken.&lt;/li&gt;&lt;li data-list-item-id="e4ea8c57590ffdd50b7ff866ce81b9518"&gt;&lt;strong&gt;Elliptic-curve Diffie–Hellman (ECDH) and &lt;/strong&gt;&lt;a href="https://csrc.nist.gov/glossary/term/elliptic_curve_digital_signature_algorithm"&gt;&lt;strong&gt;Elliptic Curve Digital Signature Algorithm&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; (ECDSA):&lt;/strong&gt; Completely broken.&lt;/li&gt;&lt;li data-list-item-id="e7818a5469359fc5ac2a6ab565e3b97d4"&gt;&lt;strong&gt;Diffie-Hellman:&lt;/strong&gt; Completely broken.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Symmetric encryption, like AES-256, is more resilient; &lt;a href="https://postquantum.com/post-quantum/grovers-algorithm/"&gt;Grover’s Algorithm&lt;/a&gt; effectively halves the key strength, meaning AES-128 provides only 64 bits of security, but AES-256 remains secure against quantum attacks. Therefore, the immediate crisis is concentrated in &lt;em&gt;asymmetric&lt;/em&gt; cryptography used for key exchange, such as TLS/SSL handshakes and SSH session negotiation, as well as for digital signatures (authentication, code signing).&lt;/p&gt;&lt;h2&gt;The "harvest now, decrypt later" strategy&lt;/h2&gt;&lt;p&gt;The most pervasive misconception regarding PQC is that organizations have until &lt;a href="https://labs.cloudsecurityalliance.org/research/strategic-post-quantum-cryptography-migration-enterprise-roa/"&gt;Q-Day&lt;/a&gt;, the day a CRQC comes online, to upgrade their systems. This view ignores the “harvest now, decrypt later” attack vector, which has fundamentally shifted the risk timeline from the future to the present.&lt;/p&gt;&lt;p&gt;In an HNDL attack, sophisticated adversaries, primarily nation-states and well-funded criminal syndicates, intercept encrypted traffic today. At scale, this harvesting is primarily executed by nation-states utilizing &lt;a href="https://www.ntia.gov/programs-and-initiatives/border-gateway-protocol"&gt;Border Gateway Protocol &lt;/a&gt;(BGP) route manipulations to hijack large volumes of data in transit, alongside the exfiltration and theft of whole encrypted databases during network intrusions. While attackers cannot currently read this data, they store it in massive data centers, effectively time-capsuling the information. The moment a quantum computer capable of running Shor’s Algorithm becomes available, they will then decrypt this harvested data.&lt;/p&gt;&lt;h2&gt;Operationalizing the migration: A phased strategy&lt;/h2&gt;&lt;p&gt;Implementing the right tools is only the first step. Organizations need a coherent operational strategy to navigate the migration. Based on &lt;a href="https://csrc.nist.gov/pubs/sp/1800/38/iprd-(1)"&gt;NIST SP 1800-38 &lt;/a&gt;and &lt;a href="https://www.cisa.gov/topics/risk-management/quantum"&gt;CISA guidance&lt;/a&gt;, the following phased approach is recommended.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Phase 1: Automated discovery: &lt;/strong&gt;Establish the baseline. You cannot fix what you do not know exists. Within environments, discovery goes a step further than reading configurations: Organizations should inventory resources from the connected accounts and actively scan their internet-facing services to capture the key exchanges and ciphers these services negotiate. Because HDNL targets data in transit, this outside-in view pinpoints the exposed cloud services most at risk and folds them directly into your &lt;a href="https://www.tenable.com/exposure-management"&gt;exposure management&lt;/a&gt; workflow.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Phase 2: Prioritization and risk assessment: &lt;/strong&gt;Not every server needs PQC today. Identify systems with the highest risk and the most critical data.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Phase 3: Remediation and crypto-agility: &lt;/strong&gt;Upgrade systems to hybrid — meaning, running in parallel both conventional cryptography and PQC — and, finally, fully PQC compliant. Governmental mandates generally have set the year 2035 for complete quantum resistance for all systems. Avoid hard-coding the new algorithms. Use configurations that allow you to swap algorithms easily. The PQC standards are new; if a vulnerability is found next year in one of the new PQC standards, you must be able to switch to an alternative without recompiling code.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Phase 4: Continuous verification: &lt;/strong&gt;Prevent regression by making regular compliance assessments. A system might be compliant today, but a DevOps push next week might overwrite the config file and revert it to RSA-only. Continuous scanning ensures you maintain the quantum safe state over time.&lt;/p&gt;&lt;h2&gt;How can Tenable help?&lt;/h2&gt;&lt;p&gt;Closing the gap on HNDL starts with treating cryptographic risk as just another exposure to manage, not a separate audit exercise.&lt;/p&gt;&lt;p&gt;Bring SSL/TLS and SSH protocol visibility across your cloud and IT infrastructure into the Tenable One Exposure Management Platform's workflow you use to track vulnerabilities, misconfigurations, and identity risk. That way, cryptographic weaknesses surface alongside everything else competing for your team’s attention, instead of living in a separate report.&lt;/p&gt;&lt;p&gt;That visibility comes together in &lt;a href="https://www.tenable.com/products/tenable-one"&gt;Tenable One’s&lt;/a&gt; Cryptographic Inventory view, which shows where cryptographic risk lives across your environment: Which services still rely on classical, quantum-vulnerable ciphers, and which have already moved to post-quantum protection. Widgets summarize your overall cryptographic posture at a glance, so quantum readiness becomes one more metric in your exposure picture.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What the cryptographic inventory view surfaces:&lt;/strong&gt;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="e6a7701d60a6559634b37aff8ef8ecc31"&gt;&lt;strong&gt;Services using PQC:&lt;/strong&gt; Reports on services equipped with at least one post-quantum cipher. It will specify which post-quantum ciphers were discovered, reporting by port and protocol.&lt;/li&gt;&lt;li data-list-item-id="e6411209e2e56983629938e2b64536414"&gt;&lt;strong&gt;Services not using PQC:&lt;/strong&gt; Reports on services that support &lt;strong&gt;no&lt;/strong&gt; post-quantum ciphers.&lt;/li&gt;&lt;li data-list-item-id="e1e65c7c1d56a5e8871b8ab6e7108245a"&gt;&lt;strong&gt;Cipher inventory&lt;/strong&gt;: View an asset JSON-based inventory by service and cipher.&lt;/li&gt;&lt;li data-list-item-id="e15d418ae5a5041ec3ba2c2e70f2f60dd"&gt;&lt;strong&gt;TLS and SSH weaknesses&lt;/strong&gt;: View plugins that have detected weaknesses in conventional-computing algorithms.&lt;/li&gt;&lt;li data-list-item-id="eb7fd2c8d2ef55334cbb700a132d977e7"&gt;&lt;strong&gt;Certificate expiry and configuration concerns&lt;/strong&gt;: See certificates that have expired or are soon to expire, as well as configuration concerns such as self-signed certificates.&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Users can drill down into specific assets to see the JSON-based Cryptographic Inventory and use the Tenable &lt;a href="https://docs.tenable.com/quick-reference/scoring-explained/Content/Overview.htm"&gt;Asset Criticality Rating&lt;/a&gt; (ACR) to help with prioritization of systems for remediation. ACR assesses factors like device function, connectivity, and third-party data. Assets with higher ACR (e.g., 6–10) are more critical to your business.&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="https://www.tenable.com/sites/default/files/inline/images/Post-Quantum%20cipher%20analysis%20dashboard.png" data-entity-uuid="e7b2c827-ab07-499e-bf27-55b89cec86b6" data-entity-type="file" alt="Post-quantum cipher analysis dashboard in Tenable One" width="1200" height="1018" class="align-center" loading="lazy"&gt;&lt;p class="text-align-center"&gt;&lt;em&gt;&lt;sup&gt;Post-quantum cipher analysis dashboard in the Tenable One Exposure Management Platform&lt;/sup&gt;&lt;/em&gt;&lt;/p&gt;&lt;h2&gt;The time for action is now&lt;/h2&gt;&lt;p&gt;The transition to PQC is an immediate engineering and compliance challenge for today's leadership. The HNDL threat makes the risks a current reality, while the strict enforcement mechanisms of Executive Order 14412, alongside international regulatory frameworks like the &lt;a href="https://www.eiopa.europa.eu/digital-operational-resilience-act-dora_en"&gt;EU’s Digital Operational Resilience Act&lt;/a&gt; (DORA), ensure that the compliance and contractual consequences are imminent.&amp;nbsp;&lt;br&gt;&lt;br&gt;The days of treating cryptography as a set-and-forget utility are over. Cryptography is now a dynamic asset class that requires active management, continuous inventory, and strategic agility.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Tenable’s introduction of the set of Cryptographic Inventory dashboards and plugins represents a critical evolution in vulnerability management. It provides the data foundation necessary for the PQC transition. It empowers organizations to answer the regulator’s question, “Are you quantum ready?”, with data, precision, and confidence. The quantum era is arriving. With the right visibility, organizations can ensure their security arrives with it.&lt;/p&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/Why%20a%20cryptographic%20inventory%20is%20key%20for%20addressing%20the%20quantum%20computing%20threat.png"&gt;
</description>
  <pubDate>Fri, 28 Aug 2026 10:01:00 -0400</pubDate>
    <dc:creator>Christopher Day</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211105</guid>
    </item>
<item>
  <title>How to build an exposure management program the business trusts: Lessons from Tenable’s CSO</title>
  <link>https://www.tenable.com/blog/how-to-build-an-exposure-management-program-the-business-trusts-lessons-from-tenables-cso</link>
  <description>&lt;p&gt;Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical metrics to communicating business risk that the C-suite and the board can understand.&lt;/p&gt;&lt;div class="blog-see-also"&gt;&lt;div class="col-sm-12"&gt;&lt;h2&gt;&lt;strong&gt;Key takeaways&lt;/strong&gt;&lt;/h2&gt;&lt;ol&gt;&lt;li data-list-item-id="ef0367e1572b61cced71eae5f522018c8"&gt;Security tool sprawl and data silos make it difficult for CISOs to holistically and accurately assess their organizations’ cyber risk.&lt;/li&gt;&lt;li data-list-item-id="e505dbd18508f016ca272d803a2e4a1d3"&gt;An exposure management program consolidates fragmented security data into a single unified view of cyber risk across the entire attack surface.&amp;nbsp;&lt;/li&gt;&lt;li data-list-item-id="e0b1c12e408081cb9c47570dbaa62c0d8"&gt;Aided by exposure management, CISOs can align security metrics with business priorities and quantify risk for key revenue-generating business units, answering the board’s main question: “Are we secure?”&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;/div&gt;&lt;p&gt;What is trust in cybersecurity? And more importantly, how do you earn it? Here’s a hint: It’s not easy, especially in this AI era.&amp;nbsp;&lt;/p&gt;&lt;p&gt;As the Chief Security Officer at Tenable, my mandate is to ensure our organization operates securely, but with the speed required to succeed in a very competitive business environment. In recent years, achieving this delicate balance — an agile yet cyber secure business — had become progressively more difficult, as we grappled with increasingly fragmented data, siloed teams, and security tool sprawl.&lt;/p&gt;&lt;p&gt;In this blog, I’ll explain how exposure management helped my team:&amp;nbsp;&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="e8f7fc8c0c36dd19691f5af894b7f82f0"&gt;Tackle security tool sprawl&lt;/li&gt;&lt;li data-list-item-id="e234c084e4b8ff8060cbafbb35a5c32d9"&gt;Bridge operational and data silos&amp;nbsp;&lt;/li&gt;&lt;li data-list-item-id="e9b16a47a0cb387c87b8466c9c470ee19"&gt;Take a more proactive approach to security&lt;/li&gt;&lt;li data-list-item-id="e4cd5fa6d1bcf51f0cff08a9ac9f55cdd"&gt;Attain visibility and control over Tenable’s attack surface&lt;/li&gt;&lt;li data-list-item-id="e899b5da96a2e8eede5a9f5f91c985bf2"&gt;Continuously and precisely assess our cyber risk posture&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;The operational impact of security data silos and tool sprawl&amp;nbsp;&lt;/h2&gt;&lt;p&gt;For years, the cybersecurity industry’s answer to every new threat or policy mandate was simple: Buy another tool, which in many — maybe most — organizations resulted in a bad case of tool sprawl. A typical large enterprise might juggle 70 or more security technology vendors, each promising to solve a specific problem. At Tenable, my team manages around 50 different security tools.&lt;/p&gt;&lt;p&gt;We found ourselves in a situation where siloed teams were running siloed tools, with separate views, prioritization criteria, key performance indicators, remediation workflows, and reporting.&amp;nbsp;&lt;/p&gt;&lt;p&gt;To illustrate this internally, I used to present a visualization of our architecture that I called the “spaghetti chart.” It was a tangled web of inputs from &lt;a href="https://www.tenable.com/blog/relying-on-edr-for-exposure-management-what-you-need-to-know"&gt;endpoint detection and response&lt;/a&gt; (EDR) vendors, bug bounty programs, vulnerability scans, security operation center (SOC) findings, penetration tests, and more. Each tool demanded its own unique workflow. As you can see, the spaghetti chart presented a picture of chaos. It reminded me of Gen. Stanley McChrystal’s quip regarding a spaghetti chart he was presented with during the war in Afghanistan: “When we understand that slide, we’ll have won the war.” Similarly, we could have said: “When we understand that chart, we’ll have eradicated cyber risk.”&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="https://www.tenable.com/sites/default/files/inline/images/Tenable%20EM%20journey%20spaghetti%20chart.jpg" data-entity-uuid="486126b1-afb5-46aa-8e0d-4e101cc0e337" data-entity-type="file" alt="A spaghetti chart illustrating a web of tangled inputs created by siloed security tools." width="960" height="540" class="align-center" loading="lazy"&gt;&lt;p&gt;&lt;br&gt;The consequences of this fragmented approach to security became glaringly apparent during my board presentations. At one board meeting, I arrived with a deck consisting of 45 slides. An exhausting 30 of those slides were packed with metrics, KPIs, and raw data.&lt;/p&gt;&lt;p&gt;My team worked incredibly hard to pull that information together to build a narrative. Yet, I faced a hard truth: many of the business leaders and board members did not understand those metrics. &lt;strong&gt;When you present purely operational metrics, like the raw number of vulnerabilities or the number of scanned assets, you lose the C-suite’s attention.&lt;/strong&gt; &lt;strong&gt;Those numbers don’t translate to business impact.&lt;/strong&gt;&lt;/p&gt;&lt;h2&gt;The board’s two core questions about cybersecurity&lt;/h2&gt;&lt;p&gt;At the executive leadership and board level, I generally get asked two simple questions.&lt;/p&gt;&lt;p&gt;First: “Are we secure?” I may also get asked a variation, such as: “What’s our exposure?” From my 30 metric-heavy slides, generated from 50-plus tools with their own disparate reporting functions, I had to somehow boil the ocean of data and make a judgment call as to how secure we actually were.&lt;/p&gt;&lt;p&gt;The second question I get asked is: “How do we compare to peers?” As a publicly traded cybersecurity company, we have a strict fiduciary responsibility. The board wants to ensure we are maintaining a reasonable cybersecurity standard of care. Are we doing the things we’re supposed to be doing, that are expected of us by our shareholders, customers, and partners?&lt;/p&gt;&lt;p&gt;My job is to take those 50-plus tools, aggregate all the KPIs, and turn them into a meaningful assessment of Tenable’s &lt;a href="https://wtci.org/you-cant-protect-what-you-cant-see-inside-the-cyber-exposure-era-with-tenable/&amp;amp;sa=D&amp;amp;source=docs&amp;amp;ust=1784831467755149&amp;amp;usg=AOvVaw3PoQ1Mam5kFYbWF6h-Aob1"&gt;cyber exposure&lt;/a&gt; that leadership can easily understand. We have multiple lines of business aligned by different products, regions, and services. True cyber risk management means being able to answer questions like: What is the associated revenue tied to each individual line of business, what level of cyber risk does each one face, and how can this risk be most effectively mitigated?&lt;/p&gt;&lt;p&gt;Without business context, you simply cannot prioritize effectively.&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="https://www.tenable.com/sites/default/files/inline/images/Tenable%20One%20dashboard%20showing%20line-of-business%20cyber%20risk%20levels.jpeg" data-entity-uuid="eb264167-0570-41b4-b4f2-dbf4b8161996" data-entity-type="file" alt="Tenable One dashboard showing line-of-business cyber risk levels" width="1200" height="690" class="align-center" loading="lazy"&gt;&lt;p class="text-align-center"&gt;&lt;em&gt;&lt;sup&gt;Tenable One dashboard showing line-of-business cyber risk levels at a hypothetical enterprise&lt;/sup&gt;&lt;/em&gt;&amp;nbsp;&lt;/p&gt;&lt;h2&gt;How siloed security tools create business friction&lt;/h2&gt;&lt;p&gt;Unfortunately, the siloed nature of our security architecture created friction not just at the top, but across the entire business. When my team reached out to engineering and IT leaders, we frequently handed them numerous fragmented reports and manual spreadsheets for each security domain, including cloud security, vulnerability management, app security, pen testing, compliance auditing, and more.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The problem arose when these engineering leaders, who have critical day jobs building and maintaining our products, looked at me and asked: “Bob, what the heck do you want me to do? What do I start with? How do I prioritize that?”&lt;/p&gt;&lt;p&gt;Coordinating reporting, mitigations, and remediations became a massive challenge. It didn’t scale well for my security teams, and it certainly didn’t scale for the receiving engineering teams, whom we hit up every week for their time.&amp;nbsp;&lt;/p&gt;&lt;h2&gt;How AI complicates cyber risk management&lt;/h2&gt;&lt;p&gt;And then, our friend AI moved the goalposts again. Every day feels like Groundhog Day: You wake up, and the newest AI capability drops out of the sky. As we ramped our AI adoption internally, our attack surface continued to expand. We knew we needed to manage &lt;a href="https://www.tenable.com/solutions/ai-security"&gt;AI security&lt;/a&gt; risks alongside traditional cyber risks. We also knew we needed visibility and context to make informed decisions about which AI security risks we were going to accept so that we could continue to move at the speed of trust. But I knew our old, siloed approach was untenable at the speed we needed to operate.&lt;/p&gt;&lt;h2&gt;The turning point: An acquisition and exposure management&lt;/h2&gt;&lt;p&gt;To truly unify our risk posture, we fundamentally changed our organizational structure. We evolved our &lt;a href="https://www.tenable.com/solutions/vulnerability-management"&gt;vulnerability management&lt;/a&gt; team into an &lt;a href="https://www.tenable.com/exposure-management"&gt;exposure management&lt;/a&gt; team. We unified all our security areas into a single foundational exposure management policy. Instead of just managing traditional CVEs, the exposure management policy needed to encompass a wider range of security issues, including misconfigurations and identity weaknesses, across the massive, modern attack surface: identity systems, cloud workloads, AI tools, on-prem assets, the application development pipeline, and more.&lt;/p&gt;&lt;p&gt;Broadening the mandate of the vulnerability management team to encompass all forms of exposure represented a massive operational shift, but notably, it didn’t increase our headcount. Instead, by centralizing our data, other specialized teams, like &lt;a href="https://www.tenable.com/solutions/cloud-security"&gt;cloud security&lt;/a&gt; and application security, got time back to focus on securely deploying infrastructure rather than chasing down colleagues for &lt;a href="https://www.tenable.com/products/patch-management"&gt;patch management&lt;/a&gt;. The exposure management team became the centralized “go-get-’em” team across the board. They don’t operate all 50 tools, but they are the ones who triage everything.&lt;/p&gt;&lt;p&gt;I then tasked my exposure management team with solving the fragmentation problem. We wrestled with the issue of “build vs. buy.” Should we dump all of the data from all of our different tools into a giant data store, and try to add analysis, workflow and reporting to that, or should we look for alternative, out-of-the-box solutions that might already exist.&amp;nbsp;&lt;/p&gt;&lt;p&gt;In the end, we decided not to build it ourselves, largely because building and maintaining a data warehouse is not our core competency, and it can get very expensive, very quickly with infrastructure, data costs, and specialized staff. Instead, we evaluated a bunch of vendors that could help us centralize our risk data with existing SaaS solutions. We chose one specific solution that best fit our integration and workflow requirements. In the end, we ended up acquiring the entire company, &lt;a href="https://www.tenable.com/press-releases/tenable-completes-acquisition-of-vulcan-cyber"&gt;Vulcan Cyber, for these same reasons&lt;/a&gt;. And today, it is a foundational part of our &lt;a href="https://www.tenable.com/products/tenable-one"&gt;Tenable One Exposure Management Platform&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;As a result of shifting to an exposure management approach and consolidating security data within a single platform, the “spaghetti” chart got transformed into this:&lt;br&gt;&amp;nbsp;&lt;/p&gt;&lt;img src="https://www.tenable.com/sites/default/files/inline/images/Tenable%20EM%20journey%20unified%20chart.png" data-entity-uuid="9750577b-688e-49ac-9e28-7f957772d00b" data-entity-type="file" alt="A chart illustrating the streamlined results of implementing exposure management and consolidating security data within a single platform." width="960" height="540" class="align-center" loading="lazy"&gt;&lt;h2&gt;Bob’s simple metrics&lt;/h2&gt;&lt;p&gt;The manifestation of this journey within our own Tenable One platform is what my team lovingly calls, “Bob’s simple metrics.” We instituted a direct visualization using the traffic-light protocol: the colors red, yellow, and green to categorize the level of cyber exposure for each of our lines of business. Red signifies critical risk. Yellow means it needs attention. Green indicates a healthy security posture. We aggressively tagged assets to contextualize them, tying specific infrastructure directly to business units and revenue streams.&lt;/p&gt;&lt;p&gt;We also automated the identification of what I call the “big rocks.” For example, if we can’t patch an asset because of system instability, our platform flags this as a systemic root-cause issue rather than just blindly listing individual vulnerabilities. We now have customized service level agreements (SLAs) tailored by region and business impact, enabling teams to track their performance against these targets effortlessly.&lt;/p&gt;&lt;h2&gt;Build business trust with exposure management&lt;/h2&gt;&lt;p&gt;The aim of exposure management is to permanently change the conversation security leaders and their teams have with stakeholders. For instance, instead of overwhelming engineering teams with fragmented reports and drowning the board in 30 slides of operational metrics, we now provide a clear, data-driven workflow. We give the business a concise, prioritized list of actions that genuinely reduce risk.&lt;/p&gt;&lt;p&gt;Now is the time for exposure management. It is the only way to operate at machine speed. If you still have to manually schedule a patch window or pivot between 50 different dashboards to figure out your risk posture, you’ve already lost. Legacy vulnerability management is simply not going to work going forward.&amp;nbsp;&lt;/p&gt;&lt;p&gt;By breaking down security silos and unifying our risk data, we’ve built an exposure management program that the C-suite, the board, and the business can finally trust.&lt;br&gt;&lt;br&gt;&lt;a href="https://www.tenable.com/products/tenable-one"&gt;&lt;em&gt;Learn more about the Tenable One Exposure Management Platform&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/Bob%20Huber%20blog%20about%20EM%20maturity.png"&gt;
