Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable blog

June 18, 2025

公开的机密信息:云数据风险暴露将企业置于风险境地

Sensitive data and secrets are leaking. How cloud security leaders can shut them down....


June 17, 2025

GerriScary:破解常见 Google 产品(ChromiumOS、Chromium、Bazel、Dart 等)的供应链。

Tenable Cloud Research discovered a supply chain compromise vulnerability in Google's Gerrit code-collaboration platform which we dubbed GerriScary. GerriScary allowed unauthorized code submission to at least 18 Google projects including ChromiumOS (CVE-2025-1568), Chromium, Dart and Bazel, which ar...


June 16, 2025

风险暴露管理就是主动安全的未来

Each Monday, the Tenable Exposure Management Academy provides the practical, real-world guidance you need to shift from vulnerability management to exposure management. In this post, Jorge Orchilles, Senior Director of Readiness and Proactive Security at Verizon, offers an up-close glimpse at the th...


June 13, 2025

網路安全快照: NIST 发布零信任实施建议,OpenAI 披露 ChatGPT 滥用事件

Check out NIST best practices for adopting a zero trust architecture. Plus, learn how OpenAI disrupted various attempts to abuse ChatGPT. In addition, find out what Tenable webinar attendees said about their exposure management experiences. And get the latest on cyber crime trends, a new cybersecuri...


June 11, 2025

新的网络安全行政命令:您需要了解的要点

A new cybersecurity Executive Order aims to modernize federal cybersecurity with key provisions for post-quantum encryption, AI risk and secure software development....


June 10, 2025

Microsoft 的 2025 年 6 月补丁星期二解决了 65 个 CVE (CVE-2025-33053)

Microsoft addresses 65 CVEs, including two zero-day vulnerabilities, with one being exploited in the wild....


June 9, 2025

如何在风险暴露管理计划中使用基于风险的指标

Each Monday, the Tenable Exposure Management Academy provides the practical, real-world guidance you need to shift from vulnerability management to exposure management. In this post, Tenable security engineers Arnie Cabral and Jason Schavel share how you can use risk-based metrics. ...


June 6, 2025

網路安全快照: Experts Issue Best Practices for Migrating to Post-Quantum Cryptography and for Improving Orgs’ Cyber Culture

Check out a new roadmap for adopting quantum-resistant cryptography. Plus, find out how your company can create a better cybersecurity environment. In addition, MITRE warns about protecting critical infrastructure from cyber war. And get the latest on exposure response strategies and on CISO compens...


June 4, 2025

五步加强云安全:在 GCP 中提升 Kubernetes 安全的 3 个快捷方法

In this fifth installment of Tenable’s “Stronger Cloud Security in Five” blog series, we offer three best practices for quickly hardening your Kubernetes environment’s security in GCP: remove wide inbound access to cluster APIs; remove root permissions from containers; and remove privileged permissi...


June 3, 2025

滥用客户端扩展 (CSE):您的 AD 环境存在后门

Crucial for applying Active Directory Group Policy Objects, client-side extensions (CSEs) are powerful but also present a significant, often overlooked, attack vector for persistent backdoors. Rather than cover well-documented common abuses of built-in CSEs, this article demonstrates how to create c...


June 2, 2025

关于 BadSuccessor 的常见问题

Frequently asked questions about “BadSuccessor,” a zero-day privilege escalation vulnerability in Active Directory domains with at least one Windows Server 2025 domain controller....


June 2, 2025

突破信息孤岛,实施风险暴露管理

Each Monday, the Tenable Exposure Management Academy provides the practical, real-world guidance you need to shift from vulnerability management to exposure management. In this post, Tenable’s chief security officer Robert Huber looks at how exposure management can help you move beyond silos....


您可加以利用的网络安全新闻

输入您的电子邮件,绝不要错过 Tenable 专家的及时提醒和安全指导。

Apache Log4j 缺陷让第三方软件成为关注焦点

获取详细信息 >