Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable blog

April 22, 2025

ConfusedComposer: A Privilege Escalation Vulnerability Impacting GCP Composer

Tenable Research discovered a privilege-escalation vulnerability in Google Cloud Platform (GCP) that is now fixed and which we dubbed ConfusedComposer. The vulnerability could have allowed an identity with permission (composer.environments.update) to edit a Cloud Composer environment to escalate privileges to the default Cloud Build service account. The default Cloud Build service account includes permissions to Cloud Build itself, as well as to Cloud Storage, Artifact Registry, and more.

May 17, 2022

Mind the (Communication) Gap: How Security Leaders Can Become Dev and Ops Whisperers

Developers, Ops and DevOps teams must incorporate security into their processes – often a hard sell. Here’s how security leaders can successfully align with them to weave security into their tools and workflows....


May 17, 2022

Terrascan Joins the Nessus Community, Enabling Nessus To Validate Modern Cloud Infrastructures

The addition of Terrascan to the Nessus family of products helps users better secure cloud native infrastructure by identifying misconfigurations, security weaknesses, and policy violations by scanning Infrastructure as Code repositories. ...


May 17, 2022

Identity Access Management in Google Cloud Platform (GCP IAM): What Security Pros Need to Know

An introduction to GCP’s RBAC mechanism for permission assignments — and how to apply the principles of least privilege to keep your organization secure....


May 16, 2022

Tenable.io Achieves StateRAMP Authorization as Part of Our Commitment to Protect State and Local Governments

StateRAMP-authorized cloud solutions like Tenable.io meet stringent security and compliance standards....


May 13, 2022

Locate Tenable Compliance Templates Faster with Revamped Portal

Following a portal relaunch, Tenable’s Audit Files are now easier to find and manage, thanks to a new search engine that supports a variety of search query criteria....


May 12, 2022

3 Ways Security Leaders Can Work With DevOps to Build a Culture of Security

Learn how your organization can boost security efforts by eliminating the disconnect between Security and DevOps teams. Establishing a strong security culture that bridges the gap between DevOps and security is one of the greatest challenges that CISOs and other security leaders face. Because ...


May 12, 2022

Announcing the 2022 Tenable Assure Partner Award Winners

Celebrating the elite defenders who are helping organizations around the world reduce their cyber risk. Cybersecurity is always a team effort. Day in, day out, defenders rely on an ecosystem of teams, partners and vendors to address the evolving threat landscape and deliver holistic security. ...


May 10, 2022

Microsoft’s May 2022 Patch Tuesday Addresses 73 CVEs (CVE-2022-26925)

Microsoft addresses 73 CVEs in its May 2022 Patch Tuesday release, including two zero-day vulnerabilities, one of which was exploited in the wild....


May 10, 2022

The Era of Responsible Cybersecurity Finally Arrives

The SEC’s proposed rule on cybersecurity promotes transparency and encourages free market forces....


Cybersecurity news you can use

Enter your email and never miss timely alerts and security guidance from the experts at Tenable.

A Look Inside the Ransomware Ecosystem

Download the Report >