</description>
  <pubDate>Thu, 27 Aug 2026 10:30:00 -0400</pubDate>
    <dc:creator>Robert Huber</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211080</guid>
    </item>
<item>
  <title>Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeter</title>
  <link>https://www.tenable.com/blog/edge-infrastructure-under-siege</link>
  <description>&lt;p&gt;&lt;strong&gt;A joint Tenable-SentinelOne &lt;/strong&gt;&lt;a href="https://www.sentinelone.com/blog/what-two-independent-datasets-reveal-about-whos-exploiting-your-perimeter/"&gt;&lt;strong&gt;analysis&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt; of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness &amp;amp; Response for their contributions to this publication.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs.&lt;/p&gt;&lt;h2&gt;Key Takeaways&lt;/h2&gt;&lt;ol&gt;&lt;li data-list-item-id="e6ad884551589f0127895e23f1facbfc1"&gt;Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap.&lt;/li&gt;&lt;li data-list-item-id="ee874f52d119f66f5dfe35565b3cb11cc"&gt;Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware).&lt;/li&gt;&lt;li data-list-item-id="ee61af0cd2fb5540fc07ee74a260a0dd6"&gt;The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix.&lt;/li&gt;&lt;li data-list-item-id="e2d474909017fa82977ffe379dcf6ba6c"&gt;54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch.&lt;/li&gt;&lt;li data-list-item-id="e19c9c9fa27e2a65f18567ddc1a11c4a6"&gt;Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers.&lt;/li&gt;&lt;li data-list-item-id="e51610c928f752c9d20f5c9afd55d0110"&gt;The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months.&lt;/li&gt;&lt;li data-list-item-id="ec51a9a421506412a6a0ecd435746328c"&gt;Leverage multiple defense-in-depth strategies: patch as quickly as possible, but also minimize the attack surface (feature-set minimization) and run endpoints in protect mode to better stop lateral movement from attacks that gain initial access.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;The convergence is the story&lt;/h2&gt;&lt;p&gt;Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories. Four examples illustrate the pattern:&lt;/p&gt;&lt;table class="table"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;CVE&lt;/td&gt;&lt;td&gt;Product&lt;/td&gt;&lt;td&gt;Actors (Nexus)&lt;/td&gt;&lt;td&gt;Significance&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://www.tenable.com/cve/CVE-2026-15409"&gt;CVE-2026-15409&lt;/a&gt;&lt;/td&gt;&lt;td&gt;SonicWall SMA1000&lt;/td&gt;&lt;td&gt;UTA0533 (unattributed) + INC Ransomware&lt;/td&gt;&lt;td&gt;Espionage-to-ransomware succession on an active zero-day&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://www.tenable.com/cve/CVE-2023-42793"&gt;CVE-2023-42793&lt;/a&gt;&lt;/td&gt;&lt;td&gt;JetBrains TeamCity&lt;/td&gt;&lt;td&gt;APT29 (Russia) + Lazarus (DPRK)&lt;/td&gt;&lt;td&gt;Two state-sponsored actors from different nations on the same CVE&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://www.tenable.com/cve/CVE-2024-3400"&gt;CVE-2024-3400&lt;/a&gt;&lt;/td&gt;&lt;td&gt;PAN-OS GlobalProtect&lt;/td&gt;&lt;td&gt;UTA0218 (China) + INC Ransomware&lt;/td&gt;&lt;td&gt;China-nexus zero-day reused by ransomware operators&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://www.tenable.com/cve/CVE-2024-24919"&gt;CVE-2024-24919&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Check Point Quantum&lt;/td&gt;&lt;td&gt;PurpleHaze (China) + Fox Kitten (Iran)&lt;/td&gt;&lt;td&gt;China and Iran independently exploiting the same gateway vulnerability&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;The remaining eight confirmed multi-nexus CVEs span Fortinet, Citrix, Cisco, and Ivanti product lines. State-sponsored actors and ransomware operators are not operating in separate vulnerability ecosystems. They share the same entry points into the same products. &lt;strong&gt;The breadth of the convergence, not any single actor's activity, is the finding.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;That pattern holds across the full combined analysis. Three conclusions emerge:&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Vendor attack surfaces are the persistent exploitation target.&lt;/strong&gt; The same eleven vendors (i.e.,&lt;em&gt; Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta's React framework&lt;/em&gt;) appear in both observation systems at 79% convergence, and all seven edge-product vendors converge. Serial exploitation timing on Ivanti products shows the vulnerability-to-exploitation pipeline refreshing at 8.5 to 13-month intervals on the same product lines. This is structural, not episodic. Patching the current CVE does not remove the vendor attack surface from the threat landscape.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;State-sponsored and ransomware actors converge structurally.&lt;/strong&gt; Twelve CVEs with confirmed multi-nexus attribution span all five nexus categories and cross the state-criminal divide. Defending against one actor category on edge devices necessarily requires defending against all of them, because the attack surface is shared. An organization that patches only for nation-state TTPs leaves itself exposed to ransomware operators exploiting the same vulnerability, and vice versa.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;High-priority CVEs take more time to remediate, not less.&lt;/strong&gt; Across Tenable's 238-CVE high-priority list, high-priority CVEs carry a median remediation time of 146 days, compared to 122 days for all other CVEs — a 24-day gap that is statistically significant. The edge-appliance-specific subset (52 CVEs) shows a consistent 8-day gap in the same direction, which was not statistically significant, but suggests the direction may hold for edge appliances too. External data corroborates the pattern: the &lt;a href="https://www.tenable.com/blog/key-findings-from-the-verizon-dbir-2026"&gt;2026 Verizon Data Breach Investigations Report (DBIR)&lt;/a&gt; found that median patch time increased from 32 to 43 days year over year, even as exploitation overtook credential theft as the number one initial access vector, and the 2025 DBIR, which incorporated Tenable RSO's remediation trend analysis across 17 edge-related CVEs, found that only 54% of edge device KEVs were fully remediated. The explanation is structural: edge devices are the network boundary, so patching a VPN gateway or firewall means downtime for every user behind it, and change management gates multiply. These devices also resist standard patching workflows because they do not run endpoint agents, often require firmware-level updates with manual validation, and frequently lack active support contracts. The result is that the devices most worth patching are operationally the hardest to patch — and as the high-priority queue grows (the 2026 DBIR reports 50% more critical vulnerabilities to patch than the prior year), everything on it waits longer.&lt;/p&gt;&lt;h2&gt;Background&lt;/h2&gt;&lt;p&gt;Edge and perimeter devices occupy a uniquely consequential position in enterprise architecture. VPN gateways, firewalls, remote access appliances, and application delivery controllers sit at the boundary between trusted and untrusted networks. They are very often the first component an attacker touches and, for many organizations, the last component that gets patched. When one of these devices is compromised, the attacker inherits its network position: inside the perimeter, with access to internal resources, often without triggering endpoint detection.&lt;/p&gt;&lt;p&gt;This analysis combines two independent datasets to demonstrate that convergence. Tenable contributes exposure telemetry from the &lt;a href="https://www.tenable.com/products/tenable-one"&gt;Tenable One Exposure Management Platform&lt;/a&gt;, covering thousands of customer containers and measuring what edge infrastructure is deployed, what is vulnerable, and how long it remains unpatched. This dataset extends Tenable Research's ongoing analysis of edge device exposure trends, including the remediation telemetry Tenable contributed to the 2025 and 2026 Verizon DBIR reports. SentinelOne contributes findings from its digital forensics and incident response (DFIR) practice, documenting which threat actors actually exploit which vulnerabilities, observed firsthand inside compromised environments. Neither dataset was built for this analysis; each was constructed independently for different operational purposes.&lt;/p&gt;&lt;p&gt;The finding that makes this analysis compelling is not about any single CVE or any single actor. It is the structural convergence: two independent observation systems, looking at the problem from opposite sides, arrive at the same conclusion about which vendor surfaces are under persistent, broad exploitation, and by whom. (For how each dataset was built and scored, see the Methodology appendix below.)&lt;/p&gt;&lt;h2&gt;What's exposed: the vulnerability surface&lt;/h2&gt;&lt;p&gt;Tenable's exposure telemetry provides the vulnerability-side view. All exposure metrics reported here use container-grain measurement: the percentage of customer environments (organizational containers) with at least one asset vulnerable to a given CVE as of Aug. 15, 2026, relative to total exposed containers over the preceding 14-month period. This measures breadth of organizational exposure to edge-product vendor vulnerabilities, not raw asset counts, across the sampling window.&lt;/p&gt;&lt;p&gt;This section covers 15 vendors in three groups: seven confirmed in both independently compiled corpora, two confirmed in SentinelOne's casework but absent from Tenable's attributed corpus, and six "candidate" vendors surfaced by a broader screen of Tenable telemetry. The candidates are not part of the convergence finding, but two, F5 and Zimbra, show broader customer exposure than most of the confirmed seven, so omitting them would understate the breadth of at-risk edge infrastructure.&lt;/p&gt;&lt;img src="https://www.tenable.com/sites/default/files/images/blog/eb14ceba-054f-4426-a6b4-1a2a2314ada8.png" alt="Tenable Exposure Telemetry data sheet showing exposure breadth and remediation speed by vendor" width="2008" height="2048" referrerpolicy="no-referrer" loading="lazy"&gt;&lt;p&gt;[&lt;strong&gt;FIGURE: Current vendor-level exposure heat map&lt;/strong&gt; (&lt;em&gt;container-grain, 15 vendors&lt;/em&gt;). Proportion of historically-exposed containers with at least one asset actively exposed to one or more relevant CVEs. Source: Tenable exposure telemetry.]&lt;/p&gt;&lt;p&gt;&lt;strong&gt;F5 and Citrix lead for different reasons.&lt;/strong&gt; Among vendors with statistically robust sample sizes, F5 customers are the most broadly exposed: 53.8% of 2,784 monitored customer environments running F5 products have at least one actively exploited CVE present. Citrix customers show the slowest remediation patterns: a median of 461 days to patch, with 71% of affected environments still carrying unpatched Citrix CVEs after a full year. F5 leads on scale of exposure; Citrix leads on &lt;em&gt;persistent&lt;/em&gt; exposure.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;The mid-pack is flatter than expected.&lt;/strong&gt; Check Point (18.6%), Ivanti (24.1%), Fortinet (24.9%), and Citrix (28.8%) cluster within a 10-point band at container-grain. Fortinet, which dominates headlines, is mid-pack by this measure.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Thin-sample vendors show extreme rates but require caution.&lt;/strong&gt; Juniper (91.7%), VMware (75.0%), Palo Alto Networks (69.2%), and Cisco (56.2%) all show container-exposure proportions above 50%, but each has fewer than 50 in-sample containers. These statistics are real directional signals, but should be considered within the context of the relatively low sample size.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Serial exploitation is structural.&lt;/strong&gt; Two clean serial-exploitation sequences appear in the dataset: Ivanti EPMM (approximately 8.5 months between successive exploited CVEs) and Ivanti Connect Secure (approximately 13 months). Same product line, new vulnerability, repeat exploitation. Tenable Research has &lt;a href="https://www.tenable.com/blog/cve-2026-1281-cve-2026-1340-ivanti-endpoint-manager-mobile-epmm-zero-day-vulnerabilities"&gt;&lt;u&gt;published advisories&lt;/u&gt;&lt;/a&gt; on both Ivanti exploitation sequences, tracking each CVE from initial disclosure through active exploitation, and the exposure data here extends that analysis with organizational remediation timelines not available at the time of the original advisories. The next one is coming.&lt;/p&gt;&lt;h2&gt;Who exploits what: the threat actor landscape&lt;/h2&gt;&lt;p&gt;This is not a targeted effort by a specific group. Edge infrastructure is a core focal point of attack across a broad range of threat actors and nexus categories. The combined Tenable-SentinelOne corpus documents exploitation by actors spanning five nexus categories: China, Russia, DPRK, Iran, and criminal (financially motivated). All five categories independently target the same vendor surfaces. Every attribution in the corpus is bucketed into one of three confidence tiers derived from a five-dimensional rubric evaluating attribution directness, evidence provenance, recency, exploitation role, and source corroboration. Confidence tiers, from high to low, are: &lt;em&gt;DIRECT&lt;/em&gt;, &lt;em&gt;TECHNIQUE-ALIGNED&lt;/em&gt;, or &lt;em&gt;INFERRED&lt;/em&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Actor density scales with vendor exposure.&lt;/strong&gt; Fortinet products face the broadest actor surface: 29 distinct threat actors across five nexus categories. Citrix follows with 22 actors across five categories, Ivanti with 19 across four, Palo Alto Networks with nine across three, and Check Point with six across two. Every focal vendor has confirmed exploitation from multiple nexus categories. No single vendor's exposure is attributable to a single adversary group.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;China-nexus actors are the highest-confidence case study&lt;/strong&gt;, appearing across nine vendors in the corpus, with four DIRECT-tier attributions from the scored dataset alone. But the analytical value here is not that China targets edge devices. That is &lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a"&gt;&lt;u&gt;well established&lt;/u&gt;&lt;/a&gt;. The value is that China, Russia, DPRK, Iran, and ransomware operators all target the &lt;em&gt;same&lt;/em&gt; edge devices, as the examples above illustrate. The governed attribution methodology is what allows this claim to be made with precision: we can distinguish confirmed multi-nexus convergence (DIRECT-tier evidence on both sides) from assessed convergence (INFERRED, requiring corroboration).&lt;/p&gt;&lt;h2&gt;What incident response sees that telemetry can't&lt;/h2&gt;&lt;p&gt;Exposure data shows which appliances are reachable, vulnerable, and unpatched. Incident response looks at what happened when attackers got in: what they accessed, what they took, and where they went next. In SentinelOne DFIR cases involving edge infrastructure, attackers used credentials stored on the appliances and the access those appliances already had to reach internal systems.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Credential theft from edge appliances&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Across three engagements, threat actors reached the management plane of FortiGate appliances and created rogue administrative accounts. In two, they also exported device configurations and extracted credentials that could be used to move further into the network. Two of these three are documented in detail in &lt;a href="https://www.sentinelone.com/blog/fortigate-edge-intrusions/"&gt;&lt;u&gt;FortiGate Edge Intrusions&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;In one of those two, the exported configuration contained LDAP bind credentials for a directory service account. The account was later used in the environment. A few hours later, the threat actor added two computers to the domain. Neither had a Service Principal Name, which is unusual for a legitimate domain join. The mS-DS-CreatorSID attribute on both accounts pointed back to the stolen service account.&lt;/p&gt;&lt;p&gt;We saw similar activity on an Ivanti Cloud Services Appliance in late 2024. A China-nexus actor chained &lt;a href="https://www.tenable.com/cve/CVE-2024-8963"&gt;CVE-2024-8963&lt;/a&gt; with &lt;a href="https://www.tenable.com/cve/CVE-2024-8190"&gt;CVE-2024-8190&lt;/a&gt; before the first public disclosure in the chain. After gaining access, the actor collected SSH keys and other stored credentials. That engagement is documented as Activity F in &lt;a href="https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/"&gt;&lt;u&gt;Follow the Smoke&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;These appliances did not provide conventional endpoint telemetry. We had to follow the activity into authentication records, newly created Active Directory objects, and the later use of credentials taken from the appliances.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;When the initial access vector cannot be confirmed&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;In December 2025, Fortinet disclosed &lt;a href="https://www.tenable.com/cve/CVE-2025-59718"&gt;CVE-2025-59718&lt;/a&gt;, an authentication bypass in its FortiCloud SSO integration affecting FortiOS and other products. Several weeks later, Fortinet disclosed &lt;a href="https://www.tenable.com/cve/CVE-2026-24858"&gt;CVE-2026-24858&lt;/a&gt;. This second flaw allowed an attacker with a FortiCloud account and a registered device to log into devices belonging to other customers when FortiCloud SSO was enabled.&lt;/p&gt;&lt;p&gt;That overlap mattered in one of the three engagements above. The appliance was running a version affected by both CVEs, but the available logs did not show when or how the attacker first gained access. The earliest retained malicious activity showed a rogue local administrator account. A few minutes later, a domain administrator authenticated from the appliance's VPN address pool. Exposure data showed that the appliance had been vulnerable to both CVEs, but that alone did not establish how it was compromised. We treated both as possible, not confirmed, initial-access vectors.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Abuse of trusted management access&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;In one SentinelOne DFIR engagement involving a FortiManager appliance, &lt;a href="https://www.tenable.com/cve/CVE-2024-47575"&gt;CVE-2024-47575&lt;/a&gt; allowed an unauthorized device to register with the appliance through the management protocol. Two log entries, seconds apart, recorded the rogue registration and the settings change that followed. The threat actor then staged an archive of managed-device configurations that could expose credentials, addresses, and details about the network. The actor had been present for about a month before the customer detected the activity.&lt;/p&gt;&lt;p&gt;In a separate engagement, a threat actor chained SQL injection, pass-the-hash authentication, and authentication bypass against an internet-facing SonicWall GMS console (&lt;a href="https://www.tenable.com/cve/CVE-2023-34133"&gt;CVE-2023-34133&lt;/a&gt;, &lt;a href="https://www.tenable.com/cve/CVE-2023-34132"&gt;CVE-2023-34132&lt;/a&gt;, and &lt;a href="https://www.tenable.com/cve/CVE-2023-34124"&gt;CVE-2023-34124&lt;/a&gt;). The actor created administrative accounts on a platform operated by a managed service provider, then used existing shared access to enter multiple customer environments. Most of the resulting traffic was advertising-related, leading us to assess that the infrastructure was being used for click fraud.&lt;/p&gt;&lt;p&gt;The actors were after different things. One collected configuration data and information about the network. The other used the access to turn systems across several environments into proxies. In both cases, the actor inherited the access that the organization had already granted to the management platform. These cases show the difference between the two views: exposure telemetry finds the vulnerable device, while incident response shows what was taken from it and where the attacker went next.&lt;/p&gt;&lt;h2&gt;What to do about it&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Patch F5 and Citrix edge devices immediately.&lt;/strong&gt; These two vendors combine the highest exposure rates with the slowest remediation timelines across statistically robust samples. Look for strategies to reduce the remediation time, particularly for weaponized CVEs. Additionally, reduce the attack surface by minimizing the enabled feature set on these devices and aim for defense in depth by running endpoints in protect mode to limit lateral movement opportunities.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Audit Ivanti Connect Secure and EPMM deployments.&lt;/strong&gt; Serial exploitation on observed 8.5 to 13-month cycles means the next exploitable CVE in these product lines is a question of timing, not probability. Organizations running Ivanti edge products should assume they will face a new actively exploited vulnerability within the next year and plan patching capacity accordingly.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Implement edge-device-specific patch SLAs.&lt;/strong&gt; The delayed remediation paradox demonstrates that general priority frameworks do not translate into faster patching on the devices that sit at the network boundary. Edge devices and network infrastructure warrant dedicated remediation timelines that are shorter than the organizational default and commensurate with the elevated risk.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Treat edge device exposure as a cross-signal priority.&lt;/strong&gt; Attribution, severity, and exposure volume identify different CVEs as "top priority." Organizations need all three signals for complete coverage. A vulnerability management program that prioritizes exclusively by CVSS will systematically underweight CVEs with strong exploitation evidence but modest severity scores, and vice versa. The Tenable One Exposure Management Platform enables this cross-signal approach by combining vulnerability severity, exposure intelligence, asset context, and exposure data into a unified prioritization view.