Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable blog

April 22, 2025

ConfusedComposer: A Privilege Escalation Vulnerability Impacting GCP Composer

Tenable Research discovered a privilege-escalation vulnerability in Google Cloud Platform (GCP) that is now fixed and which we dubbed ConfusedComposer. The vulnerability could have allowed an identity with permission (composer.environments.update) to edit a Cloud Composer environment to escalate privileges to the default Cloud Build service account. The default Cloud Build service account includes permissions to Cloud Build itself, as well as to Cloud Storage, Artifact Registry, and more.

December 10, 2021

CVE-2021-44228: Proof-of-Concept for Critical Apache Log4j Remote Code Execution Vulnerability Available (Log4Shell)

Critical vulnerability in the popular logging library, Log4j 2, impacts a number of services and applications, including Minecraft, Steam and Apple iCloud. Attackers have begun actively scanning for and attempting to exploit the flaw....


December 9, 2021

How to Start Up Your Cloud Security

Startups may think they can postpone implementing a cloud security program but should in fact take early action — here’s why, and easy steps for doing so....


December 7, 2021

Introducing Tenable.cs: Full Lifecycle, Cloud Native Security

The new offering extends the recently acquired Accurics platform to enable DevSecOps and “shift left security” with integrated controls for development and runtime workflows, focused on Infrastructure as Code (IaC)....


December 6, 2021

Securing IT-OT Environments: Why IT Security Professionals Struggle

When providing cybersecurity in converged IT and operational technology environments, it’s critical for infosec pros to understand the differences between the two and utilize a toolset that delivers a comprehensive picture of both in a single view....


November 30, 2021

#GivingTuesday: Favorite Charities of Tenable Employees

This year for #GivingTuesday, we highlight some of the causes that Tenable employees have championed this year and invite you to do the same. ...


November 23, 2021

Not Just Buckets: Are You Aware of ALL Your Public Resources?

A misconfiguration of resource-based policies can inadvertently make resources public. Do you have such misconfigured policies present in your environment?...


November 23, 2021

Fake Bitcoin, Ethereum, Dogecoin, Cardano, Ripple and Shiba Inu Giveaways Proliferate on YouTube Live

Scammers are leveraging compromised YouTube accounts to promote fake cryptocurrency giveaways for Bitcoin, Ethereum, Dogecoin, Cardano, Ripple, Shiba Inu and other cryptocurrencies....


November 18, 2021

Identifying Server Side Request Forgery: How Tenable.io Web Application Scanning Can Help

Learn how SSRF flaws arise, why three common attack paths are so challenging to mitigate and how Tenable.io Web Application Scanning can help....


November 17, 2021

Four Questions to Minimize the Cyber Risk of Your Public-facing Assets and Web Apps

Ask the following four questions to help reduce cyber risk in your public-facing assets and web apps....


Cybersecurity news you can use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

A Look Inside the Ransomware Ecosystem

Download the Report >