Tenable ブログ
サイバーセキュリティニュース: Cybersecurity Awareness Month Arrives To Find AI Security a Hot Mess, as New OT Security Guidelines Highlight Architecture Mapping

購入するか構築するかのジレンマ:エクスポージャー管理における DIY アプローチの落とし穴
Some security teams are taking a do-it-yourself approach to exposure management, according to a recent study conducted by Enterprise Strategy Group, now part of Omdia, in partnership with Tenable. But are they really ready for the hidden costs and challenges that come with a homegrown system?
Trifecta: クラウドアシスト、検索モデル、ブラウジングにおける 3 つの新たな Gemini 脆弱性により個人データが流出
Tenable Research discovered three vulnerabilities (now remediated) within Google’s Gemini AI assistant suite, which we dubbed the Gemini Trifecta. These vulnerabilities exposed users to severe privacy risks. They made Gemini vulnerable to: search-injection attacks on its Search Personalization…
サイバーセキュリティニュース: CISA が侵害分析における脆弱性管理の重要性を強調、シスコの製品に対するゼロデイ攻撃のパッチ適用が強く推奨される
CISA’s takeaways of an agency hack include a call for timely vulnerability patching. Plus, Cisco zero-day bugs are under attack — patch now. Meanwhile, the CSA issued a framework for SaaS security. And get the latest on the npm breach, the ransomware attack that disrupted air travel and more!
CVE-2025-20333、CVE-2025-20362: Cisco Adaptive Security Appliance (ASA) および Firewall Threat Defense (FTD) のゼロデイ脆弱性に関するよくある質問
Cisco published advisories and a supplemental post about three zero-day vulnerabilities, two of which were exploited in the wild by an advanced threat actor associated with the ArcaneDoor campaign.
将来に備えたサイバーセキュリティ支出
A recent study conducted by Enterprise Strategy Group, now part of Omdia, in partnership with Tenable reveals that complexity is driving a growing number of organizations to increase their exposure management budgets. Here are 5 considerations to help make the most of your investments.
州全体のサイバーセキュリティ: 州・地方行政機関や教育機関(SLED)を統合して最大限の効果を実現
In my work at Tenable, I’ve had the opportunity to meet with many CIOs, CISOs and executives nationwide. I’ve seen firsthand how successful whole-of-state efforts can solve three key challenges and help agencies reduce their cyber risk.
Active Directory のサービス アカウント: 非人間アイデンティティ(NHI)はサイバーセキュリティの最弱リンクになる可能性がある
While non-human identities (NHIs) in cloud and SaaS operations may be getting lots of attention lately, securing your Active Directory service accounts can go a long way in reducing risk. Here are three steps you can take right now.
クラウドの設定ミスリスクの解消: 隠れたクラウドセキュリティ上の欠陥を発見し修正する
Seemingly innocuous cloud configuration errors can create massive security risks, especially if your teams are siloed and your security tools don’t play well with each other. Find out how a unified, proactive security approach provides the visibility and automation needed to find and fix these…
サイバーセキュリティニュース: 調査によると CISO はセキュリティプラットフォームを活用している、AI コーディングツールには適切な監督が必要だと OpenSSF が警告
Check out why CISOs are embracing security platforms to reduce tool sprawl. Plus, learn how to prompt AI developer assistants so that they generate secure code. Further, dig into CISA’s analysis of malware tied to Ivanti EPMM vulnerabilities. And get the latest on external attack surface management…