&lt;/p&gt;&lt;h2&gt;Identifying affected systems&lt;/h2&gt;&lt;p&gt;Tenable customers can use the Tenable Vulnerability Watch dashboard to monitor classifications for all CVEs discussed in this analysis. A list of Tenable plugins for the vulnerabilities discussed in this analysis can be found on the individual CVE pages at &lt;a href="https://www.tenable.com/cve"&gt;&lt;u&gt;tenable.com/cve&lt;/u&gt;&lt;/a&gt; as they are released. This link displays all available plugins for each vulnerability, including upcoming plugins in our &lt;a href="https://www.tenable.com/plugins/pipeline"&gt;&lt;u&gt;Plugins Pipeline&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;Get more information&lt;/h3&gt;&lt;ul&gt;&lt;li data-list-item-id="e050e4717103e24d046d88c21ba3c3948"&gt;&lt;a href="https://www.tenable.com/cve"&gt;&lt;u&gt;Tenable Vulnerability Watch&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="eb17ca02fd6e73c8f8a56d6fcdbfe522e"&gt;&lt;a href="https://www.sentinelone.com/blog/what-two-independent-datasets-reveal-about-whos-exploiting-your-perimeter/"&gt;SentinelOne – What two independent datasets reveal about who's exploiting your perimeter&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="e422e99942dffb796bd6bd9cae9ee64e6"&gt;&lt;a href="https://www.sentinelone.com/labs/"&gt;&lt;u&gt;SentinelOne Threat Research&lt;/u&gt;&lt;/a&gt; (PurpleHaze, SonicWall SMA1000)&lt;/li&gt;&lt;li data-list-item-id="e0246bb622236b8352bdd597a3f3c0940"&gt;&lt;a href="https://www.sentinelone.com/blog/fortigate-edge-intrusions/"&gt;&lt;u&gt;FortiGate Edge Intrusions&lt;/u&gt;&lt;/a&gt; – SentinelOne&lt;/li&gt;&lt;li data-list-item-id="e234e60b5170221a1fa06d613b8f293b5"&gt;&lt;a href="https://www.sentinelone.com/labs/follow-the-smoke-china-nexus-threat-actors-hammer-at-the-doors-of-top-tier-targets/"&gt;&lt;u&gt;Follow the Smoke&lt;/u&gt;&lt;/a&gt; – SentinelOne&lt;/li&gt;&lt;li data-list-item-id="e284922034cc4c03beaab3cb38a194b98"&gt;&lt;a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"&gt;&lt;u&gt;CISA Known Exploited Vulnerabilities Catalog&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Join &lt;/strong&gt;&lt;/em&gt;&lt;a href="https://connect.tenable.com/category/news-you-need/discussions/vulnerability-watch"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable's Research Special Operations (RSO) Team&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt; on Tenable Connect for further discussions on the latest cyber threats.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Learn more about &lt;/strong&gt;&lt;/em&gt;&lt;a href="https://www.tenable.com/products/tenable-one"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable One&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;, the Exposure Management Platform for the modern attack surface.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;h2&gt;Appendix: Methodology and corpus construction&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;How the corpus was built.&lt;/strong&gt; Tenable's 33-CVE corpus was derived by combining and deduplicating vulnerabilities with the highest exploitation volume and broadest actor adoption; SentinelOne validated CVEs across 14 vendors, and their 66-CVE landscape view reflects 12 months of DFIR casework with false positives removed. Combined, the two datasets identify 82 distinct CVEs, 17 of which appear in both. Layered on top of these sources is a governed attribution corpus of 93 CVE-actor pairs spanning approximately 39 named threat actors and five nexus categories.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Why Tenable tracks these CVEs.&lt;/strong&gt; Tenable's set comes out of exposure management. A CVE enters it through the &lt;a href="https://www.tenable.com/blog/reducing-remediation-time-remains-a-challenge-how-tenable-vulnerability-watch-can-help"&gt;Vulnerability Watch&lt;/a&gt; program, which classifies vulnerabilities under active or likely to be exploited, and is additionally scored with a &lt;a href="https://www.tenable.com/whitepapers/enhancements-to-tenable-vulnerability-priority-rating-vpr"&gt;Vulnerability Priority Rating (VPR)&lt;/a&gt;. The question being answered is prescriptive: of everything actually deployed across customer environments, what should be prioritized and patched first? Threat-actor attribution is layered on afterward from definitive and confidence-scored sources (e.g., Federal cybersecurity advisories).&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Why SentinelOne tracks these CVEs.&lt;/strong&gt; SentinelOne's set comes from the opposite direction: incident response. A CVE earns its place in their 12-month DFIR landscape because responders found it used in a real intrusion — the initial access vector in a case someone called them about. The question being answered is forensic: what happened here, and who did it? Coverage is shaped by who engaged them, not by install base.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What "overlap" means here.&lt;/strong&gt; Overlap was measured at two levels, and the answer changes sharply depending on which level you use.&lt;/p&gt;&lt;p&gt;At the level of the individual vulnerability, the two sets barely intersect. Only 17 of 82, or 21%, of CVEs are common to both. Tenable and SentinelOne are, for the most part, not looking at the same vulnerabilities. However, the datasets converge at the product level. &lt;strong&gt;Eleven of the 14 vendors in Tenable's focal CVE set appear in SentinelOne's 12-month DFIR landscape – a 79% convergence:&lt;/strong&gt; &lt;em&gt;Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta's React framework.&lt;/em&gt; That's 79% convergence at the vendor level against 21% at the CVE level. Three vendors did not conform: Apache and SAP were absent from SentinelOne's casework, and the one Progress case they worked on was closed as a false positive. &lt;strong&gt;Narrow the comparison to edge and remote-access infrastructure specifically, and the convergence is a perfect 100%.&lt;/strong&gt; Tenable's corpus independently identified seven edge vendors (&lt;em&gt;i.e., Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, and VMware&lt;/em&gt;). All seven appear in SentinelOne's casework. Two teams, working from unrelated evidence for unrelated purposes, arrived at the same seven vendors while sharing roughly one CVE in five.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Why the distinction matters.&lt;/strong&gt; "Different vulnerabilities, same vendors" is not a weaker version of "same vulnerabilities." It is a different and more actionable claim. Had both datasets converged on the same individual CVEs, the story would be that a specific handful of vulnerabilities is being widely exploited: patch those and the problem shrinks. What the data actually shows is that state-sponsored and criminal operators are independently arriving at the same small set of edge and remote-access product vendors, then finding their own separate ways in. The durable target is the vendor attack surface. Patching this quarter's Ivanti CVE does not remove Ivanti from anyone's target list.&lt;/p&gt;&lt;p&gt;&lt;em&gt;All third-party product names, logos, and brands mentioned in this publication are the property of their respective owners and are for identification purposes only. Use of these names, logos, and brands does not imply affiliation, endorsement, sponsorship, or association with the third party.&lt;/em&gt;&lt;/p&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/S1.png"&gt;
</description>
  <pubDate>Wed, 26 Aug 2026 09:00:00 -0400</pubDate>
    <dc:creator>Research Special Operations</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211099</guid>
    </item>
<item>
  <title>Frequently asked questions about the active threat to Siemens S7 Series PLCs</title>
  <link>https://www.tenable.com/blog/frequently-asked-questions-about-the-active-threat-to-siemens-s7-series-plcs</link>
  <description>&lt;p&gt;&lt;strong&gt;A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.&lt;/strong&gt;&lt;/p&gt;&lt;h2&gt;Key Takeaways&lt;/h2&gt;&lt;ol&gt;&lt;li data-list-item-id="ed91010e43e73ea84817e4d04599ed437"&gt;Unattributed threat actors are exploiting known weaknesses and unnecessary internet exposure to conduct reconnaissance and possible pre-positioning for future disruptive attacks against Siemens S7 Series PLCs.&lt;/li&gt;&lt;li data-list-item-id="eadc6b7b738cd0f849329cc7e18b3471e"&gt;The attackers are leveraging AI to build and refine exploit scripts faster than manual development would allow. AI use lowers the technical bar for ICS attacks in a way defenders haven't had to plan for before.&lt;/li&gt;&lt;li data-list-item-id="ecd0fdd5c92e74a1dddc742eab64512d2"&gt;There is no single patch, because there is no single flaw. Mitigation depends on removing Siemens S7 Series PLCs from direct internet exposure, segmenting OT from IT networks and hardening access controls.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Background&lt;/h2&gt;&lt;p&gt;On August 19, 2026, the National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), the Department of Energy (DOE) and the Environmental Protection Agency (EPA) released a joint &lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a"&gt;&lt;u&gt;Cybersecurity Advisory (AA26-231A)&lt;/u&gt;&lt;/a&gt; warning that threat actors are actively targeting Siemens S7 Series programmable logic controllers (PLCs) that are exposed to the internet or insufficiently segmented from it. The activity spans the S7-200, S7-300, S7-400, S7-1200 and S7-1500 series and most heavily affects the Critical Manufacturing, Energy, Water and Wastewater, Chemical, Food and Agriculture and Commercial Facilities sectors, with potential exposure in the Defense Industrial Base as well.&lt;/p&gt;&lt;p&gt;According to the authoring agencies, threat actors are using AI-generated exploitation scripts, disguised as legitimate operational technology (OT) monitoring tools, to conduct reconnaissance and build capability against exposed PLCs. The Tenable Research Special Operations Team (RSO) has put together this frequently asked questions (FAQ) blog to help security and OT teams understand the threats, the techniques involved and the mitigations offered by the authoring agencies. The advisory itself notes that ongoing PLC targeting is broader than Siemens alone and that all PLC owners and operators, regardless of vendor, should apply all relevant mitigations.&lt;/p&gt;&lt;h2&gt;FAQ&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;What is the active threat to Siemens S7 Series PLCs?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The advisory describes coordinated reconnaissance and capability-development activity against Siemens S7 Series PLCs that are internet-exposed or poorly segmented. According to the authoring agencies, the threat actors combine internet scanning services with AI-assisted scripting to build custom tools that can read and write PLC memory, configuration data, and ladder logic programs over the S7comm protocol, while masquerading as legitimate monitoring software.The agencies assess the activity as persistent reconnaissance intended to develop capabilities and pre-position for future disruptive attacks against critical infrastructure&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Which Siemens PLC models are being targeted?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The advisory identifies five Siemens S7 Series product lines as targets:&lt;/p&gt;&lt;div class="table-responsive"&gt;&lt;table class="table"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;&lt;strong&gt;Series&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Variants targeted&lt;/strong&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;S7-200&lt;/td&gt;&lt;td&gt;All CPU variants&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;S7-300&lt;/td&gt;&lt;td&gt;All CPU variants, including the 314, 315 and 317 models&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;S7-400&lt;/td&gt;&lt;td&gt;All CPU variants&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;S7-1200&lt;/td&gt;&lt;td&gt;CPU 1211C, 1212C, 1214C, 1215C and 1217C variants&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;S7-1500&lt;/td&gt;&lt;td&gt;All CPU variants including F-series safety controllers&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;How is this different from the Iranian-linked PLC campaign covered in AA26-097A?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;In April 2026, CISA and its partners, including NSA, the FBI, EPA, DOE, U.S. Cyber Command, and the Treasury Department, issued and later expanded &lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a"&gt;&lt;u&gt;cybersecurity advisory AA26-097A&lt;/u&gt;&lt;/a&gt;, which detailed a campaign publicly linked to Iran-affiliated actors tracked as &lt;a href="https://www.tenable.com/blog/what-to-know-about-cyberav3ngers-the-irgc-linked-group-targeting-critical-infrastructure"&gt;&lt;u&gt;CyberAv3ngers&lt;/u&gt;&lt;/a&gt;. That campaign exploited internet-exposed PLCs from Rockwell Automation, Schneider Electric and Siemens using the vendors' own engineering software to manipulate readings and exfiltrate project files. The updates to that advisory were made just days before the news of attacks involving several water districts, including those in Minnesota. For more information on these attacks, please refer to the RSO blog; &lt;a href="https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know"&gt;&lt;u&gt;Coordinated "cyberattack" on U.S. water utilities: What you need to know&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;This new advisory covers a distinct activity pattern specifically centered on the Siemens S7 Series devices. The authoring agencies do not attribute these attacks to any named threat actor or group. The techniques described in this advisory describe threat actors leveraging AI to design scripts built on open-source industrial automation libraries, including snap7.dll, disguising these scripts as monitoring tools. Organizations should treat the two advisories as related but separate threats to the same class of equipment, and should apply the mitigations in both if they operate Siemens S7 Series PLCs. However, as the advisory points out, regardless of which PLCs your organization may operate, the recommendations are to apply the proper mitigations to help secure these devices, including mitigations from &lt;a href="https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology"&gt;&lt;u&gt;this guide&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Which threat actors are behind this activity?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The authoring agencies have not attributed this activity to a specific named threat actor or group. The advisory refers to the activity generically as being conducted by "threat actors" and describes confirmed reconnaissance, tool development and read/write operations against target PLCs without confirmed attribution to a tracked group. Tenable's RSO team will update this post if attribution information becomes available.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What is new about the AI-assisted exploitation described in the advisory?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;According to the advisory, attackers are using AI to generate exploitation scripts, demonstrating a new capability dimension in the PLC targeting. The advisory describes threat actors combining publicly available open source industrial automation libraries (specifically snap7.dll and python-snap7) with AI-assisted scripting to create custom tools. These tools could be leveraged to provide read/write access to Siemens S7 Series PLC memory, configuration data and ladder logic programs via the S7comm protocol.&lt;/p&gt;&lt;p&gt;This represents an evolution in OT threat actor capabilities. AI dramatically reduces the technical expertise required to develop working ICS exploitation tools. Building functional S7comm exploitation scripts previously required specialized protocol knowledge and threat actor use of AI collapses that barrier. Coupling these capabilities with internet accessible devices provides attackers with abundant resources to test, iterate and rapidly improve their exploits.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Are specific CVEs associated with this advisory?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;No individual CVE identifiers are named in the advisory. Instead, the authoring agencies state that if these PLCs are exposed to the internet or insufficiently segmented, threat actors "can exploit various critical and high severity known vulnerabilities." The advisory directs owners and operators to consult Siemens ProductCERT advisories for model and firmware-specific vulnerability details or mitigation options if patches are not available or cannot be immediately applied.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Does this involve zero-day exploitation?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;No. The advisory describes exploitation of known vulnerabilities, weak or default credentials and unnecessary internet exposure, not a previously unknown or undisclosed flaw. The novel element the authoring agencies highlight is the use of AI to generate and rapidly iterate exploitation scripts and evasive tooling, not zero-day exploitation of an undisclosed vulnerability.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What techniques are the threat actors using?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The advisory maps the observed activity to the MITRE ATT&amp;amp;CK Matrix for ICS and MITRE ATT&amp;amp;CK Matrix for Enterprise frameworks:&lt;/p&gt;&lt;div class="table-responsive"&gt;&lt;table class="table"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;&lt;strong&gt;Tactic&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Technique&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;ID&lt;/strong&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Reconnaissance&lt;/td&gt;&lt;td&gt;Scanning services to find exposed PLCs&lt;/td&gt;&lt;td&gt;&lt;a href="https://attack.mitre.org/versions/v19/techniques/T1596/005/"&gt;&lt;u&gt;T1596.005&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Resource Development&lt;/td&gt;&lt;td&gt;Developing exploits to target known Siemens S7 Series vulnerabilities&lt;/td&gt;&lt;td&gt;&lt;a href="https://attack.mitre.org/versions/v19/techniques/T1587/004/"&gt;&lt;u&gt;T1587.004&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Resource Development&lt;/td&gt;&lt;td&gt;AI-assisted development of exploit code&lt;/td&gt;&lt;td&gt;&lt;a href="https://attack.mitre.org/versions/v19/techniques/T1588/007/"&gt;&lt;u&gt;T1588.007&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Lateral Movement&lt;/td&gt;&lt;td&gt;Accessing devices with default or improperly configured credentials&lt;/td&gt;&lt;td&gt;&lt;a href="https://attack.mitre.org/versions/v19/techniques/T1694/"&gt;&lt;u&gt;T1694&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Execution&lt;/td&gt;&lt;td&gt;Abuse AI-generated Python scripts developed using the snap7.dll library&lt;/td&gt;&lt;td&gt;&lt;a href="https://attack.mitre.org/versions/v19/techniques/T0834/"&gt;&lt;u&gt;T0834&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Execution&lt;/td&gt;&lt;td&gt;Write operations on data blocks&lt;/td&gt;&lt;td&gt;&lt;a href="https://attack.mitre.org/versions/v19/techniques/T0821/"&gt;&lt;u&gt;T0821&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Evasion&lt;/td&gt;&lt;td&gt;Masquerading malicious scripts as legitimate monitoring tools&lt;/td&gt;&lt;td&gt;&lt;a href="https://attack.mitre.org/versions/v19/techniques/T0849/"&gt;&lt;u&gt;T0849&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Collection&lt;/td&gt;&lt;td&gt;Perform reconnaissance by reading controller data&lt;/td&gt;&lt;td&gt;&lt;a href="https://attack.mitre.org/versions/v19/techniques/T0893/"&gt;&lt;u&gt;T0893&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;p&gt;&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Is there a proof-of-concept or working exploit code available?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The threat actors described in the advisory have functional, custom-built exploitation tooling in active use; this is not an unconfirmed or theoretical capability. However, the authoring agencies have not published this tooling and Tenable is not aware of a publicly available proof-of-concept (PoC) tied to this specific campaign as of the date this blog was published. Because the actors are using AI to generate and rapidly iterate their own scripts, organizations should not treat the absence of a public PoC as a reason to deprioritize mitigation.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What are the potential operational impacts?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The advisory outlines several potential consequences of unauthorized PLC access:&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="e13908f240454e38672675caef648fb9a"&gt;&lt;strong&gt;Disruption of critical industrial processes&lt;/strong&gt;. This can impact production throughput, product quality and public services&lt;/li&gt;&lt;li data-list-item-id="edaa48e4c3d825075d4a51c66b2708679"&gt;&lt;strong&gt;Safety incidents from manipulation&lt;/strong&gt;. This could lead to emergency shutdowns, manipulation of safety interlocks or manipulation of process parameters&lt;/li&gt;&lt;li class="ck-list-marker-bold" data-list-item-id="eceb686d3beb5bb31360caa9b26e63356"&gt;&lt;strong&gt;Equipment damage and extended operational downtime&lt;/strong&gt;&lt;/li&gt;&lt;li class="ck-list-marker-bold" data-list-item-id="e3aaa19ddff80fb1229d3619b95b0523a"&gt;&lt;strong&gt;Compromise of sensitive operational data&lt;/strong&gt;&lt;/li&gt;&lt;li data-list-item-id="eb5be4b28457bedc9410bcfe239408ca7"&gt;&lt;strong&gt;Cascading impacts&lt;/strong&gt; across interconnected systems, supply chains and dependent facilities&lt;/li&gt;&lt;li data-list-item-id="e044138ca1aeacff954107903d4fe4464"&gt;&lt;strong&gt;Regulatory compliance violations&lt;/strong&gt; tied to process safety management failures&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;Are patches or mitigations available?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Because this activity exploits internet exposure, improper configurations and a range of known vulnerabilities, rather than a single flaw, there is no single patch that resolves all risks related to this advisory. Instead, owners and operators are recommended to contact Siemens ProductCERT for firmware updates addressing known vulnerabilities in each affected CPU family, with priority given to internet-facing or DMZ-resident controllers. Additionally, the advisory outlines seven categories of hardening action:&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="e291c4e581a63fa4f191b9527b1fc12b4"&gt;Inventory all Siemens S7 Series PLCs and engineering workstations&lt;/li&gt;&lt;li data-list-item-id="e11640f24fb7ff94b47897a0ee8936de6"&gt;Applying current firmware and TIA Portal/STEP 7 updates&lt;/li&gt;&lt;li data-list-item-id="ef0236a028a0452d518d460a68cc6315c"&gt;Verifying segmentation and blocking TCP port 102 at the network perimeter&lt;/li&gt;&lt;li data-list-item-id="ef0ef2a675cbbd60fcb03e011cd9f213b"&gt;Strengthen access controls including restricting engineering software access and enabling PLC password protection and multi-factor authentication for remote OT access&lt;/li&gt;&lt;li data-list-item-id="ec124f687f33300846d36347ba9626785"&gt;Deploying ICS-aware monitoring and logging&lt;/li&gt;&lt;li data-list-item-id="e7e6184ef99551f2f43cb8a28f95e78cb"&gt;Security hardening including disabling unused protocols, web servers and default SNMP strings&lt;/li&gt;&lt;li data-list-item-id="ea40db4430a6653293cbabf6ab48930d4"&gt;Engaging Siemens Technical Support for model-specific guidance&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;What preventative actions should organizations take?&lt;/strong&gt;&lt;/p&gt;&lt;ol&gt;&lt;li data-list-item-id="e0921629a495a9cd810a3a2dcf2a1af78"&gt;&lt;strong&gt;Treat internet accessibility as the primary risk factor.&lt;/strong&gt; Any Siemens S7 Series PLC reachable from the internet, directly or through a third-party integrator's remote access path, should be treated as under active threat. Block TCP port 102 at the network perimeter and verify there is no unauthorized routing between corporate and OT networks.&lt;/li&gt;&lt;li data-list-item-id="ed29e5abc8d126623673844345e0e9fa7"&gt;&lt;strong&gt;Apply firmware updates&lt;/strong&gt; for your specific device models, prioritizing internet-facing and DMZ-resident controllers and test updates in a non-production environment before deployment.