Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs 2026-05-29 True Research Special Operations True Download pumping: New npm deception technique for supply chain attacks 2026-05-28 True Ron Popov True Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect 2026-05-27 True Trevor Farthing True Key findings from the Verizon DBIR 2026: Slower vulnerability remediation meets faster exploitation 2026-05-19 True Scott Caveza True Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182) 2026-05-15 True Research Special Operations True Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation 2026-05-14 True Satnam Narang True Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103) 2026-05-12 True Research Special Operations True Dirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chain 2026-05-08 True Scott Caveza True Why the approaching flood of vulnerabilities changes everything — and what to do about it 2026-05-08 True Raymond Carney True Copy Fail (CVE-2026-31431): Frequently asked questions about Linux kernel privilege escalation vulnerability 2026-04-30 True Satnam Narang True As the NVD scales back CVE enrichment, here’s what Tenable customers need to know 2026-04-27 True Lucas Tamagna-Darr True Crushing the Axios supply chain threat with Tenable Hexa AI: Use cases for agentic AI 2026-04-10 True James Davies True What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure 2026-04-09 True Research Special Operations True CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild 2026-04-06 True Scott Caveza True The developer credential economy: Why exposure data is the new front line in the supply chain war 2026-04-03 True Research Special Operations True Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069 2026-04-01 True Research Special Operations True Supply chain attack on Axios npm package: Scope, impact, and remediations 2026-03-31 True Ron Popov True What’s new in Tenable Cloud Security: Custom policies, AWS ABAC, and research-driven protection 2026-03-31 True Yoel Calderon True The hidden cost of AI speed: Unmanaged cyber risk 2026-03-23 True Ari Eitan True CVE-2026-21992: Critical Out-of-Band Oracle Identity Manager and Oracle Web Services Manager Remote Code Execution Vulnerability 2026-03-20 True Satnam Narang True FAQ on CVE-2026-21514: OLE bypass N-Day in Microsoft Word 2026-03-17 True Research Special Operations True Operation Epic Fury: Why exposure data changes everything about Iran's cyber-kinetic campaign 2026-03-17 True Robert Huber True Cyber Retaliation: Analyzing Iranian Cyber Activity Following Operation Epic Fury 2026-03-11 True Research Special Operations True LeakyLooker: Hacking Google Cloud’s Data via Dangerous Looker Studio Vulnerabilities 2026-03-10 True Liv Matan True Operation Epic Fury: Potential Iranian Cyber Counteroffensive Operations 2026-03-03 True Research Special Operations True CVE-2026-20127: Cisco Catalyst SD-WAN Controller/Manager Zero-Day Authentication Bypass Vulnerability Exploited in the Wild 2026-02-25 True Scott Caveza True New Malicious npm Package "ambar-src" Targets Developers with Open Source Malware 2026-02-24 True Ron Popov True I pretended to be an AI agent on Moltbook so you don’t have to 2026-02-09 True Ben Smith True LookOut: Discovering RCE and Internal Access on Looker (Google Cloud & On-Prem) 2026-02-04 True Liv Matan True Frequently Asked Questions About Notepad++ Supply Chain Compromise 2026-02-03 True Satnam Narang True CVE-2026-1281, CVE-2026-1340: Ivanti Endpoint Manager Mobile (EPMM) Zero-Day Vulnerabilities Exploited 2026-01-30 True Research Special Operations True Tenable Discovers SSRF Vulnerability in Java TLS Handshakes That Creates DoS Risk 2026-01-20 True Ireneusz Pastusiak True CVE-2025-14847 (MongoBleed): MongoDB Memory Leak Vulnerability Exploited in the Wild 2025-12-29 True Scott Caveza True CVE-2025-40602: SonicWall Secure Mobile Access (SMA) 1000 Zero-Day Exploited 2025-12-17 True Scott Caveza True Cybersecurity Snapshot: OWASP Ranks Top Agentic AI App Risks, as CISA Lists Most Dangerous Software Flaws 2025-12-12 True Juan Perez True Cybersecurity Snapshot: Fending Off BRICKSTORM Malware Data-Theft Attacks and Integrating AI into OT Securely 2025-12-05 True Juan Perez True CVE-2025-55182: Frequently Asked Questions About React2Shell: React Server Components Remote Code Execution Vulnerability 2025-12-04 True Satnam Narang True Agentic AI Security: Keep Your Cyber Hygiene Failures from Becoming a Global Breach 2025-12-01 True Robert Huber True A Practical Defense Against AI-led Attacks 2025-12-01 True Blake Kizer True Verizon 2025 DBIR: Tenable Research Collaboration Shines a Spotlight on CVE Remediation Trends 2025-04-23 True Scott Caveza True ConfusedComposer: A Privilege Escalation Vulnerability Impacting GCP Composer 2025-04-22 True Liv Matan True CVE-2025-32433: Erlang/OTP SSH Unauthenticated Remote Code Execution Vulnerability 2025-04-18 True Scott Caveza, Ben Smith True Cybersecurity Snapshot: Ghost Ransomware Group Targets Known Vulns, CISA Warns, While Report Finds Many Cyber Pros Want To Switch Jobs 2025-02-21 True Juan Perez True How To Reduce DNS Infrastructure Risk To Secure Your Cloud Attack Surface 2025-02-19 True Rémy Marot True Cybersecurity Snapshot: Cyber Agencies Offer Best Practices for Network Edge Security, While OWASP Ranks Top Risks of Non-Human Identities 2025-02-07 True Juan Perez True Salt Typhoon: An Analysis of Vulnerabilities Exploited by this State-Sponsored Actor 2025-01-23 True Scott Caveza True CVE-2024-55591: Fortinet Authentication Bypass Zero-Day Vulnerability Exploited in the Wild 2025-01-14 True Scott Caveza True CVE-2025-0282: Ivanti Connect Secure Zero-Day Vulnerability Exploited In The Wild 2025-01-08 True Satnam Narang True Cybersecurity Snapshot: After Telecom Hacks, CISA Offers Security Tips for Cell Phone Users, While Banks Seek Clearer AI Regulations 2025-01-03 True Juan Perez True