Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Blog de Tenable

April 6, 2026

CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild

Exploitation has been observed for CVE-2026-35616, a critical improper access control zero-day vulnerability affecting Fortinet FortiClientEMS devices.Key takeaways:CVE-2026-35616, an improper access ...

25 de abril de 2025

CVE-2025-31324: Vulnerabilidad de día cero en SAP NetWeaver explotada en la realidad

SAP has released out-of-band patch to address CVE-2025-31324, a critical zero-day vulnerability in SAP NetWeaver that has been exploited by threat actors. Organizations are strongly encouraged to apply patches as soon as possible.


25 de abril de 2025

Instantánea de ciberseguridad: Verizon DBIR Finds Attackers Feast on Vulnerability Exploits for Initial Access, While MITRE ATT&CK Adds Mobile, Cloud, ESXi Threat Intel

Check out highlights from this year’s Verizon DBIR, including a surge in zero-day exploits targeting edge devices and VPNs. Plus, find out what’s new in the latest version of MITRE ATT&CK. Also, see what Tenable webinar attendees said about AI security. And get the latest on ransomware preparedness…


24 de abril de 2025

A pesar del reciente endurecimiento de la seguridad, la función de sincronización de Entra ID permanece susceptible a vulneraciones perpetradas por atacantes

Microsoft synchronization capabilities for managing identities in hybrid environments are not without their risks. In this blog, Tenable Research explores how potential weaknesses in these synchronization options can be exploited.


23 de abril de 2025

Seguridad en la nube más robusta en cinco minutos: Cómo proteger sus cargas de trabajo en la nube

In the first installment of Tenable’s “Stronger Cloud Security in Five” blog series, we covered cloud security posture management (CSPM), which focuses on protecting your multi-cloud infrastructure by detecting misconfigurations. Today, we turn to securing cloud workloads, which are the…


23 de abril de 2025

Verizon 2025 DBIR: La colaboración de Tenable Research destaca las tendencias de corrección de CVE

The 2025 Verizon Data Breach Investigations Report (DBIR) reveals that vulnerability exploitation was present in 20% of breaches — a 34% increase year-over-year. To support the report, Tenable Research contributed enriched data on the most exploited vulnerabilities. In this blog, we analyze 17 edge…


22 de abril de 2025

Cumplimiento de CISA BOD 25-01 Compliance: Lo que los organismos gubernamentalesde los EE. UU. necesitan saber

U.S. government agencies are required to bring their Microsoft 365 cloud services into compliance with a recent Binding Operational Directive. Here’s how Tenable can help.


22 de abril de 2025

ConfusedComposer: Una vulnerabilidad de escalación de privilegios que afecta a GCP Composer

Tenable Research discovered a privilege-escalation vulnerability in Google Cloud Platform (GCP) that is now fixed and which we dubbed ConfusedComposer. The vulnerability could have allowed an identity with permission (composer.environments.update) to edit a Cloud Composer environment to escalate…


April 21, 2025

Turn to Exposure Management to Prioritize Risks Based on Business Impact

Todos los lunes, la Exposure Management Academy de Tenable ofrece la orientación práctica y del mundo real que necesita para pasar de la gestión de vulnerabilidades a la gestión de exposición. In this post, Tenable CSO Robert Huber shares practical advice on using an exposure management program to focus on risks that have…


April 18, 2025

CVE-2025-32433: Vulnerabilidad de ejecución de código remoto no autenticado de Erlang/OTP SSH

Proof-of-concept code has been released after researchers disclosed a maximum severity remote code execution vulnerability in Erlang/OTP SSH. Successful exploitation could allow for complete takeover of affected devices.


Noticias de ciberseguridad que le son útiles

Ingrese su correo electrónico y nunca se pierda alertas oportunas y orientación en seguridad de los expertos de Tenable.