&lt;/li&gt;&lt;li data-list-item-id="ed3745d778069c82205a683b48546b41f"&gt;&lt;strong&gt;Restrict engineering software access.&lt;/strong&gt; Limit TIA Portal and STEP 7 access to authorized engineering workstations through MAC/IP allowlisting, enable PLC password protection and available protection levels and require multi-factor authentication for remote access into OT networks. Ensure engineering workstations are up to date with the latest software and security updates.&lt;/li&gt;&lt;li data-list-item-id="e9cb98a417b78f6031086fef288382e0f"&gt;&lt;strong&gt;Monitor for the specific indicators the advisory calls out:&lt;/strong&gt; snap7.dll or python-snap7 library usage outside approved engineering workstations, S7comm connections from non-engineering hosts, IP scanning on TCP port 102 and PUT/GET write operations to data blocks outside scheduled change windows.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Identifying affected systems&lt;/h2&gt;&lt;p&gt;Tenable customers can use the &lt;a href="https://www.tenable.com/products/tenable-one"&gt;&lt;u&gt;Tenable One Exposure Management Platform&lt;/u&gt;&lt;/a&gt;, including &lt;a href="https://www.tenable.com/products/ot-security"&gt;&lt;u&gt;Tenable One OT Exposure&lt;/u&gt;&lt;/a&gt;, to inventory Siemens S7 Series PLCs and other OT assets and prioritize remediation. Tenable One OT Exposure also provides continuous monitoring of your OT assets to provide deep visibility into your industrial control system networks and associated devices. If any individual Siemens S7 CVEs are confirmed relevant to this campaign, we will update this blog with relevant plugin coverage.&lt;/p&gt;&lt;p&gt;Tenable customers with &lt;a href="https://www.tenable.com/products/security-center"&gt;&lt;u&gt;Tenable Security Center&lt;/u&gt;&lt;/a&gt; or &lt;a href="https://www.tenable.com/products/vulnerability-management"&gt;&lt;u&gt;Tenable One Vulnerability Management&lt;/u&gt;&lt;/a&gt; can utilize the &lt;a href="https://connect.tenable.com/discussions/product-announcements/now-available-vm-native-ot-discovery/111595"&gt;&lt;u&gt;OT Recon&lt;/u&gt;&lt;/a&gt; scan policy to identify Siemens and other OT assets.&lt;/p&gt;&lt;h3&gt;Get more information&lt;/h3&gt;&lt;ul&gt;&lt;li data-list-item-id="e926aef690937040b052711dcf6f33a41"&gt;&lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-231a"&gt;&lt;u&gt;CISA Advisory AA26-231A: Defending Against an Active Threat to Siemens S7 Series PLCs&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="e66e7128d6530cba240ed7e806a64798a"&gt;&lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-097a"&gt;&lt;u&gt;CISA Advisory AA26-097A: Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="ecbf094e64011605982817520d9441885"&gt;&lt;a href="https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know"&gt;&lt;u&gt;Tenable Blog: Coordinated "cyberattack" on U.S. water utilities: What you need to know&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="e26278d6c0d75507d7352d189683570cc"&gt;&lt;a href="https://www.cisa.gov/resources-tools/resources/primary-mitigations-reduce-cyber-threats-operational-technology"&gt;&lt;u&gt;CISA: Primary Mitigations to Reduce Cyber Threats to Operational Technology&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="e8ade06713094c0631101a431701c39f8"&gt;&lt;a href="https://www.cisa.gov/resources-tools/resources/secure-connectivity-principles-operational-technology-ot"&gt;&lt;u&gt;CISA: Secure Connectivity Principles for Operational Technology&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="e31662a93dbedb6d1c1882870a197b627"&gt;&lt;a href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-265a"&gt;&lt;u&gt;CISA AA22-265A: Control System Defense: Know the Opponent&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="eca4431d793d817c0c343ef3201227e2b"&gt;&lt;a href="https://www.siemens.com/cert"&gt;&lt;u&gt;Siemens ProductCERT&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Join &lt;/strong&gt;&lt;/em&gt;&lt;a href="https://connect.tenable.com/category/news-you-need/discussions/vulnerability-watch"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable's Research Special Operations (RSO) Team&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt; on Tenable Connect for further discussions on the latest cyber threats.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Learn more about &lt;/strong&gt;&lt;/em&gt;&lt;a href="https://www.tenable.com/products/tenable-one"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable One&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;, the Exposure Management Platform for the modern attack surface.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/Siemens%20S7.png"&gt;
</description>
  <pubDate>Thu, 20 Aug 2026 10:01:58 -0400</pubDate>
    <dc:creator>Research Special Operations</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211093</guid>
    </item>
<item>
  <title>Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs</title>
  <link>https://www.tenable.com/blog/oracle-august-2026-critical-security-patch-update-cspu-addresses-925-cves</link>
  <description>&lt;p&gt;&lt;strong&gt;Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.&lt;/strong&gt;&lt;/p&gt;&lt;h2&gt;Key Takeaways&lt;/h2&gt;&lt;ol&gt;&lt;li data-list-item-id="e4216255a7fd79678947317f1e6da8ae6"&gt;The August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943 security updates&lt;/li&gt;&lt;li data-list-item-id="e505ada01a359330cc2aaeeb49f39b42e"&gt;154 issues (16.3% of all patches) were assigned a critical severity rating&lt;/li&gt;&lt;li data-list-item-id="ef7b30f40adc6f2504a1e778823aa3fdc"&gt;Oracle Fusion Middleware received the highest number of patches at 262, accounting for 27.8% of all patches&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Background&lt;/h2&gt;&lt;p&gt;On August 18, Oracle released its &lt;a href="https://www.oracle.com/security-alerts/cspuaug2026.html"&gt;&lt;u&gt;Critical Security Patch Update (CSPU) for August 2026&lt;/u&gt;&lt;/a&gt;. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 925 unique CVEs in 943 security updates across 23 Oracle product families, a nearly fourfold increase in patch volume compared to the June 2026 CSPU, which addressed 243 CVEs in 245 patches across 11 product families.&lt;/p&gt;&lt;p&gt;To put that in context against the quarterly CPUs: the April 2026 CPU contained 481 patches across 241 CVEs, and the July 2026 CPU, the largest CPU release of 2026, contained 1,449 patches across 1,235 CVEs. August's CSPU at 943 patches sits well above the April CPU and represents roughly 65% of July's quarterly volume, a striking figure for what is nominally a targeted between-cycle release. The expansion to 23 product families (up from 11 in June) further blurs the line between CSPU and CPU in terms of scope.&lt;/p&gt;&lt;img src="https://www.tenable.com/sites/default/files/inline/images/Oracle%20Critical%20Security%20Patch%20Update%20for%20August%202026%20-%20Security%20Patches.png" data-entity-uuid="340722e7-24a4-4e4c-8835-0f5994663717" data-entity-type="file" alt="Pie chart showing the count of patches released in the Oracle August 2026 Critical Security Patch Update (CSPU)" width="670" height="371" loading="lazy"&gt;&lt;p&gt;Out of the 943 security updates published, 16.3% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 59%, followed by medium severity patches at 21%.&lt;/p&gt;&lt;p&gt;This month's update includes 154 critical patches across 151 CVEs.&lt;/p&gt;&lt;div class="table-responsive"&gt;&lt;table class="table"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;&lt;strong&gt;Severity&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Issues Patched&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;CVEs&lt;/strong&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Critical&lt;/td&gt;&lt;td&gt;154&lt;/td&gt;&lt;td&gt;151&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;High&lt;/td&gt;&lt;td&gt;556&lt;/td&gt;&lt;td&gt;541&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Medium&lt;/td&gt;&lt;td&gt;198&lt;/td&gt;&lt;td&gt;198&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Low&lt;/td&gt;&lt;td&gt;35&lt;/td&gt;&lt;td&gt;35&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Total&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;943&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;925&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;h2&gt;Analysis&lt;/h2&gt;&lt;p&gt;This month's update saw the Oracle Fusion Middleware product family contain the highest number of patches at 262, accounting for 27.8% of the total patches, followed by Oracle Hyperion at 262 patches, which accounted for 27.8% of the total patches.&lt;/p&gt;&lt;p&gt;A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.&lt;/p&gt;&lt;div class="table-responsive"&gt;&lt;table class="table"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;&lt;strong&gt;Oracle Product Family&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Number of Patches&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Remote Exploit without Auth&lt;/strong&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;Oracle Fusion Middleware&lt;/td&gt;&lt;td&gt;262&lt;/td&gt;&lt;td&gt;182&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Hyperion&lt;/td&gt;&lt;td&gt;262&lt;/td&gt;&lt;td&gt;107&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle E-Business Suite&lt;/td&gt;&lt;td&gt;120&lt;/td&gt;&lt;td&gt;27&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Commerce&lt;/td&gt;&lt;td&gt;66&lt;/td&gt;&lt;td&gt;47&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Siebel CRM&lt;/td&gt;&lt;td&gt;50&lt;/td&gt;&lt;td&gt;21&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Supply Chain&lt;/td&gt;&lt;td&gt;46&lt;/td&gt;&lt;td&gt;18&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Virtualization&lt;/td&gt;&lt;td&gt;21&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Analytics&lt;/td&gt;&lt;td&gt;16&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle PeopleSoft&lt;/td&gt;&lt;td&gt;15&lt;/td&gt;&lt;td&gt;7&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Communications&lt;/td&gt;&lt;td&gt;13&lt;/td&gt;&lt;td&gt;9&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Enterprise Manager&lt;/td&gt;&lt;td&gt;11&lt;/td&gt;&lt;td&gt;6&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle MySQL&lt;/td&gt;&lt;td&gt;9&lt;/td&gt;&lt;td&gt;5&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Financial Services Applications&lt;/td&gt;&lt;td&gt;8&lt;/td&gt;&lt;td&gt;6&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Autonomous Health Framework&lt;/td&gt;&lt;td&gt;7&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Application Testing Suite&lt;/td&gt;&lt;td&gt;7&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Database Server&lt;/td&gt;&lt;td&gt;6&lt;/td&gt;&lt;td&gt;4&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle JD Edwards&lt;/td&gt;&lt;td&gt;6&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Java SE&lt;/td&gt;&lt;td&gt;5&lt;/td&gt;&lt;td&gt;4&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Retail Applications&lt;/td&gt;&lt;td&gt;5&lt;/td&gt;&lt;td&gt;5&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Essbase&lt;/td&gt;&lt;td&gt;4&lt;/td&gt;&lt;td&gt;3&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Food and Beverage Applications&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;td&gt;2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Construction and Engineering&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;Oracle Hospitality Applications&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;td&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;h2&gt;Solution&lt;/h2&gt;&lt;p&gt;Patches for all affected products are available in the &lt;a href="https://www.oracle.com/security-alerts/cspuaug2026.html"&gt;&lt;u&gt;August 2026 advisory&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;h2&gt;Identifying affected systems&lt;/h2&gt;&lt;p&gt;A list of Tenable plugins to identify these vulnerabilities will appear &lt;a href="https://www.tenable.com/plugins/search?q=%22%28August+2026+CSPU%29%22&amp;amp;sort=&amp;amp;page=1"&gt;&lt;u&gt;here&lt;/u&gt;&lt;/a&gt; as they're released. This link uses a search filter so that all matching plugin coverage appears as it is released.&lt;/p&gt;&lt;h3&gt;Get more information&lt;/h3&gt;&lt;ul&gt;&lt;li data-list-item-id="e2fa6cd5528001bc9c4de25b1d84aac7e"&gt;&lt;a href="https://www.oracle.com/security-alerts/cspuaug2026.html"&gt;&lt;u&gt;Oracle Critical Security Patch Update Advisory - August 2026&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="e09e9bf807b1ff670df8afec682509ee8"&gt;&lt;a href="https://www.oracle.com/security-alerts/cspuaug2026verbose.html"&gt;&lt;u&gt;Oracle August 2026 Critical Security Patch Update Risk Matrices&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="ec6e42802dba0ea84dceb2082c702f64f"&gt;&lt;a href="https://www.oracle.com/security-alerts/public-vuln-to-advisory-mapping.html"&gt;&lt;u&gt;Oracle Advisory to CVE Map&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Join&lt;/strong&gt;&lt;/em&gt; &lt;a href="https://connect.tenable.com/category/news-you-need/discussions/vulnerability-watch"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable's Research Special Operations (RSO) Team&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt; &lt;em&gt;&lt;strong&gt;on Tenable Connect for further discussions on the latest cyber threats.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Learn more about&lt;/strong&gt;&lt;/em&gt; &lt;a href="https://www.tenable.com/products/tenable-one"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable One&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;, the Exposure Management Platform for the modern attack surface.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/oracle-august-2026-critical-security-patch-update-cspu.png"&gt;
</description>
  <pubDate>Tue, 18 Aug 2026 20:41:38 -0400</pubDate>
    <dc:creator>Research Special Operations</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211090</guid>
    </item>
<item>
  <title>Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities</title>
  <link>https://www.tenable.com/blog/detecting-cloud-ransomware-in-azure-with-tenable-ones-cloud-detection-and-response</link>
  <description>&lt;p&gt;Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose Storm-0501 TTPs, backed by precision-engineered threat detection alerts.&lt;/p&gt;&lt;div class="blog-see-also"&gt;&lt;div class="col-sm-12"&gt;&lt;h2&gt;Key takeaways&lt;/h2&gt;&lt;ol&gt;&lt;li data-list-item-id="e65224f06c6a421e09593b21e4b017b96"&gt;Storm-0501 demonstrates that cloud-first ransomware groups have shifted from simple endpoint encryption to the total hijacking of cloud tenants.&lt;/li&gt;&lt;li data-list-item-id="e413aa242c4c9fed570fe229688978a3f"&gt;Storm-0501 systematically neutralizes resource locks, immutability policies, and backups, making the detection of these configuration changes critical for early intervention.&lt;/li&gt;&lt;li data-list-item-id="e007b2aa1c9f6f8f90ba2701729d77a2d"&gt;Detecting modern campaigns requires moving beyond static rules to a unified threat story that contextually connects the dots across the attack chain.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;/div&gt;&lt;h2&gt;From ransomware to cloud ransomware&lt;/h2&gt;&lt;p&gt;Historically, ransomware functioned as a localized threat: malicious software infected a workstation or server to encrypt local drives and hold specific host systems hostage.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Today, sophisticated ransomware actors like&lt;a href="https://attack.mitre.org/groups/G1053/"&gt; Storm-0501&lt;/a&gt; have fundamentally changed the battleground. Instead of relying on local malware execution, they target the cloud control plane itself. They hijack high-privilege administrative identities, weaponize native cloud tools, systematically dismantle defensive barriers, and compromise entire cloud tenants from the inside out.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Storm-0501, a financially motivated cybercrime group, exemplifies this tactical shift and has repeatedly demonstrated its proficiency in bridging on-premises Active Directory systems with cloud-native Microsoft Entra ID and Azure environments.&amp;nbsp;&lt;/p&gt;&lt;p&gt;In 2024, &lt;a href="https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/"&gt;Microsoft observed&lt;/a&gt; how Storm-0501 began expanding its on-premises ransomware tactics to the cloud, using cloud-native capabilities to evade detection, exfiltrate data, destroy data backups, and demand ransom payments.&lt;/p&gt;&lt;p&gt;This new reality of cloud ransomware demands more than endpoint monitoring; it requires &lt;a href="https://www.tenable.com/cloud-security/solutions/cloud-detection-and-response"&gt;cloud detection and response&lt;/a&gt; (CDR). CDR provides full visibility into the attack chain and identifies the surgical techniques employed by adversaries like Storm-0501.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Driven by deep threat intelligence on &lt;a href="https://www.microsoft.com/en-us/security/blog/2025/08/27/storm-0501s-evolving-techniques-lead-to-cloud-based-ransomware/"&gt;Storm-0501's evolving tactics, techniques, and procedures (TTPs&lt;/a&gt;), &lt;a href="https://www.tenable.com/cloud-security/products/cnapp"&gt;Tenable One Cloud Exposure&lt;/a&gt; maps these sophisticated maneuvers to ensure robust protection across the entire attack chain and to extend preemptive &lt;a href="https://www.tenable.com/exposure-management"&gt;exposure management&lt;/a&gt; into post-compromise incident response.&lt;/p&gt;&lt;p&gt;Even in scenarios where initial breach access slips past existing security controls, Tenable One's contextual detections empower your defenders to maintain control, trace lateral movement, and neutralize fast-moving attacks before threat actors can seize, encrypt, exfiltrate, and destroy your organization’s critical data.&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Unmasking Storm-0501 TTPs: A guided walkthrough&lt;/h2&gt;&lt;p&gt;In the following video, we demonstrate the CDR capabilities of Tenable One and how it aggregates Azure activity logs into a cohesive threat story, mapping Storm-0501 capabilities directly to the &lt;a href="https://attack.mitre.org/"&gt;MITRE ATT&amp;amp;CK framework&lt;/a&gt;. You will also see the specific detections required to expose and intercept these tactics.&lt;/p&gt;&lt;img class="vidyard-player-embed" src="https://play.vidyard.com/9tcSeKBn6woHeuXnMm2xp3.jpg" alt="Demo video about Tenable One Cloud Exposure's cloud detection and response capabilities" width="100%" height="100%" data-uuid="9tcSeKBn6woHeuXnMm2xp3" data-v="4" data-type="inline" loading="lazy"&gt;&lt;h2&gt;From detection to action: Rapid triage and containment&lt;/h2&gt;&lt;p&gt;Defenders can immediately use Tenable One’s CDR capabilities, with &lt;a href="https://connect.tenable.com/discussions/product-announcements/transform-disparate-isolated-alerts-to-one-threat-story-with-tenable%E2%80%99s-cloud-det/112070"&gt;AI-powered threat stories&lt;/a&gt;, to guide surgical containment of a Storm-0501 cloud ransomware campaign. By consolidating fragmented Azure activity logs into a clear chronological timeline, Tenable One eliminates hours of manual log parsing and enables security teams to execute the following containment actions immediately:&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="e82c6501c372645c381f0be8f6a9d1079"&gt;&lt;strong&gt;Scope and revoke identities&lt;/strong&gt;: Use the timeline to identify the initial breach point of an &lt;a href="https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/permissions-reference"&gt;Entra ID Global Administrator role&lt;/a&gt;. Immediately terminate all active sessions, revoke refresh tokens, and rotate credentials for the compromised accounts.&lt;/li&gt;&lt;li data-list-item-id="e17a3f374a95834bd1cf48afe5c4eebf6"&gt;&lt;strong&gt;Revert rogue access&lt;/strong&gt;: Trace role-assignment events in the events explorer dashboard in Tenable One to strip attacker-assigned owner privileges across affected subscriptions and delete any unauthorized persistence accounts or guest users.&lt;/li&gt;&lt;li data-list-item-id="e5ec1c6b29e8ccaa66c70197dfc1ff11e"&gt;&lt;strong&gt;Analyze the blast radius&lt;/strong&gt;: Investigate additional resources associated with the attacker using the events explorer page.&lt;/li&gt;&lt;li data-list-item-id="e7a718067a4d205ca2762e2b43c5e5357"&gt;&lt;strong&gt;Restore defenses&lt;/strong&gt;: If the alert trail indicates deleted &lt;a href="https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/using-resource-locks-to-prevent-accidental-changes-in-azure/3842402"&gt;Azure Resource Locks&lt;/a&gt;, immutability policies, or &lt;a href="https://learn.microsoft.com/en-us/azure/backup/backup-azure-recovery-services-vault-overview"&gt;Azure Recovery Services&lt;/a&gt; vaults, immediately re-apply these defensive barriers to all surviving cloud infrastructure.&lt;/li&gt;&lt;li data-list-item-id="efbbf4f5976b51051cfa5c5827de5e6a8"&gt;&lt;strong&gt;Recover adversary-created keys&lt;/strong&gt;:&lt;strong&gt; &lt;/strong&gt;If the adversary created an unauthorized &lt;a href="https://azure.microsoft.com/en-us/products/key-vault"&gt;Azure Key Vault&lt;/a&gt; or encryption scope to lock your storage accounts, revoke adversary access first, then restore the soft-deleted keys, take ownership of the vault, and re-encrypt data under your own keys before the soft-delete window expires.&lt;/li&gt;&lt;/ul&gt;&lt;h2&gt;Azure cloud security: How to protect infrastructure against cloud ransomware&lt;/h2&gt;&lt;p&gt;The campaign orchestrated by Storm-0501 underscores that modern defenders can no longer rely on disparate alerts. They need a unified view that connects the dots. Tenable One’s CDR capabilities provide that clarity, context, and insight, turning attackers’ complex cloud maneuvers into a clear, actionable threat story that empowers organizations to intercept ransomware at the earliest stage possible.&lt;/p&gt;&lt;p&gt;&lt;em&gt;Note: Tenable continuously monitors attacker campaigns and the threat landscape; therefore, additional detection rules will be released to provide an even more comprehensive coverage against this threat actor and others.&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;a href="https://www.tenable.com/data-sheets/tenable-one-cloud-exposure-cloud-detection-and-response-cdr"&gt;&lt;em&gt;Learn more about Tenable One’s CDR capabilities.&amp;nbsp;&lt;/em&gt;&lt;/a&gt;&lt;/p&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/Detecting%20cloud%20ransomware%20in%20Azure%20with%20Tenable%20One%E2%80%99s%20cloud%20detection%20and%20response%20capabilities.png"&gt;
</description>
  <pubDate>Mon, 17 Aug 2026 11:15:00 -0400</pubDate>
    <dc:creator>Clément Notin</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211082</guid>
    </item>
<item>
  <title>The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure</title>
  <link>https://www.tenable.com/blog/the-agentic-ai-threat-cluster-seven-incidents-three-actors-and-what-they-mean</link>
  <description>&lt;p&gt;&lt;strong&gt;Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous offensive AI has crossed from theoretical risk to operational reality.&lt;/strong&gt;&lt;/p&gt;&lt;h2&gt;Key Takeaways&lt;/h2&gt;&lt;ol&gt;&lt;li data-list-item-id="eb8ef29eeebcca6a019606b75830a6d97"&gt;Taiwan's Ministry of Digital Affairs confirmed a near-autonomous AI cyber attack in July 2026 in which autonomous agents mapped 21 connected government systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records in approximately four days.&lt;/li&gt;&lt;li data-list-item-id="e35795c8bb7bf8562ca324ab8883cf98c"&gt;The Taiwan campaign is part of a broader seven-incident agentic AI threat cluster that also includes JADEPUFFER, which exploited CVE-2025-3248 in the Langflow AI workflow platform for automated database extortion, and knaithe/KnYuan, a Chinese-speaking operator assessed by Unit 42 with moderate confidence, using the same AI agent framework for autonomous vulnerability scanning.&lt;/li&gt;&lt;li data-list-item-id="e259fabe235ecae545c6f39622e074a20"&gt;The common entry point across all cluster activity is identity and authentication exposure: discoverable federation endpoints, weak credentials, and misconfigured SSO are the conditions autonomous agents exploit at machine speed, and Tenable One can identify this class of risk in customer environments.&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;Background&lt;/h2&gt;&lt;p&gt;The Taiwan autonomous AI cyber attack, confirmed by Taiwan’s Ministry of Digital Affairs on Aug. 13, 2026, is the highest-profile event in a broader pattern Tenable’s RSO team has been tracking as an intelligence cluster since July 21, 2026. That cluster now encompasses seven confirmed incidents of autonomous or semi-autonomous AI systems deployed for offensive cyber operations or escaping containment boundaries, spanning November 2025 through August 2026.&lt;/p&gt;&lt;p&gt;The Taiwan campaign is the anchor finding, but it is not the whole story. In late July, Palo Alto Networks’ Unit 42 independently documented a separate Chinese-speaking individual operator using the same underlying AI agent framework for autonomous vulnerability scanning. Before either of those events became public, the RSO team was already tracking JADEPUFFER, the first documented agentic threat actor, which exploited an AI workflow platform for initial access and pivoted to database extortion. Three additional agentic AI exploitation incidents emerged during Q1 and Q2 of 2026. And on the defensive side, a confirmed AI sandbox escape incident involving a frontier model demonstrated that autonomous systems can break containment from the inside, not just be weaponized from the outside.&lt;/p&gt;&lt;p&gt;Tenable’s RSO team assesses that these events are not coincidental. They represent two sides of the same exposure condition: autonomous AI systems operating beyond the boundaries their developers intended. This FAQ explains what the cluster contains, what the Taiwan anchor event revealed, and what the cluster reveals about the broader exposure condition.&lt;/p&gt;&lt;h2&gt;FAQ&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;What happened in the Taiwan AI cyber attack?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Between July 1 and July 4, 2026, a suspected China-linked operator ran a four-day intrusion campaign against Taiwanese government infrastructure across 12 distinct attack waves. Starting from a single government portal, autonomous AI agents mapped 21 connected systems, compromised 85 accounts, and exfiltrated more than 2,564 personnel records. The operation then expanded beyond its initial foothold to reach Taiwan’s national nuclear safety agency, seven energy companies, government IT supply chain vendors, and a government email system.&lt;/p&gt;&lt;p&gt;Dream Security's chief strategy officer, Amir Becker, a former member of Israel's Unit 8200, characterized the level of autonomy demonstrated as unprecedented against a government target, according to SecurityAffairs reporting. Taiwan’s Ministry of Digital Affairs confirmed the attack on Aug. 13, 2026, but did not publicly attribute it to a specific state.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;How did the AI agents conduct the attack autonomously?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The operator assembled a multi-agent framework from two open-source AI agent projects, Hermes Agent and OpenClaw, and added Bayesian decision engines capable of coordinating up to eight parallel sub-agents per attack wave. Rather than following a fixed script, the agents scraped the government portal's publicly accessible authentication metadata: the federated sign-on endpoints, service identifiers, and identity-provider configuration that interconnected web applications routinely expose, then used what they found to independently discover and map the 21 connected systems behind it. In what Dream Security described as a fully autonomous decision, the agents followed a URL from the portal's JavaScript bundles to a GitBook documentation site hosting the national SSO integration guide, scraped the documentation using GitBook's built-in content features, and downloaded two SDK integration projects. Dream's analysis notes that while the agents ran automated code review on the SDK samples, none of those findings produced confirmed exploits. The actual breaches came from server-side flaws discoverable through standard black-box testing.&lt;/p&gt;&lt;p&gt;To acquire credentials, the agents generated password variations based on employee identifiers and automatically solved CAPTCHA challenges through optical character recognition, compromising 85 accounts without a human operator manually testing each one. The agents also bypassed their own AI safety guardrails by reframing the offensive operation as “authorized penetration testing,” a novel prompt-based technique with no current mapping in the MITRE ATT&amp;amp;CK framework. Throughout the operation, the agents pulled exploitation techniques from public vulnerability databases and GitHub in real time rather than relying on a pre-loaded set of exploits, a pattern Tenable’s RSO team assesses as genuine adaptive behavior rather than simple scripted branching.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Did the attackers exploit a specific vulnerability or zero-day?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;No single classifiable Common Vulnerabilities and Exposures (CVE) entry drove this campaign. Instead, the AI agents dynamically identified and abused misconfigurations, exposed administrative interfaces, and weak credentials already present in the target environment, sourcing exploitation techniques from public databases as they went. Tenable’s RSO team regards this absence as analytically significant: it demonstrates an attack category that a purely CVE-centric defensive model cannot fully address, because the exposure is the target’s entire discoverable attack surface rather than one known vulnerability.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Who was behind the attack?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Dream Security's linguistic analysis of the recovered 160MB archive found that internal operator communications were in Simplified Chinese while the exfiltrated government data was in Traditional Chinese. The targeting sequence (government portal, then nuclear safety agency, then energy sector) also aligns with previously documented Chinese strategic intelligence collection priorities against Taiwan.&lt;/p&gt;&lt;p&gt;Attribution currently rests on a single primary source. Dream Security is the sole entity that has published technical and linguistic analysis of the archive, and no second vendor has yet corroborated a link to a specific Chinese state entity. Tenable’s RSO team evaluated three competing attribution hypotheses (state-sponsored, state-adjacent contractor, and false flag) and assesses a state-adjacent contractor or patriotic hacker origin as the leading explanation, with state sponsorship as a close runner-up that cannot be excluded.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What is the connection to the Unit 42 findings on knaithe/KnYuan?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;On July 30, 2026, roughly two weeks before the Taiwan campaign became public, Unit 42 published research on a separate Chinese-speaking individual operator tracked as knaithe (also known as KnYuan), assessed with moderate confidence as operating out of Zhuhai, China. Unit 42 discovered the actor after a misconfigured Hermes Agent instance accidentally exposed the actor's full operational workspace. Unit 42's report details the exposed contents: tool configurations, API credentials, exploit scripts, target lists, and session logs from autonomous exploitation runs.&lt;/p&gt;&lt;p&gt;Knaithe/KnYuan used Hermes Agent paired with the DeepSeek reasoning model to run autonomous vulnerability-scanning campaigns against Langflow and n8n instances, and separately achieved confirmed data exfiltration from three Citrix NetScaler targets and command execution on 11 Marimo Notebook endpoints through manual exploitation. The actor has no known connection to the Taiwan operator, but the two cases share the same underlying framework and demonstrate that autonomous AI offensive capability is not confined to a single well-resourced group.&lt;/p&gt;&lt;p&gt;An individual operator, working alone, independently built comparable tooling, evidence the RSO team views as confirmation that the barrier to entry for this class of attack is collapsing.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What is the broader agentic AI threat cluster?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The Taiwan campaign is the most visible event, but Tenable’s RSO team is tracking it as one node in a cluster of seven confirmed incidents. The cluster includes three categories of activity.&lt;/p&gt;&lt;p&gt;First, offensive weaponization: the Taiwan campaign operator, the knaithe/KnYuan autonomous scanning operation, and JADEPUFFER, the first documented agentic threat actor tracked by the RSO team, which demonstrated agentic AI capability by exploiting Langflow and pivoting to database extortion before either the Taiwan or Unit 42 reports were published. Security vendors documented three additional early-stage agentic exploitation incidents during Q1 and Q2 of 2026.&lt;/p&gt;&lt;p&gt;Second, defensive AI escape: a confirmed sandbox escape by a frontier AI model during legitimate safety testing demonstrated that advanced AI systems can independently breach their containment boundaries without any adversary involvement. Other AI laboratories have reported similar incidents, reinforcing the pattern.&lt;/p&gt;&lt;p&gt;The RSO team treats these as a single analytical cluster because they share the same root exposure condition: autonomous AI systems acting beyond the boundaries their operators intended. Whether the system was weaponized by an attacker or broke out during legitimate use, the downstream risk to organizations is the same, systems they assumed were controlled were not. This is why the RSO team classifies the open-source AI agent framework weaponization pattern and the broader AI governance gap as distinct exposure conditions tracked under the same cluster umbrella.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What makes this different from previous AI-assisted cyber attacks?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The individual Taiwan campaign is significant on its own terms, but the cluster pattern is what changes how organizations need to think about risk. Earlier AI-assisted intrusions used AI to accelerate a specific step, such as writing phishing content or triaging scan output, while a human operator directed the overall operation. The Taiwan campaign compressed reconnaissance, credential attacks, and lateral expansion into a continuous, largely self-directed sequence: the agents chose which systems to map, which techniques to pull from public sources, and when to expand into new sectors, all without step-by-step human direction. Kevin Surace, CEO of TokenCore, &lt;a href="https://www.scworld.com/news/taiwan-confirms-ai-assisted-cyberattack-on-government-systems"&gt;&lt;u&gt;described the operation&lt;/u&gt;&lt;/a&gt; as “near-autonomous rather than completely independent,” adding that "humans still selected the targets, defined the objectives, assembled the framework, and reportedly persuaded the underlying model that the operation was an authorized security test." Tenable’s RSO team adopts the same “near-autonomous” framing.&lt;/p&gt;&lt;p&gt;What elevates this beyond a single incident is the convergence the cluster reveals. Two unrelated actors independently adopted the same framework. A third actor (JADEPUFFER) demonstrated agentic capability through a different operational pattern. AI systems escaped containment without adversary involvement. The barrier to entry collapsed far enough that a solo operator in Zhuhai built comparable tooling to what was used against a national government. As Trey Ford observed, this is “not the first AI-driven government attack,” but rather “the first one we’ve heard about.” The cluster data suggests he is right.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What does the tradecraft analysis reveal about how these attacks actually work?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Tenable’s RSO team conducted structured tradecraft profiling across all three actors and the anchor campaign to understand how agentic AI attacks compare to conventional intrusions at the operational level. Four findings stand out.&lt;/p&gt;&lt;p&gt;First, agentic AI tradecraft is additive, not transformative. The innovation in this cluster is concentrated in one dimension: the use of AI agents as the execution engine. Everything else, the command-and-control infrastructure, the initial access vectors, the operational security practices, remains at commodity levels. The Taiwan operator’s AI agents autonomously mapped 21 systems and compromised 85 accounts, but the underlying techniques they used (credential brute force against weak passwords, abuse of discoverable OAuth and Keycloak metadata, exploitation of publicly known vulnerabilities) are familiar. What changed is the speed, parallelism, and self-direction with which those techniques were applied. For defenders, this means the kill chain itself has not fundamentally changed. What has changed is the tempo at which an attacker can execute it.&lt;/p&gt;&lt;p&gt;Second, the convergence across unrelated actors is not coincidental, and the tradecraft data confirms it. When the RSO team compared the operational profiles of the Taiwan operator, knaithe/KnYuan, and JADEPUFFER, all three produced strikingly similar capability levels despite having no organizational relationship, shared training, or common infrastructure. The similarity is structural: the same freely available open-source tools (Hermes Agent, OpenClaw, DeepSeek) impose a common operational template on anyone who uses them. This is the clearest evidence that the barrier to autonomous AI offensive capability has collapsed. The tools define the tradecraft, and the tools are available to everyone.&lt;/p&gt;&lt;p&gt;Third, these actors are not living off the land. The RSO team estimates the substantial majority of the observed tradecraft in this cluster was AI-agent-driven rather than reliant on the target environment’s native tools. The small portion that did leverage target infrastructure involved abusing the inherent discoverability of federated authentication systems (OAuth discovery endpoints, OpenID Connect metadata, Keycloak realm configurations). This matters for detection strategy: catching agentic AI intrusions requires a different detection model than living-off-the-land indicators that flag conventional APT activity. The detection focus can be on execution-layer anomalies, specifically the behavioral signatures of AI-driven reconnaissance, automated credential campaigns, and parallel multi-target scanning.&lt;/p&gt;&lt;p&gt;Fourth, the speed of adaptation compresses the defender’s window to near zero. In the JADEPUFFER campaign documented by Sysdig, an AI agent diagnosed a failed credential insertion, identified the cause as a missing runtime dependency in the execution environment, and issued a corrective multi-step payload within 31 seconds. Traditional incident response timelines assume minutes to hours between attacker actions. Agentic AI eliminates that breathing room. Every exposed credential, every misconfigured authentication endpoint, every unpatched service will be found and will be exploited at machine speed. The window between exposure and compromise is collapsing, which makes foundational cyber hygiene (patching, hardening, reducing the discoverable attack surface) more urgent than it has ever been, not less.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;How does this affect organizations deploying AI agents?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;The attack surface the Taiwan agents exploited is not specific to Taiwanese government infrastructure. Any organization running interconnected web applications with centralized authentication (OAuth or OpenID Connect federation, SAML providers, or Keycloak deployments) exposes the same category of discoverable metadata the Taiwan operator's agents used to map 21 systems from a single entry point. The methodology is geography-agnostic: the agents require only one foothold and self-discover everything else.&lt;/p&gt;&lt;p&gt;The Taiwan agents also autonomously discovered and scraped a GitBook documentation portal hosting the national SSO integration guide, using GitBook's built-in content features to download SDK integration samples. Organizations that host developer documentation, API guides, or integration resources on publicly accessible platforms treat that content as part of the discoverable attack surface: autonomous agents will find it.&lt;/p&gt;&lt;p&gt;Separately, organizations that deploy their own AI agents face an additional governance exposure. &lt;a href="https://www.kiteworks.com/sites/default/files/resources/kiteworks-report-data-security-compliance-risk-2026-forecast-report.pdf"&gt;&lt;u&gt;Industry survey data&lt;/u&gt;&lt;/a&gt; from Kiteworks indicates that 63% of organizations cannot enforce purpose limitations on the AI agents they deploy, 60% cannot quickly terminate a misbehaving agent, and 55% cannot isolate AI systems from broader network access. The Cybersecurity and Infrastructure Security Agency (CISA) and Five Eyes partners published joint guidance titled "Careful Adoption of Agentic AI Services" in May 2026, identifying privilege escalation, design and configuration failures, behavioral misalignment, structural brittleness, and accountability gaps as the core risk categories. These are two distinct exposure categories: being targeted by AI agents and governing your own, but both require action now.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;What can organizations do to protect themselves?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;This campaign is a forcing function to address two distinct exposure categories. First, the identity and authentication weaknesses the Taiwan attacker actually exploited (exposed discovery endpoints, weak credentials, and misconfigured federation) exist in most enterprise environments today and are exactly the kind of foothold agentic AI will find at machine speed. Second, organizations deploying their own AI agents face the governance gaps Kiteworks documented: if you cannot enforce purpose limitations or terminate a misbehaving agent, you share the same structural vulnerability from the inside. Neither category has a single patch. Both require architectural and operational changes.&lt;/p&gt;&lt;ol&gt;&lt;li data-list-item-id="e46b325149c5210206e1d061e1d1926b3"&gt;&lt;strong&gt;Audit public-facing authentication surfaces for information disclosure.&lt;/strong&gt; Review OAuth, OpenID Connect discovery endpoints, and Keycloak realm configurations for unnecessary public exposure, since the Taiwan operator’s entire ecosystem map originated from data these interfaces exposed voluntarily. The Taiwan agents autonomously discovered a GitBook documentation portal hosting the national SSO integration guide, scraped it, and downloaded SDK integration samples, all from a single URL embedded in the portal's JavaScript. Publicly accessible developer documentation, integration guides, and SDK samples are part of the discoverable attack surface that agentic AI will find.&lt;/li&gt;&lt;li data-list-item-id="e457f2aee009fd42db0a5d311ea037687"&gt;&lt;strong&gt;Deploy behavioral detection for automated reconnaissance and credential attacks&lt;/strong&gt;, including quick sequential API enumeration, mass credential testing paired with CAPTCHA solve-and-retry patterns, and parallel scanning of multiple connected systems within minutes of an initial compromise. Indicator-based detection alone is insufficient because autonomous AI agent traffic closely resembles legitimate security testing.&lt;/li&gt;&lt;li data-list-item-id="e99825ea9d112251a9cbc90d18fe37e42"&gt;&lt;strong&gt;Reduce the discoverable attack surface.&lt;/strong&gt; The Taiwan agents built their entire operation from information the target environment volunteered: authentication metadata, API endpoints, developer documentation, and SDK integration guides hosted on publicly accessible platforms. Audit what internet-facing applications expose through JavaScript bundles, discovery endpoints, documentation portals, and integration resources. If it helps a legitimate developer integrate, it helps an autonomous agent map your environment.&lt;/li&gt;&lt;li data-list-item-id="ed2c58372ce02ec711f19b1f56c79b33a"&gt;&lt;strong&gt;Close the purpose-limitation and kill-switch gap identified by Kiteworks.&lt;/strong&gt; Organizations that cannot quickly terminate a misbehaving AI agent or restrict what it is authorized to do are exposed to the same category of risk the Taiwan attack demonstrated, independent of any single vulnerability.&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;Organizations running Citrix NetScaler, Marimo Notebook, Langflow, n8n, Apache Tomcat, PAN-OS, or Windows IKE VPN, the platforms targeted in the related knaithe/KnYuan campaign, can check patch status via the CVE links in the Product Coverage section below. Manual exploitation following autonomous reconnaissance has already produced confirmed data exfiltration and command execution against unpatched instances of some of these products.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Has Tenable released any product coverage for these threats?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Tenable customers can use the &lt;a href="https://www.tenable.com/products/tenable-one"&gt;&lt;u&gt;Tenable One Exposure Management Platform&lt;/u&gt;&lt;/a&gt; to assess their exposure to this threat cluster across three dimensions. Tenable One Attack Surface Management helps identify internet-facing authentication surfaces, OAuth and OpenID Connect discovery endpoints, and exposed AI agent framework instances before an adversary finds them. Tenable One Identity Exposure helps organizations surface the excessive privileges, weak credential patterns, and misconfigured single sign-on integrations that AI agents in this campaign exploited without needing a single CVE. Tenable One Vulnerability Management provides coverage for the known vulnerabilities exploited in the related knaithe/KnYuan campaign, including:&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="e008a3cff708ee709622aa99a239dbe56"&gt;&lt;a href="https://www.tenable.com/cve/CVE-2026-33017/plugins"&gt;&lt;u&gt;CVE-2026-33017&lt;/u&gt;&lt;/a&gt; (Langflow)&lt;/li&gt;&lt;li data-list-item-id="ed0c468e0c3ff7afe0576f1e2c413a1f1"&gt;&lt;a href="https://www.tenable.com/cve/CVE-2026-3055/plugins"&gt;&lt;u&gt;CVE-2026-3055&lt;/u&gt;&lt;/a&gt; (Citrix NetScaler)&lt;/li&gt;&lt;li data-list-item-id="e4ec5965e3a1da5383d88e84010d91d7c"&gt;&lt;a href="https://www.tenable.com/cve/CVE-2026-39987/plugins"&gt;&lt;u&gt;CVE-2026-39987&lt;/u&gt;&lt;/a&gt; (Marimo Notebook)&lt;/li&gt;&lt;li data-list-item-id="e167f8d8304e288c0310904252cc5abe3"&gt;&lt;a href="https://www.tenable.com/cve/CVE-2026-34486/plugins"&gt;&lt;u&gt;CVE-2026-34486&lt;/u&gt;&lt;/a&gt; (Apache Tomcat)&lt;/li&gt;&lt;li data-list-item-id="e423c70f9beffd786209c8c7e05b38bd2"&gt;&lt;a href="https://www.tenable.com/cve/CVE-2026-21858/plugins"&gt;&lt;u&gt;CVE-2026-21858&lt;/u&gt;&lt;/a&gt; (n8n)&lt;/li&gt;&lt;li data-list-item-id="ede6e701161671b485b034edf3ffde983"&gt;&lt;a href="https://www.tenable.com/cve/CVE-2025-68613/plugins"&gt;&lt;u&gt;CVE-2025-68613&lt;/u&gt;&lt;/a&gt; (n8n)&lt;/li&gt;&lt;li data-list-item-id="e74e868273d6764b276b8bc86e506a96e"&gt;&lt;a href="https://www.tenable.com/cve/CVE-2026-0300/plugins"&gt;&lt;u&gt;CVE-2026-0300&lt;/u&gt;&lt;/a&gt; (PAN-OS)&lt;/li&gt;&lt;li data-list-item-id="e3274e70712fb015fe82e90220e9043c5"&gt;&lt;a href="https://www.tenable.com/cve/CVE-2026-33824/plugins"&gt;&lt;u&gt;CVE-2026-33824&lt;/u&gt;&lt;/a&gt; (Windows IKE VPN)&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;These links will display all available plugins for these vulnerabilities, including upcoming plugins in our &lt;a href="https://www.tenable.com/plugins/pipeline"&gt;&lt;u&gt;Plugins Pipeline&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;JADEPUFFER, a separate actor in the same cluster, exploited an earlier Langflow vulnerability (&lt;a href="https://www.tenable.com/cve/CVE-2025-3248/plugins"&gt;&lt;u&gt;CVE-2025-3248&lt;/u&gt;&lt;/a&gt;) in its database extortion campaign. Tenable plugin coverage for that CVE is also available.&lt;/p&gt;&lt;p&gt;During the autonomous SDK code review phase, the agents also identified a Cross-Site Request Forgery weakness in the portal’s SSO integration. CSRF was not among the confirmed breach vectors in this campaign (the actual compromises came from server-side authentication flaws), but Tenable One Web App Scanning can identify this class of vulnerability in customer-facing portals with federated authentication:&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="ecb5db84cec720a8fbe770ddf84500383"&gt;&lt;a href="https://www.tenable.com/plugins/was/98112"&gt;&lt;u&gt;Cross-Site Request Forgery&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="ec8ba2cab3fc743ed7e5d3f0d96c08b54"&gt;&lt;a href="https://www.tenable.com/plugins/was/113900"&gt;&lt;u&gt;Cross-Site Request Forgery Token Validation Bypass&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;strong&gt;What does this mean for the future of cybersecurity?&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Tenable’s RSO team is actively monitoring seven indicators tied to this cluster. The four forecasts in our internal assessment deserve public summary.&lt;/p&gt;&lt;p&gt;First, framework proliferation: the RSO team assesses with moderate confidence that additional actors across multiple capability tiers will adopt autonomous AI attack methodologies within the next six to 12 months. Two distinct actors already built comparable capability independently, and the open-source tools they used remain freely available under permissive licenses.&lt;/p&gt;&lt;p&gt;Second, target expansion: the methodology is geography-agnostic. The AI agents require only a single entry point and self-discover everything else. The RSO team assesses that the same or similar frameworks will likely appear against non-Taiwan targets within three to six months, a timeline the knaithe/KnYuan discovery (which predated the Taiwan disclosure) already suggests is conservative.&lt;/p&gt;&lt;p&gt;Third, regulatory acceleration: the Taiwan incident provides concrete evidence for regulatory bodies that were already moving on agentic AI governance. The RSO team assesses that CISA or an equivalent Five Eyes agency will likely issue additional agentic AI guidance within three months, building on the joint guidance published in May 2026.&lt;/p&gt;&lt;p&gt;Fourth, defensive AI containment failures will continue. The sandbox escape incident tracked as FIND-020 and similar events at other AI laboratories are not anomalies. As AI models grow more capable, organizations face a dual-axis threat: offensive weaponization by adversaries from the outside and defensive containment failure from the inside. Both vectors converge on the same exposure: autonomous systems operating beyond the boundaries organizations assume they control.&lt;/p&gt;&lt;p&gt;The RSO team will continue to track this cluster and publish updates as monitoring indicators are triggered. Organizations that treat the Taiwan event as an isolated incident rather than a pattern will find themselves behind the curve when the next data point arrives.&lt;/p&gt;&lt;h3&gt;Get more information&lt;/h3&gt;&lt;ul&gt;&lt;li data-list-item-id="e6aabd3e4b67c9502bbe0220ea200fcd2"&gt;&lt;a href="https://www.tenable.com/products/tenable-one"&gt;&lt;u&gt;Tenable One Exposure Management Platform&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="e1093d15a325e5366c345bd2642549f3d"&gt;&lt;a href="https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services"&gt;&lt;u&gt;CISA and Five Eyes - "Careful Adoption of Agentic AI Services"&lt;/u&gt;&lt;/a&gt; (May 2026)&lt;/li&gt;&lt;li data-list-item-id="ea034be2e6d01a231187abfae91ca1a49"&gt;&lt;a href="https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/"&gt;&lt;u&gt;Unit 42 - “Chinese-Speaking Threat Actor Harnesses AI Models”&lt;/u&gt;&lt;/a&gt; (July 30, 2026)&lt;/li&gt;&lt;li data-list-item-id="eb016e297108c1a659d1ac54a6533783c"&gt;&lt;a href="https://dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia"&gt;&lt;u&gt;Dream Security - “Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia”&lt;/u&gt;&lt;/a&gt; (Aug. 12, 2026)&lt;/li&gt;&lt;li data-list-item-id="e7da2c1830ef9d38a8ec6eb83436a8e40"&gt;&lt;a href="https://www.sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion"&gt;&lt;u&gt;Sysdig TRT - “JADEPUFFER: Agentic Ransomware for Automated Database Extortion”&lt;/u&gt;&lt;/a&gt; (July 1, 2026)&lt;/li&gt;&lt;li data-list-item-id="eb6d5436a3cf62aaf2a38fb3009f8068a"&gt;&lt;a href="https://moda-gov-tw.translate.goog/ACS/press/news/press/20394?utm&amp;amp;_x_tr_sl=auto&amp;amp;_x_tr_tl=en&amp;amp;_x_tr_hl=en&amp;amp;_x_tr_pto=wapp"&gt;&lt;u&gt;Taiwan Ministry of Digital Affairs - official confirmation (English Translation)&lt;/u&gt;&lt;/a&gt; (Aug. 13, 2026)&lt;/li&gt;&lt;li data-list-item-id="eef1de4a32de92c2b76fd1c2dbf21d85d"&gt;&lt;a href="https://www.tenable.com/cve"&gt;&lt;u&gt;Tenable Vulnerability Watch&lt;/u&gt;&lt;/a&gt; - authoritative vulnerability classification&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Join&lt;/strong&gt;&lt;/em&gt; &lt;a href="https://connect.tenable.com/category/news-you-need/discussions/vulnerability-watch"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable's Research Special Operations (RSO) Team&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt; &lt;em&gt;&lt;strong&gt;on Tenable Connect for further discussions on the latest cyber threats.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Learn more about&lt;/strong&gt;&lt;/em&gt; &lt;a href="https://www.tenable.com/products/tenable-one"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable One Exposure Management Platform&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;, the exposure management platform for the modern attack surface.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/faq-agentic-ai.png"&gt;
</description>
  <pubDate>Fri, 14 Aug 2026 21:36:57 -0400</pubDate>
    <dc:creator>Research Special Operations</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211081</guid>
    </item>
<item>
  <title>Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)</title>
  <link>https://www.tenable.com/blog/microsofts-august-2026-patch-tuesday-addresses-398-cves-cve-2026-68820</link>
  <description>&lt;ol class="blog-severity-badges"&gt;&lt;li class="blog-severity-badges critical" data-list-item-id="ec83421fa2dc002eb9d19f21e6507ea9e"&gt;&lt;span class="number"&gt;42&lt;/span&gt;Critical&lt;/li&gt;&lt;li class="blog-severity-badges important" data-list-item-id="eba71489ab6f94822193880812a7d87a1"&gt;&lt;span class="number"&gt;355&lt;/span&gt;Important&lt;/li&gt;&lt;li class="blog-severity-badges moderate" data-list-item-id="ecf35de7aa843f5d996265b48256de491"&gt;&lt;span class="number"&gt;1&lt;/span&gt;Moderate&lt;/li&gt;&lt;li class="blog-severity-badges low" data-list-item-id="e47c621a3f5bba0b25c59d34abb460b74"&gt;&lt;span class="number"&gt;0&lt;/span&gt;Low&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;strong&gt;Microsoft addresses 398 CVEs in the eighth Patch Tuesday of 2026, with three zero-days, including one that was exploited in the wild.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Microsoft patched 398 CVEs in its August 2026 Patch Tuesday release, with 42 rated critical, 355 rated as important and one rated as moderate. Our counts omitted two CVEs assigned by MITRE; CVE-2026-6726 and CVE-2026-6727.&lt;/p&gt;&lt;img src="https://www.tenable.com/sites/default/files/images/blog/f367a044-9e99-4c9e-a491-1703e2bf186b.png" alt="A pie chart showing the severity distribution across the Patch Tuesday CVEs patched in August 2026." width="865" height="473" referrerpolicy="no-referrer" loading="lazy"&gt;&lt;p&gt;This month’s update includes patches for:&lt;/p&gt;&lt;ul&gt;&lt;li data-list-item-id="e2d1fef0e3158d3dc3ca117db2b45a4ce"&gt;.NET&lt;/li&gt;&lt;li data-list-item-id="e5a0af2487881b2a67517368dbf303715"&gt;.NET Core&lt;/li&gt;&lt;li data-list-item-id="e6ca85e7059b29d8232c565d2f2cee290"&gt;.NET Framework&lt;/li&gt;&lt;li data-list-item-id="ecc0357d8d0bcafd17b1af318370400f1"&gt;AMD Zen&lt;/li&gt;&lt;li data-list-item-id="eca635a32de4cd4686944b430b3f16414"&gt;Active Directory Certificate Services (AD CS)&lt;/li&gt;&lt;li data-list-item-id="e8edbd465d9b3ee79a7996f770183e745"&gt;Application Information Services&lt;/li&gt;&lt;li data-list-item-id="edd457ea55f41cdcbaae5b12488ab3eec"&gt;Azure Active Directory&lt;/li&gt;&lt;li data-list-item-id="e5f15149446ff9a71e89348f569ed8eeb"&gt;Azure CycleCloud&lt;/li&gt;&lt;li data-list-item-id="ee67eb5508a260030a0561fed421bc5e7"&gt;Azure Monitor Agent&lt;/li&gt;&lt;li data-list-item-id="e74c767d1c8081ba5e1241240565e213f"&gt;Azure Storage Explorer&lt;/li&gt;&lt;li data-list-item-id="e277f1219f81d4d62deaf7bf9f29d9a0f"&gt;Capability Access Management Service (camsvc)&lt;/li&gt;&lt;li data-list-item-id="e45b59a446fcb3f220828d9fc1dc9744f"&gt;Desktop Window Manager&lt;/li&gt;&lt;li data-list-item-id="ee98b00d6de4dd503043202db8b7c8912"&gt;Dynamics Business Central&lt;/li&gt;&lt;li data-list-item-id="e9af516fc24ae191a75a486ff76b654af"&gt;GitHub Copilot and Visual Studio Code&lt;/li&gt;&lt;li data-list-item-id="e0da040c7ef1d16e4d25686a99f6d992d"&gt;Microsoft Azure Attestation service and Device Health Attestation Service&lt;/li&gt;&lt;li data-list-item-id="e7a96f3639b046c90056c7754545f746e"&gt;Microsoft COM for Windows&lt;/li&gt;&lt;li data-list-item-id="ec49168b738b0f95ac6ee245474997fc7"&gt;Microsoft Defender for Endpoint&lt;/li&gt;&lt;li data-list-item-id="e904059f47ed5b807c2067ee4a9851848"&gt;Microsoft Digest Authentication&lt;/li&gt;&lt;li data-list-item-id="e251be51c08bcb65ea944e5a234483719"&gt;Microsoft Dynamics 365 (on-premises)&lt;/li&gt;&lt;li data-list-item-id="e90a7f5e11cdcd93377bcf945ae26fd10"&gt;Microsoft Entra Connect Sync&lt;/li&gt;&lt;li data-list-item-id="e913124733e9f108916376609ea69eb91"&gt;Microsoft Exchange Server&lt;/li&gt;&lt;li data-list-item-id="e582222cbb586631a9a9513b99721ea09"&gt;Microsoft High Performance Computing (HPC) Pack&lt;/li&gt;&lt;li data-list-item-id="e3506d9a6e2e824a32985d7a0d725738c"&gt;Microsoft Identity Services&lt;/li&gt;&lt;li data-list-item-id="e1af939dd4de9b9c7b9e2cf25d3feee03"&gt;Microsoft Local Security Authority Server (lsasrv)&lt;/li&gt;&lt;li data-list-item-id="e29bc56c000fc5d1e20a500f70bb6c104"&gt;Microsoft Office&lt;/li&gt;&lt;li data-list-item-id="ef2dbd31339f39919732c2171c6a988ff"&gt;Microsoft Office Access&lt;/li&gt;&lt;li data-list-item-id="e085d935d23430b694c752b548888e287"&gt;Microsoft Office Excel&lt;/li&gt;&lt;li data-list-item-id="e1e31636ff4204d6f48f5e85c193a9bf4"&gt;Microsoft Office Graphics Component&lt;/li&gt;&lt;li data-list-item-id="ee901f9039d750d51b9d882ddcb3a16cf"&gt;Microsoft Office Outlook&lt;/li&gt;&lt;li data-list-item-id="e141d55a54da18e54feb2f037b73bda7f"&gt;Microsoft Office PowerPoint&lt;/li&gt;&lt;li data-list-item-id="e6653937408512c2002f6b8092c01fc36"&gt;Microsoft Office SharePoint&lt;/li&gt;&lt;li data-list-item-id="e43748e2e6e278ffa4c0d065d87b91c94"&gt;Microsoft Office Word&lt;/li&gt;&lt;li data-list-item-id="e53c0b65713541d0fc779134626642fe6"&gt;Microsoft OneDrive&lt;/li&gt;&lt;li data-list-item-id="e89031e355f2e3daef3f036ea7bf09334"&gt;Microsoft PowerShell&lt;/li&gt;&lt;li data-list-item-id="edb9da0335bb5ac1049b40394646c4d31"&gt;Microsoft PowerShell Core&lt;/li&gt;&lt;li data-list-item-id="e3518dde97533ae08b86bb0c12a4cdae8"&gt;Microsoft QUIC&lt;/li&gt;&lt;li data-list-item-id="ebaf555040a5f0077458f75ca4107c5e1"&gt;Microsoft Remote Registry Service&lt;/li&gt;&lt;li data-list-item-id="e47d6b70557e705c4614f9966b796a940"&gt;Microsoft Teams Mobile&lt;/li&gt;&lt;li data-list-item-id="eb61ae8f2449638552c6cd4a217f84730"&gt;Microsoft Teams for Android&lt;/li&gt;&lt;li data-list-item-id="ebf2f2cceab0ca329ab87494ee10266fd"&gt;Microsoft Windows Codecs Library&lt;/li&gt;&lt;li data-list-item-id="e4d7b1df8b8575e061ac7ace16cf74143"&gt;Microsoft Windows Media Foundation&lt;/li&gt;&lt;li data-list-item-id="e987c9a2e1cedd5e9f8c0e2b3729962c3"&gt;Microsoft Windows Search Component&lt;/li&gt;&lt;li data-list-item-id="e0e3bb2118b95c92134e149e24e2d81a7"&gt;Power BI&lt;/li&gt;&lt;li data-list-item-id="e2ec2050e37609f1c69bc47b034fc9254"&gt;RPC Runtime&lt;/li&gt;&lt;li data-list-item-id="e626698337ce533447d4c236a90f7831d"&gt;Reliable Multicast Transport Driver (RMCAST)&lt;/li&gt;&lt;li data-list-item-id="e449caaa656302cfbb0081808109bea8b"&gt;Remote Desktop Client&lt;/li&gt;&lt;li data-list-item-id="ef1d84f2e17ca129be180cbaf4adf81a4"&gt;User-Mode Power Service (UMPS)&lt;/li&gt;&lt;li data-list-item-id="e722557914b3d7829d6b2a64cd90a6f53"&gt;Virtual Hard Disk (VHD) Miniport Driver&lt;/li&gt;&lt;li data-list-item-id="eb47b4ba6343e1ccecd94056c1849d8ac"&gt;Visual Studio Code&lt;/li&gt;&lt;li data-list-item-id="e6fa48ad4d0d022749c3e0c9c9bc03814"&gt;Visual Studio Code - Python extension&lt;/li&gt;&lt;li data-list-item-id="e7ae989c8beb7ccd507124115d5790ecf"&gt;Visual Studio Code CoPilot Chat Extension&lt;/li&gt;&lt;li data-list-item-id="e32061e09ea1d743e3830a4f80e91edfd"&gt;Windows Accessibility Infrastructure (ATBroker.exe)&lt;/li&gt;&lt;li data-list-item-id="e35dd6fd47827982b8c2fba4bdbb0d929"&gt;Windows Active Directory&lt;/li&gt;&lt;li data-list-item-id="e22f57a7ec2d662f067f54afa0a18274d"&gt;Windows Ancillary Function Driver for WinSock&lt;/li&gt;&lt;li data-list-item-id="e961dfb36d3b539151559dbce0dfe8375"&gt;Windows Autopilot&lt;/li&gt;&lt;li data-list-item-id="e0492c4e6aff752a60556b554927974b5"&gt;Windows Backup Engine&lt;/li&gt;&lt;li data-list-item-id="e379b3e7c1b384b22e431c1d1de386ff4"&gt;Windows Bind Filter Driver&lt;/li&gt;&lt;li data-list-item-id="eee49453d1385f6e681cba51a7acaaf56"&gt;Windows Cloud Files Mini Filter Driver&lt;/li&gt;&lt;li data-list-item-id="e0a419271b2570ee1033023c94da732f3"&gt;Windows Common Log File System Driver&lt;/li&gt;&lt;li data-list-item-id="e26bb2b18eb77ae0a181f33106d7c346b"&gt;Windows Container Isolation FS Filter Driver (unionfs.sys)&lt;/li&gt;&lt;li data-list-item-id="e2d58f99366070907ec0bfddfea79028f"&gt;Windows Cross Device Service&lt;/li&gt;&lt;li data-list-item-id="e6231eb6eca3c8be6038439a0e3e6eb23"&gt;Windows DHCP Client&lt;/li&gt;&lt;li data-list-item-id="e2603abb40bf6adfdfb4a64f13aaac70c"&gt;Windows DHCP Server&lt;/li&gt;&lt;li data-list-item-id="e4bde99615d7886ef61133bcff4ecd81e"&gt;Windows DNS&lt;/li&gt;&lt;li data-list-item-id="e32925bd37d1c0b054c7c72098f085f88"&gt;Windows DWM Core Library&lt;/li&gt;&lt;li data-list-item-id="e3644c5a1dd30b28f29bc9e1400dec8f4"&gt;Windows Defender Firewall Service&lt;/li&gt;&lt;li data-list-item-id="efa711268762e110749b8b662bf9032db"&gt;Windows Deployment Services&lt;/li&gt;&lt;li data-list-item-id="e309935528197428732d7457ccbece8f3"&gt;Windows Device Association Service&lt;/li&gt;&lt;li data-list-item-id="ef5f033928d0e24494ba052d9318f6cb8"&gt;Windows Display Enhancement Service&lt;/li&gt;&lt;li data-list-item-id="e57339d5dfa27ff2216a31fec18ae7948"&gt;Windows Encrypting File System (EFS)&lt;/li&gt;&lt;li data-list-item-id="e513c315bd9e98fa5c3568f8a1798600e"&gt;Windows Event Logging Service&lt;/li&gt;&lt;li data-list-item-id="eb1edac82f4a7bfa7b028d7645de9ee1d"&gt;Windows GDI&lt;/li&gt;&lt;li data-list-item-id="e1dd12a1f7381172b7b012f2d76ed84d3"&gt;Windows GDI+&lt;/li&gt;&lt;li data-list-item-id="e9c4feb57af09e9977e1aa5188a29f81c"&gt;Windows Graphics Kernel&lt;/li&gt;&lt;li data-list-item-id="eacda198f39c173468939d4698fc4d494"&gt;Windows HTTP Protocol Stack&lt;/li&gt;&lt;li data-list-item-id="e287bb2629f954d698fcc7485bf68ae03"&gt;Windows HTTP.sys&lt;/li&gt;&lt;li data-list-item-id="ef4d99f371d944927032714e31880db6d"&gt;Windows Hello&lt;/li&gt;&lt;li data-list-item-id="e6266896599af6286322fac181d1dd88f"&gt;Windows Hyper-V&lt;/li&gt;&lt;li data-list-item-id="e9ca7159bc9b42a72f5c9304f6fd197ee"&gt;Windows Imaging Component&lt;/li&gt;&lt;li data-list-item-id="ee74cf76cbf60960aa9aabedd3dedb2aa"&gt;Windows Installer&lt;/li&gt;&lt;li data-list-item-id="eba4d3ebd9a65646a6ec70ef111f326ea"&gt;Windows Kerberos&lt;/li&gt;&lt;li data-list-item-id="ef011f9d67d49f49694f75e0b5ac31e2f"&gt;Windows Kernel&lt;/li&gt;&lt;li data-list-item-id="e89b95bb161592d7a2f92c3003dac8e20"&gt;Windows Key Guard&lt;/li&gt;&lt;li data-list-item-id="e683c7baf6a0b13a7153aadac474391ce"&gt;Windows LDAP - Lightweight Directory Access Protocol&lt;/li&gt;&lt;li data-list-item-id="edb64cd972b3f9a68de76239a724992fb"&gt;Windows LUAFV&lt;/li&gt;&lt;li data-list-item-id="ecf71a73f63be9dc01f5afa16d4463313"&gt;Windows License Manager&lt;/li&gt;&lt;li data-list-item-id="e47c027d3fb8cd5921cb6cc029ccb71d0"&gt;Windows MIDI Service Module&lt;/li&gt;&lt;li data-list-item-id="e04f7e9746453fa03296b9d26c13946c1"&gt;Windows Management Instrumentation&lt;/li&gt;&lt;li data-list-item-id="e17d650564ba22a15faf1334a4b223090"&gt;Windows Management Services&lt;/li&gt;&lt;li data-list-item-id="ea1f066cb3882d25c1be6452cbaa661a8"&gt;Windows Message Queuing&lt;/li&gt;&lt;li data-list-item-id="e62d0dc200a9cd37e25f24ba0137b3148"&gt;Windows Modern Device Management (MDM)&lt;/li&gt;&lt;li data-list-item-id="ebf349598d6d8348f4aa1642cf3214f1b"&gt;Windows NTFS&lt;/li&gt;&lt;li data-list-item-id="ebd25f71437bbdf456786ce5492c2c2ef"&gt;Windows Narrator Braille&lt;/li&gt;&lt;li data-list-item-id="e78827e80124b759977705fa3011f4fb8"&gt;Windows Network Address Translation (NAT)&lt;/li&gt;&lt;li data-list-item-id="e8f28b2b19c37eda6224007e14c9e0148"&gt;Windows Network Connection Broker&lt;/li&gt;&lt;li data-list-item-id="e02ad8574f9320a1b6bc0eedffbb435cf"&gt;Windows Network File System&lt;/li&gt;&lt;li data-list-item-id="ebf84f47499670e8d1a98454a41b2d518"&gt;Windows Package Manager&lt;/li&gt;&lt;li data-list-item-id="e8580ada5ce4f79831fb488733d04afce"&gt;Windows Program Compatibility Assistant Service&lt;/li&gt;&lt;li data-list-item-id="e62e8ad5c6aa0c0c87f38783396f73f2f"&gt;Windows Projected File System&lt;/li&gt;&lt;li data-list-item-id="ec282d04f2c832eca46dc400825905337"&gt;Windows Push Notifications&lt;/li&gt;&lt;li data-list-item-id="e8a3231d2432719350dc3ae4fb6d57c97"&gt;Windows RPC API&lt;/li&gt;&lt;li data-list-item-id="ea81437347d3a09419c359f639297abd5"&gt;Windows Remote Access API&lt;/li&gt;&lt;li data-list-item-id="ef9d32b91f3aa446863f1b93b8df6d18a"&gt;Windows Remote Access Connection Manager&lt;/li&gt;&lt;li data-list-item-id="ef49df531f251079f2f5490d9fb5e5600"&gt;Windows Remote Desktop Services&lt;/li&gt;&lt;li data-list-item-id="ebd27209ab58da638d7d9a99fa95f3714"&gt;Windows Remote Help&lt;/li&gt;&lt;li data-list-item-id="e459cde1f3afc1ac02fa30900781d8b45"&gt;Windows Remote Help Defense&lt;/li&gt;&lt;li data-list-item-id="ecdf1ed89f15351f9bf9ffcc481fc2e1d"&gt;Windows Routing and Remote Access Service (RRAS)&lt;/li&gt;&lt;li data-list-item-id="e3a8d939fb4597da4fc7154e3d5fccc91"&gt;Windows SMB Client&lt;/li&gt;&lt;li data-list-item-id="e4bbea7daaf668f6f5c8e93a2eeb7c929"&gt;Windows SMB Server&lt;/li&gt;&lt;li data-list-item-id="e280207969dc24e7dfaeda18f95982d40"&gt;Windows Schannel&lt;/li&gt;&lt;li data-list-item-id="e45bc70fb75f9816698aa46c6e67cd054"&gt;Windows Secure Socket Tunneling Protocol (SSTP)&lt;/li&gt;&lt;li data-list-item-id="e56eb92babd557042f9250999c955906c"&gt;Windows Sensor Data Service&lt;/li&gt;&lt;li data-list-item-id="ea844d9e6fbf1eab584e5b5baf9912319"&gt;Windows Shell&lt;/li&gt;&lt;li data-list-item-id="e2597f15603779b0ab7e4856cc2046b80"&gt;Windows Storage&lt;/li&gt;&lt;li data-list-item-id="e24600aec0fbd977d263969321118582b"&gt;Windows Storage Port Driver&lt;/li&gt;&lt;li data-list-item-id="e9d3e0e2465d4c96987be2a913d330db1"&gt;Windows TCP/IP&lt;/li&gt;&lt;li data-list-item-id="ef88cefdf1d3d45909d0b9c1e5f52b36f"&gt;Windows Telephony Service&lt;/li&gt;&lt;li data-list-item-id="e0034ebfa5f63dc213c99eb55439147bf"&gt;Windows USB Driver&lt;/li&gt;&lt;li data-list-item-id="ec65f11b281c6a05a3698ed31f813fe86"&gt;Windows Universal Disk Format File System Driver (UDFS)&lt;/li&gt;&lt;li data-list-item-id="e84de1af42251eacf9721322d56364667"&gt;Windows User Profile Service&lt;/li&gt;&lt;li data-list-item-id="e587b47c6dac570e2b7b038dca3622d73"&gt;Windows Win32K&lt;/li&gt;&lt;li data-list-item-id="e44696b7d9e68b70684876325efe8b70d"&gt;Windows Wired AutoConfig Service&lt;/li&gt;&lt;li data-list-item-id="e95d8fc4a73755c56f069765075a293d1"&gt;Windows Work Folder Service&lt;/li&gt;&lt;li data-list-item-id="e14aff5a8506e484495c63cec39eb1916"&gt;Windows iSCSI Target Service&lt;/li&gt;&lt;li data-list-item-id="e6428f09af872cafc70632b71b9dc09db"&gt;Winlogon&lt;/li&gt;&lt;/ul&gt;&lt;img src="https://www.tenable.com/sites/default/files/images/blog/dc71ea2f-373b-4582-8a50-5512036717e9.png" alt="A bar chart showing the count by impact of CVEs patched in the August 2026 Patch Tuesday release." width="865" height="419" referrerpolicy="no-referrer" loading="lazy"&gt;&lt;p&gt;Elevation of Privilege (EoP) vulnerabilities accounted for 40.7% of the vulnerabilities patched this month, followed by remote code execution (RCE) vulnerabilities at 27.1%.&lt;/p&gt;&lt;div class="blog-severity-alert"&gt;&lt;div class="col-sm-2 nopad"&gt;&lt;div class="blog-severity-badge important"&gt;Important&lt;/div&gt;&lt;/div&gt;&lt;div class="col-sm-10"&gt;&lt;h2&gt;CVE-2026-68820 | Windows Ancillary Function Driver for WinSock elevation of privilege vulnerability&lt;/h2&gt;&lt;/div&gt;&lt;div class="col-sm-12"&gt;&lt;p&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-68820"&gt;&lt;u&gt;CVE-2026-68820&lt;/u&gt;&lt;/a&gt; is an EoP vulnerability affecting Windows Ancillary Function Driver for WinSock. It received a CVSSv3 score of 7.0 and was rated as important. A local attacker could exploit this vulnerability to elevate to SYSTEM privileges. According to Microsoft, this vulnerability was exploited in the wild as a zero-day.&lt;/p&gt;&lt;p&gt;Two additional EoP vulnerabilities affecting this driver were patched this month. &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-61348"&gt;&lt;u&gt;CVE-2026-61348&lt;/u&gt;&lt;/a&gt; and &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-70307"&gt;&lt;u&gt;CVE-2026-70307&lt;/u&gt;&lt;/a&gt; also received CVSSv3 scores of 7.0, however no exploitation has been reported for these flaws. Both were assessed as "Exploitation More Likely" according to &lt;a href="https://www.microsoft.com/en-us/msrc/exploitability-index"&gt;&lt;u&gt;Microsoft's Exploitability Index&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;p&gt;Prior zero-days in this driver include &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-32709"&gt;&lt;u&gt;CVE-2025-32709&lt;/u&gt;&lt;/a&gt; in &lt;a href="https://www.tenable.com/blog/microsofts-may-2025-patch-tuesday-addresses-71-cves-cve-2025-32701-cve-2025-32706"&gt;&lt;u&gt;May 2025&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-21418"&gt;&lt;u&gt;CVE-2025-21418&lt;/u&gt;&lt;/a&gt; in &lt;a href="https://www.tenable.com/blog/microsofts-february-2025-patch-tuesday-addresses-55-cves-cve-2025-21418-cve-2025-21391"&gt;&lt;u&gt;February 2025&lt;/u&gt;&lt;/a&gt;, and &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-38193"&gt;&lt;u&gt;CVE-2024-38193&lt;/u&gt;&lt;/a&gt; in &lt;a href="https://www.tenable.com/blog/microsofts-august-2024-patch-tuesday-addresses-88-cves"&gt;&lt;u&gt;August 2024&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blog-severity-alert"&gt;&lt;div class="col-sm-2 nopad"&gt;&lt;div class="blog-severity-badge important"&gt;Important&lt;/div&gt;&lt;/div&gt;&lt;div class="col-sm-10"&gt;&lt;h2&gt;CVE-2026-62832 | Windows User Profile Service elevation of privilege vulnerability&lt;/h2&gt;&lt;/div&gt;&lt;div class="col-sm-12"&gt;&lt;p&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62832"&gt;&lt;u&gt;CVE-2026-62832&lt;/u&gt;&lt;/a&gt; is an elevation of privilege vulnerability affecting Windows User Profile Service. It received a CVSSv3 score of 7.8 and is rated as important. A local attacker could exploit this vulnerability to gain ADMINISTRATOR privileges. It was publicly disclosed prior to a patch being available and was assessed as “Exploitation More Likely.”&lt;/p&gt;&lt;p&gt;Historically, the Windows User Profile Service has received four total CVEs since January 2022. Prior zero-days in this family include &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-21919"&gt;&lt;u&gt;CVE-2022-21919&lt;/u&gt;&lt;/a&gt; in &lt;a href="https://www.tenable.com/blog/microsofts-january-2022-patch-tuesday-addresses-97-cves-cve-2022-21907"&gt;&lt;u&gt;January 2022&lt;/u&gt;&lt;/a&gt; and &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2022-26904"&gt;&lt;u&gt;CVE-2022-26904&lt;/u&gt;&lt;/a&gt; in &lt;a href="https://www.tenable.com/blog/microsofts-april-2022-patch-tuesday-addresses-117-cves-cve-2022-24521"&gt;&lt;u&gt;April 2022&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blog-severity-alert"&gt;&lt;div class="col-sm-2 nopad"&gt;&lt;div class="blog-severity-badge important"&gt;Important&lt;/div&gt;&lt;/div&gt;&lt;div class="col-sm-10"&gt;&lt;h2&gt;CVE-2026-72971 | Windows Container Isolation FS Filter Driver (unionfs.sys) tampering vulnerability&lt;/h2&gt;&lt;/div&gt;&lt;div class="col-sm-12"&gt;&lt;p&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-72971"&gt;&lt;u&gt;CVE-2026-72971&lt;/u&gt;&lt;/a&gt; is a tampering vulnerability affecting the Windows Container Isolation FS Filter Driver (unionfs.sys). It received a CVSSv3 score of 5.5 and is rated as important. It was publicly disclosed prior to a patch being available. Successful exploitation would allow a local attacker to perform tampering. Despite being publicly disclosed, Microsoft assesses this vulnerability as “Exploitation Unlikely.”&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blog-severity-alert"&gt;&lt;div class="col-sm-2 nopad"&gt;&lt;div class="blog-severity-badge critical"&gt;Critical&lt;/div&gt;&lt;/div&gt;&lt;div class="col-sm-10"&gt;&lt;h2&gt;CVE-2026-62893 | Windows Deployment Services TFTP Server remote code execution vulnerability&lt;/h2&gt;&lt;/div&gt;&lt;div class="col-sm-12"&gt;&lt;p&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62893"&gt;&lt;u&gt;CVE-2026-62893&lt;/u&gt;&lt;/a&gt; is a remote code execution vulnerability affecting Windows Deployment Services Trivial File Transfer Protocol (TFTP) Server. It received a CVSSv3 score of 9.8 and is rated as critical. It was assessed as "Exploitation More Likely." Successful exploitation of this flaw could occur when a remote, unauthenticated attacker sends crafted packets to a vulnerable service, resulting in code execution. It was reported to Microsoft by Nikolai Skliarenko of TrendAI Research.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blog-severity-alert"&gt;&lt;div class="col-sm-2 nopad"&gt;&lt;div class="blog-severity-badge critical"&gt;Critical&lt;/div&gt;&lt;/div&gt;&lt;div class="col-sm-10"&gt;&lt;h2&gt;CVE-2026-62823 | Windows DHCP Server remote code execution vulnerability&lt;/h2&gt;&lt;/div&gt;&lt;div class="col-sm-12"&gt;&lt;p&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62823"&gt;&lt;u&gt;CVE-2026-62823&lt;/u&gt;&lt;/a&gt; is a remote code execution vulnerability affecting Windows DHCP Server. It received a CVSSv3 score of 8.8 and is rated as critical. It was assessed as "Exploitation More Likely" according to Microsoft's Exploitability Index. Successful exploitation would allow a remote, unauthenticated attacker to execute code over an adjacent network by exploiting a heap-based buffer overflow flaw using a crafted packet.&lt;/p&gt;&lt;p&gt;13 additional Windows DHCP server vulnerabilities were patched this month, however these flaws were only rated as important. The flaws include eight information disclosure vulnerabilities with CVSSv3 scores of 6.5 (&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62714"&gt;&lt;u&gt;CVE-2026-62714&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62715"&gt;&lt;u&gt;CVE-2026-62715&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62716"&gt;&lt;u&gt;CVE-2026-62716&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62718"&gt;&lt;u&gt;CVE-2026-62718&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62720"&gt;&lt;u&gt;CVE-2026-62720&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62742"&gt;&lt;u&gt;CVE-2026-62742&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62745"&gt;&lt;u&gt;CVE-2026-62745&lt;/u&gt;&lt;/a&gt; &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62745"&gt;and&lt;/a&gt; &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62814"&gt;&lt;u&gt;CVE-2026-62814&lt;/u&gt;&lt;/a&gt;) and five EoP vulnerabilities with CVSSv3 scores of 7.8 (&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62761"&gt;&lt;u&gt;CVE-2026-62761&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62776"&gt;&lt;u&gt;CVE-2026-62776&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62803"&gt;&lt;u&gt;CVE-2026-62803&lt;/u&gt;&lt;/a&gt;, &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62807"&gt;&lt;u&gt;CVE-2026-62807&lt;/u&gt;&lt;/a&gt; and &lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62812"&gt;&lt;u&gt;CVE-2026-62812&lt;/u&gt;&lt;/a&gt;).&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blog-severity-alert"&gt;&lt;div class="col-sm-2 nopad"&gt;&lt;div class="blog-severity-badge critical"&gt;Critical&lt;/div&gt;&lt;/div&gt;&lt;div class="col-sm-10"&gt;&lt;h2&gt;Multiple CVEs | Microsoft Office SharePoint spoofing, remote code execution, elevation of privilege, information disclosure and tampering vulnerabilities&lt;/h2&gt;&lt;/div&gt;&lt;div class="col-sm-12"&gt;&lt;p&gt;This month's update includes patches for 29 CVEs affecting Microsoft Office SharePoint. Of the 29 CVEs, three were rated as critical and three were assessed as 'Exploitation More Likely.' A breakdown of the CVEs can be found in the table below:&lt;/p&gt;&lt;div class="table-responsive"&gt;&lt;table class="table"&gt;&lt;thead&gt;&lt;tr&gt;&lt;th&gt;&lt;strong&gt;CVE&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Description&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;CVSSv3&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Severity&lt;/strong&gt;&lt;/th&gt;&lt;th&gt;&lt;strong&gt;Exploitability Index&lt;/strong&gt;&lt;/th&gt;&lt;/tr&gt;&lt;/thead&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-70306"&gt;&lt;u&gt;CVE-2026-70306&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft Office SharePoint Spoofing&lt;/td&gt;&lt;td&gt;9.3&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62827"&gt;&lt;u&gt;CVE-2026-62827&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Elevation of Privilege&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Critical&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-65665"&gt;&lt;u&gt;CVE-2026-65665&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Remote Code Execution&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Critical&lt;/td&gt;&lt;td&gt;Exploitation More Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-64921"&gt;&lt;u&gt;CVE-2026-64921&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Elevation of Privilege&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Critical&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-63514"&gt;&lt;u&gt;CVE-2026-63514&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Remote Code Execution&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-64901"&gt;&lt;u&gt;CVE-2026-64901&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Remote Code Execution&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-65658"&gt;&lt;u&gt;CVE-2026-65658&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Remote Code Execution&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-65663"&gt;&lt;u&gt;CVE-2026-65663&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Remote Code Execution&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-66805"&gt;&lt;u&gt;CVE-2026-66805&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Remote Code Execution&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-66808"&gt;&lt;u&gt;CVE-2026-66808&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Remote Code Execution&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-70321"&gt;&lt;u&gt;CVE-2026-70321&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Remote Code Execution&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-70324"&gt;&lt;u&gt;CVE-2026-70324&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Elevation of Privilege&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-70326"&gt;&lt;u&gt;CVE-2026-70326&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Elevation of Privilege&lt;/td&gt;&lt;td&gt;8.8&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-63520"&gt;&lt;u&gt;CVE-2026-63520&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Remote Code Execution&lt;/td&gt;&lt;td&gt;8.1&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation More Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-57105"&gt;&lt;u&gt;CVE-2026-57105&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft Office SharePoint Spoofing&lt;/td&gt;&lt;td&gt;8.0&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-70355"&gt;&lt;u&gt;CVE-2026-70355&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Elevation of Privilege&lt;/td&gt;&lt;td&gt;7.3&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation More Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-58639"&gt;&lt;u&gt;CVE-2026-58639&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;6.5&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62837"&gt;&lt;u&gt;CVE-2026-62837&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Information Disclosure&lt;/td&gt;&lt;td&gt;6.5&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62839"&gt;&lt;u&gt;CVE-2026-62839&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;6.5&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-63512"&gt;&lt;u&gt;CVE-2026-63512&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Tampering&lt;/td&gt;&lt;td&gt;6.5&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-63516"&gt;&lt;u&gt;CVE-2026-63516&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;6.5&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-65660"&gt;&lt;u&gt;CVE-2026-65660&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;6.5&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62829"&gt;&lt;u&gt;CVE-2026-62829&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;4.6&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-62917"&gt;&lt;u&gt;CVE-2026-62917&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;4.6&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-64897"&gt;&lt;u&gt;CVE-2026-64897&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;4.6&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-64922"&gt;&lt;u&gt;CVE-2026-64922&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;4.6&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Less Likely&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-64900"&gt;&lt;u&gt;CVE-2026-64900&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;7.3&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;N/A&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-64902"&gt;&lt;u&gt;CVE-2026-64902&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;4.6&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;N/A&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2026-64916"&gt;&lt;u&gt;CVE-2026-64916&lt;/u&gt;&lt;/a&gt;&lt;/td&gt;&lt;td&gt;Microsoft SharePoint Server Spoofing&lt;/td&gt;&lt;td&gt;4.6&lt;/td&gt;&lt;td&gt;Important&lt;/td&gt;&lt;td&gt;Exploitation Unlikely&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;h2&gt;Tenable solutions&lt;/h2&gt;&lt;p&gt;A list of all the plugins released for Microsoft's August 2026 Patch Tuesday update can be found &lt;a href="https://www.tenable.com/plugins/search?q=%22August+2026%22+AND+script_family%3A%28%22Windows%22+OR+%22MacOS+X+Local+Security+Checks%22+OR+%22Windows+%3A+Microsoft+Bulletins%22%29&amp;amp;sort=&amp;amp;page=1"&gt;&lt;u&gt;here&lt;/u&gt;&lt;/a&gt;. As always, we recommend patching systems as soon as possible and regularly scanning your environment to identify those systems yet to be patched.&lt;/p&gt;&lt;p&gt;For more specific guidance on best practices for vulnerability assessments, please refer to our blog post on &lt;a href="http://www.tenable.com/blog/how-to-perform-efficient-vulnerability-assessments-with-tenable"&gt;&lt;u&gt;How to Perform Efficient Vulnerability Assessments with Tenable&lt;/u&gt;&lt;/a&gt;.&lt;/p&gt;&lt;h3&gt;Get more information&lt;/h3&gt;&lt;ul&gt;&lt;li data-list-item-id="eac44328711ff6438e815b53f82bc1396"&gt;&lt;a href="https://msrc.microsoft.com/update-guide/en-us/releaseNote/2026-Aug"&gt;&lt;u&gt;Microsoft's August 2026 Security Updates&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="e3960ae74d9af3f1f7c5417f5bd8b3193"&gt;&lt;a href="https://www.tenable.com/plugins/search?q=%22August+2026%22+AND+script_family%3A%28%22Windows%22+OR+%22MacOS+X+Local+Security+Checks%22+OR+%22Windows+%3A+Microsoft+Bulletins%22%29&amp;amp;sort=&amp;amp;page=1"&gt;&lt;u&gt;Tenable plugins for Microsoft August 2026 Patch Tuesday Security Updates&lt;/u&gt;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Join &lt;/strong&gt;&lt;/em&gt;&lt;a href="https://connect.tenable.com/category/news-you-need/discussions/vulnerability-watch"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable's Research Special Operations (RSO) Team&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt; on Tenable Connect for further discussions on the latest cyber threats.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;&lt;p&gt;&lt;em&gt;&lt;strong&gt;Learn more about &lt;/strong&gt;&lt;/em&gt;&lt;a href="https://www.tenable.com/products/tenable-one"&gt;&lt;em&gt;&lt;strong&gt;&lt;u&gt;Tenable One&lt;/u&gt;&lt;/strong&gt;&lt;/em&gt;&lt;/a&gt;&lt;em&gt;&lt;strong&gt;, the Exposure Management Platform for the modern attack surface.&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/microsoft-august-2026-patch-tuesday-398-cves-3-zero-days.png"&gt;
</description>
  <pubDate>Tue, 11 Aug 2026 14:04:04 -0400</pubDate>
    <dc:creator>Research Special Operations</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211072</guid>
    </item>
<item>
  <title>Agentic AI for cyber defenders: What security teams built at Black Hat USA 2026</title>
  <link>https://www.tenable.com/blog/agentic-ai-for-cyber-defenders-what-security-teams-built-at-black-hat-usa-2026</link>
  <description>&lt;p&gt;Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event.&lt;/p&gt;&lt;div&gt;&lt;div&gt;&lt;h2&gt;&lt;strong&gt;Key takeaways&lt;/strong&gt;&lt;/h2&gt;&lt;ol&gt;&lt;li data-list-item-id="e10eff813a2df5b275d5b79243f47d207"&gt;&lt;strong&gt;Building defensive cybersecurity tooling no longer requires a developer.&lt;/strong&gt; Agentic tooling drove the cost of finding and exploiting a vulnerability down to 1990s levels; it also removed the engineering barrier that kept defenders from building the automation they’ve always wanted.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li data-list-item-id="e3754565dab63a80b658220710e9a3dd5"&gt;&lt;strong&gt;The unglamorous work won the room: triage, reconciliation, toil.&lt;/strong&gt; Given two days and a requirement to publish, practitioners at SWARM developed agents for prioritization, cross-tool reconciliation, and the unglamorous toil they recognize from their own environments.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li data-list-item-id="eede711e5f1136338664ae2d1226a0de0"&gt;&lt;strong&gt;All SWARM builds live on the &lt;/strong&gt;&lt;a href="https://exchange.tenable.com" target="_blank"&gt;&lt;strong&gt;CyberAgents Exchange&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;, source repos attached.&lt;/strong&gt; Every component built at SWARM is published open source with its source repository attached, so the next team facing the same problem starts from working code instead of a blank editor.&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;/div&gt;&lt;h2&gt;Another security team already built the AI agent you need&lt;/h2&gt;&lt;p&gt;You may not realize it, but somewhere out in the ether, there’s a security team facing the same challenge as you. The only difference is they just solved the problem with agentic AI. The problem is, you have no way to find out the solution even exists.&lt;/p&gt;&lt;p&gt;It could be an asset inventory that three systems describe in three different ways; a findings queue nobody has the hours to work; or a “critical” that a platform upgrade quietly neutralized six months ago, still sitting there waiting for someone to prove it. Somebody has already built the thing you keep meaning to build. Now it’s time we help you find it.&lt;/p&gt;&lt;p&gt;At Black Hat USA 2026, nearly 100 registrants had the opportunity to come together for 48 hours and solve both halves of that problem: identifying a key operational pain point and building the fix.&lt;/p&gt;&lt;p&gt;Problems like those got solved at SWARM, and the fixes are sitting on the &lt;a href="https://exchange.tenable.com" target="_blank"&gt;CyberAgents Exchange&lt;/a&gt; right now, open source, with their source repositories attached.&amp;nbsp;&lt;/p&gt;&lt;p&gt;One team built the agent that works out which handful of fixes retires the most risk across thousands of findings. Another correlated two scanners to tell whether a flaw in the code is even reachable in the running application. A third made the case that a finding had already been mitigated, with evidence an auditor would accept. You can download and deploy any of them today.&lt;/p&gt;&lt;h2&gt;Agentic AI doesn’t just arm attackers&lt;/h2&gt;&lt;p&gt;Black Hat’s keynote stage spent this year focused on one theme: the plummeting cost of cyber offense in the agentic AI era. The price for an attacker to find and exploit a vulnerability is at lows the industry hasn’t seen since the 1990s, when a working exploit meant weeks of expert reverse engineering. Now all it takes is an afternoon and a subscription.&lt;/p&gt;&lt;p&gt;The artisanal exploit isn’t rare anymore. True. But neither is the defender who can build.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The same agentic tooling that’s arming attackers puts real building power in everyone’s hands, and that half of the story got almost no airtime. &lt;strong&gt;Security automation used to require the work and ongoing maintenance of skilled engineers. Now practitioners who understand the problem can build the fix.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Inside the conference room at the Mandalay Bay where Tenable hosted our inaugural &lt;a href="https://www.tenable.com/blog/black-hat-2026-swarm-event-build-AI-security-agents" target="_blank"&gt;SWARM&lt;/a&gt; event, the proof of that was on every table. The winning ranking engine ships as &lt;a href="https://exchange.tenable.com/skills/chokepoint-finder-skill/" target="_blank"&gt;a skill that runs on the Python standard library alone&lt;/a&gt; — no packages, no install step, no build pipeline. Point it at the bundled demo estate and it answers “what should we fix first?” in seconds. That’s a deliverable a practitioner can produce and a colleague can run, and two days was enough.&lt;/p&gt;&lt;p&gt;The attacker-defender asymmetry doesn’t stem from a lack of talent or willingness. Offensive cyber capabilities compound because the tooling circulates: it’s built once, forked, passed on, or sold to the next threat actor to leverage in their attack.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Meanwhile, defenders continue to build in silos, with hundreds of teams solving the same fix for the same problem. Not because anyone wants to keep it to themselves, but because there’s never been an easy way to pass it along. Defensive cyber tools are built, then lost, then rebuilt somewhere else. That’s a distribution gap, and now defenders can close it themselves on the &lt;a href="https://exchange.tenable.com" target="_blank"&gt;CyberAgents Exchange&lt;/a&gt;.&lt;/p&gt;&lt;h2&gt;We gave defenders a mission and two days to build&lt;/h2&gt;&lt;p&gt;Tenable hosted its first SWARM event, running alongside Black Hat, so practitioners could come together and build open-source agentic AI. Sponsored by AWS and with technical staff from Anthropic onsite for judging, SWARM came with a couple simple rules: build something practical that solves a real problem for your team, and publish it to the CyberAgents Exchange.&lt;/p&gt;&lt;p&gt;Then we got out of the way, and the magic immediately took shape.&lt;/p&gt;&lt;h3&gt;Practitioners built AI agents for Monday morning, not for the demo&lt;/h3&gt;&lt;p&gt;The room skewed hard toward unglamorous work. Not autonomous red teams or self-healing networks, but the specific tasks that eat a practitioner’s week: reconciling asset inventories that three systems disagree about, triaging a findings queue nobody has time for, chasing down whether a finding is even real before someone spends a sprint on it.&amp;nbsp;&lt;/p&gt;&lt;p&gt;One team built an agent that reads vendor advisories and mitigation notes, compares them against live findings, and recommends risk recasts — the kind of work a senior engineer does by hand, one CVE at a time, and never gets credit for. They built the thing that was annoying them last Tuesday.&lt;/p&gt;&lt;h3&gt;Defenders didn’t build robot analysts, they built plumbing&lt;/h3&gt;&lt;p&gt;The most common thing in the room wasn’t a flashy autonomous agent. It was connective tissue: capabilities to normalize findings across scanners that describe the same asset three different ways, wrap the tools that teams already own so an agent can reach them, and package recurring analyst tasks as reusable skills instead of one-off scripts.&amp;nbsp;&lt;/p&gt;&lt;p&gt;That tracks with how this technology actually gets adopted. Nobody rips out their stack to adopt agentic AI. They teach an agent to drive what’s already there, and the integration layer is where the real work sits.&lt;/p&gt;&lt;h2&gt;The agentic AI builds the judges put on the podium&lt;/h2&gt;&lt;p&gt;Three teams took the podium. None of their work stayed in the room: every build had to ship to the CyberAgents Exchange as open source to be eligible to win, so the shortlist below is a set of tools you can read and run tonight. The judges — Tenable CSO Robert Huber, AWS Security Specialist SA Leader Chris Elmore, and a member of Anthropic’s technical staff — scored impact above everything else, and all three solve problems you probably recognize.&lt;/p&gt;&lt;h3&gt;First place: from thousands of findings to a handful of proven fixes&lt;/h3&gt;&lt;h4&gt;&lt;a href="https://exchange.tenable.com/playbooks/chokepoint-remediation-playbook/" target="_blank"&gt;&lt;strong&gt;Chokepoint Finder&lt;/strong&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;Built by Team Vauban; MIT licensed&lt;/p&gt;&lt;p&gt;Security teams don’t have a detection problem, they have a selection problem: a mid-size estate carries thousands of open findings and capacity for maybe 10 changes a week. Published as four agentic components—an &lt;a href="https://exchange.tenable.com/agents/chokepoint-finder/"&gt;agent&lt;/a&gt;, &lt;a href="https://exchange.tenable.com/mcp-servers/chokepoint-finder-mcp/"&gt;MCP server&lt;/a&gt;, &lt;a href="https://exchange.tenable.com/skills/chokepoint-finder-skill/"&gt;skill&lt;/a&gt;, and &lt;a href="https://exchange.tenable.com/playbooks/chokepoint-remediation-playbook/"&gt;playbook&lt;/a&gt;—Chokepoint Finder ranks fixes, not findings. It groups findings by the single action that resolves them (i.e., patches, base images, IAM roles, security groups, etc.) then solves for the shortest ordered list that mitigates the most weighted risk, leveraging its playbook to agentically inspect and rank fixes over eight distinct stages, with a human decision in the middle.&lt;/p&gt;&lt;p&gt;That discipline earned the top spot. The agent holds no write credentials, evidence it can’t read or can’t date resolves to a hold, and a re-scan has to prove the risk moved before the record closes. The team’s week stops being an unmanageable queue, collapsing its demo estate with 3,734 synthetic findings across 783 assets into seven concrete remediation actions. Each member of Team Vauban took home $2,000 in Anthropic credits, an AWS specialist certification voucher, and a gold-border SWARM patch.&lt;/p&gt;&lt;h3&gt;2nd Place: determine if flaws in code are reachable&lt;/h3&gt;&lt;h4&gt;&lt;a href="https://github.com/giraldomauricio/threatcorraling" target="_blank"&gt;&lt;strong&gt;ThreatCorraling&lt;/strong&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;by Team ShellCodeandChill; MIT licensed&lt;/p&gt;&lt;p&gt;A team running two scanners has two lists and no shared view: the code scanner flags a flaw, the application scanner watches the running app, and nobody can say whether the flaw is reachable. ThreatCorraling correlates Checkmarx static analysis results against Tenable Web Application Scanning findings for the same scoped assets, so a team can tell which flagged flaws are actually exposed in production.&lt;/p&gt;&lt;p&gt;From there it maps what it finds to SOC 2 and ISO 27001 controls and generates remediation and regression-testing patterns specific to the team’s stack, rather than generic advice. The reconciliation spreadsheet becomes a ranked, control-mapped list. It ships as both halves of the same code: a local app, and an MCP server exposing the same tools to clients like Claude Code. Each member of Team ShellCodeandChill took home $1,500 in Anthropic credits, an AWS specialist certification voucher, and a silver-border SWARM patch.&lt;/p&gt;&lt;h3&gt;3rd place: prove if findings were already mitigated&lt;/h3&gt;&lt;h4&gt;&lt;a href="https://exchange.tenable.com/agents/evidence-backed-vulnerability-investigator/" target="_blank"&gt;&lt;strong&gt;Evidence-Backed Vulnerability Investigator&lt;/strong&gt;&lt;/a&gt;&lt;/h4&gt;&lt;p&gt;by Team ZeroSignal; MIT licensed&lt;/p&gt;&lt;p&gt;Arguing that a finding was already mitigated usually means an analyst has to rebuild the case from memory with no traceable record of why. The Evidence-Backed Vulnerability Investigator loads scanner findings, matches them against the vendor advisories a team already keeps on disk, and asks Claude for a disposition with detailed justification evidence.&lt;/p&gt;&lt;p&gt;The matching is deterministic, performed by an identifier and keyword scoring script so analysts can reliably see why advisories are returned, and only the human’s decision gets recorded. The disposition arrives with its evidence attached instead of as an assertion. Anyone who’s argued with an auditor about a “critical” upgrade that’s quietly fixed knows what that saves. Each member of Team ZeroSignal took home $1,000 in Anthropic credits, an AWS specialist certification voucher, and a bronze-border SWARM patch.&lt;/p&gt;&lt;h3&gt;Congratulations to the winners!&lt;/h3&gt;&lt;p&gt;Congratulations to all three teams, and to everyone who shipped something in 48 hours and put their name on it in public. That takes more nerve than a demo. One SWARM participant walked out with an NVIDIA DGX Spark, drawn from raffle tickets every ceremony attendee earned just by being in the room.&lt;/p&gt;&lt;h2&gt;SWARM was two days, the CyberAgents Exchange lives on&lt;/h2&gt;&lt;p&gt;Every component built at SWARM is now on the &lt;a href="https://exchange.tenable.com/" target="_blank"&gt;CyberAgents Exchange&lt;/a&gt;, under open licenses, and that’s the whole point. The work gets done once. Take two days of work from a few dozen practitioners, then multiply it by a community publishing continuously instead of once at a hackathon, and you get the two things threat actors have always had that defenders haven’t: scale and distribution.&lt;/p&gt;&lt;h3&gt;What is the CyberAgents Exchange?&lt;/h3&gt;&lt;p&gt;The CyberAgents Exchange is the industry’s &lt;a href="https://exchange.tenable.com/" target="_blank"&gt;first open-source, vendor agnostic AI agent exchange&lt;/a&gt;, a cybersecurity-native registry for AI agents, skills, MCP servers, and multi-agent playbooks. It’s built around the objection practitioners actually have to agentic AI, and that objection was never automation. It’s opacity. You can’t responsibly hand production authority to something whose reasoning and provenance you can’t inspect. That isn’t blind distrust; it’s justifiable caution.&lt;/p&gt;&lt;p&gt;So every component links to its source repository. No bundled binaries. You can see who built it, when, and whether it’s been reviewed by Tenable, vetted by the community, or if it was freshly submitted. You set your own trust threshold before you run anything. The CyberAgents Exchange is free: there are no fees to list or use what’s there. SentinelOne and Recorded Future joined as founding members, which matters, because a registry carrying one vendor’s agents isn’t an exchange.&lt;/p&gt;&lt;p&gt;That’s the idea Tenable CTO Vlad Korsunsky keeps coming back to: “Security is a team sport,” he says. “We’re creating a collaborative ‘town square’ where cybersecurity practitioners can build, test, improve, and share the best in agentic defense.” Security has already learned to circulate threat intelligence, indicators of compromise, and detection rules. Agentic tooling is simply the next.&lt;/p&gt;&lt;h2&gt;&lt;strong&gt;Your turn to build an AI agent&lt;/strong&gt;&lt;/h2&gt;&lt;p&gt;Please &lt;a href="https://exchange.tenable.com" target="_blank"&gt;check out the CyberAgents Exchange&lt;/a&gt; for yourself!&lt;/p&gt;&lt;p&gt;Start by leveraging what other teams have already contributed. Find the component that maps to your own worst Tuesday scenario, read the source, inspect the code, and deploy it on your terms. Build if you feel inspired. If not, express your gratitude to builders, and strengthen our collective defense either way.&lt;/p&gt;&lt;h2&gt;&lt;strong&gt;Learn more&lt;/strong&gt;&lt;/h2&gt;&lt;ul&gt;&lt;li data-list-item-id="eb86faa6b000bc5343d754d92f34e3476"&gt;Read the &lt;a href="https://www.tenable.com/press-releases/tenable-launches-industrys-first-open-source-ai-agent-exchange" target="_blank"&gt;announcement of the CyberAgents Exchange&lt;/a&gt;, the industry’s first open-source AI agent exchange for cybersecurity&lt;/li&gt;&lt;li data-list-item-id="eaf263d88af52192c24a7b1930d9aa39d"&gt;See what &lt;a href="https://www.tenable.com/blog/testing-claude-mythos-preview-for-code-security-tenable" target="_blank"&gt;30 days with Claude Mythos Preview&lt;/a&gt; taught Tenable’s own security team about proving exploitability instead of ranking suspicion&lt;/li&gt;&lt;li data-list-item-id="e680af9ad658b84764f3a8ba40313ce28"&gt;Explore how &lt;a href="https://www.tenable.com/blog/tenable-hexa-ai-automating-exposure-remediation-with-agentic-routines" target="_blank"&gt;Tenable Hexa AI automates exposure remediation with agentic routines&lt;/a&gt;, with a human in the loop&lt;/li&gt;&lt;/ul&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/agentic-ai-for-cybersecurity.png"&gt;
</description>
  <pubDate>Fri, 07 Aug 2026 08:00:00 -0400</pubDate>
    <dc:creator>Nick Hayes</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211063</guid>
    </item>
<item>
  <title>AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing</title>
  <link>https://www.tenable.com/blog/ai-code-security-with-claude-mythos-preview-inside-tenables-500-hours-of-testing-for-project</link>
  <description>&lt;p&gt;We spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won't run your code security program, but used well, it can make one even stronger.&lt;/p&gt;&lt;div class="blog-see-also"&gt;&lt;div class="col-sm-12"&gt;&lt;h2&gt;&lt;strong&gt;Key takeaways&lt;/strong&gt;&lt;/h2&gt;&lt;ol&gt;&lt;li data-list-item-id="e577d43e429dc65895e4cd76cd28c7a4a"&gt;&lt;strong&gt;Frontier AI dramatically scales security testing.&lt;/strong&gt; In one month, Tenable dedicated 11 security experts and more than 40 billion tokens testing Claude Mythos Preview across source code analysis, exploit creation, binary reverse engineering, threat modeling, and dynamic testing.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li data-list-item-id="ed9bf244bd7f87605a56b396291dcc1f4"&gt;&lt;strong&gt;Human expertise turns frontier AI findings into real risk reduction.&lt;/strong&gt; More findings don't automatically mean more risk. Mythos Preview surfaced a high volume of findings, but only a fraction proved to be true exposures once Tenable experts determined their reachability, exploitability, and whether existing controls already mitigated them.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;li data-list-item-id="e9b168442fb57d2ca4adc0b9b3b15ee65"&gt;&lt;strong&gt;Source code access is the defender's asymmetric advantage.&lt;/strong&gt; Frontier AI is far more powerful when it can read the full source, and that visibility is something defenders have and outside attackers don't. Securing code repositories is more important than ever.&lt;br&gt;&amp;nbsp;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;/div&gt;&lt;p&gt;Ever since Anthropic introduced &lt;a href="https://www.tenable.com/blog/claude-mythos-prepare-for-AI-cybersecurity-questions-from-your-board-of-directors" target="_blank"&gt;Claude Mythos Preview&lt;/a&gt;, the security community has been buzzing with equal amounts of excitement, anxiety, and healthy skepticism.&lt;/p&gt;&lt;p&gt;After well over &lt;a href="https://www.tenable.com/blog/testing-claude-mythos-preview-for-code-security-tenable" target="_blank"&gt;500 hours of rigorous testing&lt;/a&gt; at the hands of Tenable security analysts, engineers, and researchers, we’re excited to share our assessment, even as we proceed with testing Claude Mythos 5 (more to come on that).&lt;/p&gt;&lt;p&gt;Here’s what Tenable learned from &lt;a href="https://www.tenable.com/blog/testing-claude-mythos-preview-for-code-security-tenable" target="_blank"&gt;our month in the trenches with Mythos Preview&lt;/a&gt;, and what it means for your organization’s security posture. Our headline finding: used well, frontier AI earns a real place in a modern code security program. It won't run the program on its own, but paired with the right harness and expert oversight, it makes a strong program measurably stronger.&lt;/p&gt;&lt;h2&gt;How Tenable is testing Claude Mythos Preview&lt;/h2&gt;&lt;p&gt;It’s important to clarify that we are not using &lt;a href="https://www.tenable.com/cybersecurity-guide/principles/claude-mythos-preview" target="_blank"&gt;Claude Mythos Preview&lt;/a&gt; in any Tenable products. The same restriction applies to all &lt;a href="https://www.tenable.com/blog/anthropic-claude-mythos-tenable-joins-project-glasswing" target="_blank"&gt;Project Glasswing&lt;/a&gt; participants: The model may be evaluated for research purposes, but it cannot be incorporated into commercial products.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;We evaluated the source code scanning, exploit creation, binary reverse engineering, threat model creation, and dynamic testing capabilities of Claude Mythos Preview.&lt;/strong&gt; &lt;strong&gt;Tenable dedicated a team of experienced security engineers for the testing along with white-box source code analysis and a purpose-built testing harness (the set of prompts and tools that constrain and orchestrate a model across a multi-step task).&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;Before evaluating Claude Mythos Preview, we built an independent testing harness. Our testing showed that the real power comes not from the model alone, but from the combination of the model, a purpose-built harness, rich context, and expert human oversight.&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Where Mythos and frontier AI fit alongside SAST, DAST, and SCA&lt;/h2&gt;&lt;p&gt;To understand where a frontier model like Claude Mythos Preview fits into your software security posture, it helps to compare Mythos directly to your existing stack of deterministic tools, including static application security testing (SAST), dynamic application security testing (DAST), and software composition analysis (SCA).&amp;nbsp;&lt;/p&gt;&lt;p&gt;Deterministic tools rely on hard-coded rules and produce the same exact output for any given input. Non-deterministic tools, like frontier AI models and generative AI systems, use statistical probabilities to predict outcomes. Consequently, non-deterministic systems can yield different results across identical inputs.&amp;nbsp;&lt;/p&gt;&lt;p&gt;The bottom line: Traditional, deterministic code security tools remain the core of an effective, audit- and compliance-ready program. &lt;strong&gt;Frontier AI models like Claude Mythos Preview provide additional capability for the creative, variance-tolerant layer where humans continue to review findings.&lt;/strong&gt; In other words, it’s a powerful new arrow in the quiver with the potential to make your whole security arsenal more effective.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Table 1: Traditional security scanning tools vs. Claude Mythos Preview&amp;nbsp;&lt;/strong&gt;&lt;/p&gt;&lt;table class="table"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Feature&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Traditional tools (SAST, DAST, SCA)&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Frontier AI models&lt;/strong&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Consistency&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Deterministic&lt;/strong&gt;: Produces identical, highly repeatable results every run. Perfect for enterprises with rigorous compliance requirements.&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Non-deterministic&lt;/strong&gt;: Yielded as much as a 30% run-to-run variance in finding counts and severity rankings during Tenable’s testing.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Operational cost&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;&lt;strong&gt;Low&lt;/strong&gt;: Fast, cheap, and easily integrated into continuous &lt;a href="https://www.tenable.com/cybersecurity-guide/learn/ci-cd-workflow-integration" target="_blank"&gt;CI/CD pipelines&lt;/a&gt;.&lt;/td&gt;&lt;td&gt;&lt;strong&gt;High&lt;/strong&gt;: Expensive to validate raw, noisy outputs; best used for periodic testing.&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;Strength&lt;/strong&gt;&lt;/td&gt;&lt;td&gt;Catching known vulnerabilities, patch-diffing, and maintaining compliance baselines.&lt;/td&gt;&lt;td&gt;Creative, exploratory “offensive” testing, threat modeling, and contextual code analysis.&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;h2&gt;Match the tool to the task: determinism for audit, frontier AI for exploration&lt;/h2&gt;&lt;p&gt;Frontier AI models, including Claude Mythos Preview, are fundamentally non-deterministic. If you run the exact same target through the exact same model on different days, the model will yield different results.&lt;/p&gt;&lt;p&gt;In Tenable’s testing, we observed Mythos outputting different issue counts &lt;em&gt;and&lt;/em&gt; different severity rankings, despite using the exact same prompt. That variance is an asset for creative, exploratory work with an expert reviewing output, but it's the wrong fit as the backbone of a consistent, repeatable, audit-grade security or compliance program. For this reason, deterministic tooling remains core, though it will need to adapt to AI and integrate it in a meaningful way.&lt;/p&gt;&lt;p&gt;That adaptation isn't free. Before you fold a frontier model into a security program, three constraints shape where and how it earns its place:&lt;/p&gt;&lt;ol&gt;&lt;li data-list-item-id="e4ee21bd60cc79aa28eb96f766841dfab"&gt;&lt;strong&gt;The cost &lt;/strong&gt;- The economics only work when you're deliberate about where you deploy it. The tokens required to run the model as a continuous scanning tool would be cost-prohibitive — in our estimation, costs could reach $500,000 per full-time employee (FTE) per year, based on an estimated one-month token usage of roughly $41,700 per FTE.&amp;nbsp;&lt;/li&gt;&lt;li data-list-item-id="e3607880b1f139c490ad3989850767da4"&gt;&lt;strong&gt;The noise &lt;/strong&gt;- In Tenable tests, model outputs (the findings) were noisy and required heavy validation. Consequently, if you’re going to use Claude Mythos Preview for source code scanning, you’ll want to feed the model’s high-quality findings into your existing static analysis and gating workflows. Without a validation pipeline working alongside the model, you’ll get buried in noise.&amp;nbsp;&lt;/li&gt;&lt;li data-list-item-id="e873a991c650c56c69bdf4896cf5e7316"&gt;&lt;strong&gt;The results &lt;/strong&gt;- Claude Mythos Preview produced different outputs even when our inputs were the same. This kind of inconsistent model behavior breaks pipelines that need to run predictably at scale. What’s more, compliance requirements demand reproducible, defensible evidence. A model that produces different results each run won’t stand up to auditors.&amp;nbsp;&lt;/li&gt;&lt;/ol&gt;&lt;h2&gt;The real costs of code security with frontier AI go beyond tokens&lt;/h2&gt;&lt;p&gt;When calculating the total cost of ownership (TCO) for frontier AI as code security tool, many organizations make the mistake of focusing exclusively on API and token costs.&amp;nbsp;&lt;/p&gt;&lt;p&gt;While token costs can quickly add up, they still represent just one factor in the TCO equation. Because frontier models generate a high volume of noisy findings, your TCO model should include the cost to validate the findings, which includes the cost of the experienced security engineers required to handle the manual validation.&amp;nbsp;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;TCO is why frontier AI works best as a targeted, high-value layer rather than a day-to-day security scanning engine.&lt;/strong&gt; Run it against everything continuously and the costs quickly become prohibitive, quickly. Consider that just one of our security analysts used more than 10 billion tokens in a month of rigorous testing, which cost $41,700. Multiply that by 12 months, and you’ve got a nearly $500,000 annual run rate for just that one person.&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Frontier AI changes the scale of discovery, not the nature of source code flaws&lt;/h2&gt;&lt;p&gt;Some organizations are bracing for a new class of “Mythos-level” bugs. Based on our experience with Mythos, that’s the wrong worry. The model finds the same kinds of source code flaws a pen tester would, such as broken logic and memory corruption; it just finds far more of them, at much greater speed, and if appropriately prompted, can create the exploit. &lt;strong&gt;Claude Mythos hasn’t uncovered a new class of vulnerabilities; it’s amplified the speed and volume of findings.&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;It’s important to remember that a potential finding is not the same as a validated exposure. A finding signals a &lt;em&gt;potential&lt;/em&gt; issue. AI surfaces a large volume of findings, but &lt;a href="https://www.tenable.com/products/tenable-one" target="_blank"&gt;security teams require context&lt;/a&gt; about potential flaws in the source code — whether they’re reachable, exploitable, and the extent to which any existing security controls mitigate them — to validate and remediate the findings that do indeed create true exposure.&amp;nbsp;&lt;/p&gt;&lt;blockquote&gt;&lt;p&gt;In a world of AI-driven vulnerability discovery, the context, triage, validation, and prioritization work become much more important. Once you subtract what your existing tools already catch, what others have reported, and what isn’t actually reachable, the list worth acting on gets shorter. Your capacity to validate and fix is the constraint now, not discovery.&lt;/p&gt;&lt;/blockquote&gt;&lt;h2&gt;Source code access gives defenders a major advantage&lt;/h2&gt;&lt;p&gt;The immense power of frontier models in code security relies on “white-box” source code analysis. Source code access gives internal security teams the ultimate asymmetric advantage against threat actors. The deep source code visibility that supercharges an internal defender’s automated pipeline is exactly what an outside, black-box attacker lacks.&amp;nbsp;&lt;/p&gt;&lt;p&gt;Consequently, protecting your source code repository has never been more vital. If an attacker gains access to your source code, they gain the keys to run their own highly optimized AI discovery engines against you.&lt;/p&gt;&lt;h2&gt;The bottom line: frontier AI shifts your edge from finding flaws to proving what matters&lt;/h2&gt;&lt;p&gt;Tenable testing confirmed Claude Mythos Preview can function as a highly capable pen-testing tool.&amp;nbsp;&lt;/p&gt;&lt;p&gt;When combined with a purpose-built harness and the two things only a human defender has — source code access and the ability to validate findings live — Claude Mythos Preview can deliver powerful results. Give it a harness and an expert to drive it, and it becomes a genuine force multiplier; leave Mythos to run on its own and the output tends to be noisy, with many of the findings never making it to validation. Either way, frontier AI shifts the hard work from discovery to verification, prioritization, and remediation.&lt;/p&gt;&lt;p&gt;We continue to evaluate frontier AI models, including Mythos 5, to identify where they’ll serve customers best, and we look forward to sharing our ongoing findings in upcoming blogs.&amp;nbsp;&lt;/p&gt;&lt;h2&gt;Learn more&lt;/h2&gt;&lt;ul&gt;&lt;li data-list-item-id="ee428ffc888e4d7629a9ea4faf1d26091"&gt;&lt;a href="https://www.tenable.com/blog/testing-claude-mythos-preview-for-code-security-tenable"&gt;Inside Tenable’s first 30 days with Claude Mythos Preview&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="ef989e3ba7c6e9c8a0385e964cb71e91c"&gt;&lt;a href="https://www.tenable.com/cybersecurity-guide/principles/claude-mythos-preview"&gt;What is Claude Mythos Preview?&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="efe00d158ea0273eb0e2c2fc163533c13"&gt;&lt;a href="https://www.tenable.com/blog/claude-mythos-prepare-for-AI-cybersecurity-questions-from-your-board-of-directors"&gt;Claude Mythos: Prepare for your board’s cybersecurity questions about the latest model from Anthropic&lt;/a&gt;&lt;/li&gt;&lt;li data-list-item-id="e31840394798b8b58b0dd29154b3591b7"&gt;&lt;a href="https://www.tenable.com/blog/anthropic-claude-mythos-tenable-joins-project-glasswing"&gt;Tenable joins Anthropic’s Project Glasswing to advance AI-era cyber defense&amp;nbsp;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;img src="https://www.tenable.com/sites/default/files/images/articles/ai%20code%20security%20with%20claude%20mythos%20preview.png"&gt;
</description>
  <pubDate>Thu, 06 Aug 2026 08:00:00 -0400</pubDate>
    <dc:creator>Robert Huber, Tenable Research</dc:creator>
    <guid isPermaLink="true">https://www.tenable.com/211058</guid>
    </item>

  </channel>
</rss>
