Skip to content
Visnia
CtrlK
EconomyAI buildoutMarket MapFundsWatchlist
Log in
Market cap
Revenue
Net income
Cash on hand
Gross margin
Net margin
EPS
P/E ratio
Search
Market mapFundsWatchlist
Visnia

TTenable Holdings, Inc.

EconomyAI buildoutMarket MapFundsWatchlist
Log in
T

Tenable Holdings, Inc.

  • Overview
  • Financial statements
  • Metrics
  • Quarterly earnings
  • Similar companies
  • History
  • News
  • Insider Transactions

News

News

  • Oracle September 2026 Critical Security Patch Update addresses 672 CVEs
    Sep 15, 2026Tenable Blog

    Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates.Key TakeawaysThe September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates104 issues (15.5% of all patches) were assigned a critical severity ratingOracle E-Business Suite received the highest number of patches at 159, accounting for 23.6% of all patchesBackgroundOn September 15, Oracle released its Critical Security Patch Update (CSPU) for September 2026. Beginning in May 2026, Oracle introduced CSPUs as a monthly release cycle that sits between the larger quarterly Critical Patch Updates (CPUs), addressing a focused set of high-severity issues on a faster cadence. This CSPU contains fixes for 672 unique CVEs in 673 security updates across 17 Oracle product families. Out of the 673 security updates published, 15.5% of patches were assigned a critical severity. High severity patches accounted for the bulk of security patches at 74.7%, followed by critical severity patches at 15.5%.This month's update includes 104 critical patches across 104 CVEs.SeverityIssues PatchedCVEsCritical104104High503503Medium5958Low77Total673672AnalysisThis month's update saw the Oracle E-Business Suite product family contain the highest number of patches at 159, accounting for 23.6% of the total patches, followed by Oracle Fusion Middleware at 153 patches, which accounted for 22.7% of the total patches.A full breakdown of the patches for this CSPU can be seen in the following table, which also includes a count of vulnerabilities that can be exploited over a network without authentication.Oracle Product FamilyNumber of PatchesRemote Exploit without AuthOracle E-Business Suite15919Oracle Fusion Middleware15378Oracle Hyperion10250Oracle Siebel CRM6326Oracle Analytics508Oracle Communications3123Oracle Commerce2716Oracle Supply Chain195Oracle Virtualization191Oracle PeopleSoft164Oracle Database Server115Oracle Enterprise Manager75Oracle Financial Services Applications62Oracle Application Testing Suite30Oracle Java SE33Oracle Autonomous Health Framework21Oracle Utilities Applications21SolutionPatches are available in the September 2026 advisory for full details.<h

  • Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.
    Sep 15, 2026Tenable Blog

    Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential Eight itself only ever covered on-premises enterprise IT, built around eight named technical controls, such as application control and patching. It never extended to the security of cloud, identity, or OT.The shift challenges the traditional checklist approach to cybersecurity, where organizations demonstrate compliance through periodic assessments and point-in-time reports.In dynamic environments spanning IT, cloud, identity, and OT, security posture can change quickly and repeatedly between assessments.Exposure management can help organizations continuously understand where they are exposed, prioritize the most critical weaknesses, and provide evidence of their current security posture.ASD’s strategic shift to active security posture validationCan you prove your security posture is solid, right now, on demand?That’s the question the Australian Signals Directorate (ASD) has effectively put in front of every Australian organization’s board, CISO, and C-suite.ASD’s decision to retire the Essential Eight signals a fundamental move away from point-in-time, checklist-based security toward an outcomes-focused model where organizations will need to demonstrate continuous compliance.It’s no longer enough to show that your organization had a control in place at the time of the last assessment. In a technology environment that changes continuously across IT, cloud, identity, and operational technology (OT), organizations must be able to answer a much more immediate question:How are we currently exposed?&nbsp;ASD is replacing the Essential EightASD announced it was replacing the Essential Eight in June 2026. The agency expects deprecation to begin around mid-2027, roughly 12 months later. This is the point at which ASD starts actively steering organizations toward the new framework, not a deadline by which compliance must switch over.&nbsp;Full retirement of the Essential Eight follows about a year after that, around mid-2028. ASD has described these timelines as targets rather than fixed dates, and both the Essential Eight and the new Essentials series will remain live throughout the transition.Compliance isn’t universally mandatory. The Protective Security Policy Framework requires the Essential Eight for roughly 98 non-corporate Commonwealth entities. For private-sector organizations, it’s voluntary guidance, not law, though many of these organizations’ insurers, customers, and contracting government agencies expect them to comply with the framework. Whether that same government mandate will carry over to the Essentials series hasn’t yet been confirmed.&nbsp;But if you focus only on the timetable, you risk missing the bigger story: What’s different between a checklist and a continuous state of proof?ASD is moving toward a cybersecurity model built around outcomes and intent that goes well beyond simply swapping eight controls for a new checklist. The new Essentials series is structured as chapters, beginning with one on enterprise IT, which folds i

  • Tenable Ranks #1 in Device Vulnerability and Exposure Management for Eighth Consecutive Year
    Sep 10, 2026Tenable News Feed

    Tenable® Holdings, Inc. (NASDAQ: TENB), the exposure management company, today announced that it has been ranked first in worldwide market share in the IDC Worldwide Device Vulnerability and Exposure Management Market Shares report (doc #US53903826, August 2026).Exposure management is a fundamental and necessary shift in how businesses perceive and reduce risk in the AI era. Defenders have reached a crossroads: the volume of critical and complex threats has increased exponentially, and they have increasingly less time to assess and respond before AI-enabled attackers strike. The Tenable One Exposure Management Platform was purpose-built to address this challenge, helping customers better understand cyber risk, prioritize action and defend against evolving cyberattacks.According to the IDC Market Shares report, “Tenable held its ground as the clear market leader, retaining 24.6% share in the worldwide device vulnerability and exposure management market, which is nearly $260 million ahead of its nearest competitor.”Tenable credits its market share position to its ongoing platform advancements designed to unify visibility, deliver precise contextualized exposure intelligence, and accelerate and automate action across the enterprise. In recent months, Tenable introduced autonomous, always-on capabilities in Tenable Hexa AI, the agentic AI engine of Tenable One, expanded Tenable One AI Exposure capabilities to cover all major AI platforms and developer tools, expanded coverage into application security environments and extended its platform’s continuous security control and validation capabilities.&nbsp;Tenable is committed to actively shaping the future of AI-driven exposure management through continued platform innovation and strategic work with OpenAI and Anthropic. In addition to participating in both the OpenAI Daybreak Defense Network and Anthropic’s Project Glasswing, Tenable recently announced the availability of Claude Mythos 5 within Tenable One, helping customers better understand cyber risk, prioritize action and defend against evolving cyberattacks.&nbsp;"We believe our eight consecutive years of market share leadership reflect our commitment to delivering the continuous innovation that sets the standard for exposure management," said Mark Thurmond, co-chief executive officer, Tenable. "We’re empowering customers to transform their organization’s defense for the AI era by equipping them with the comprehensive visibility, advanced analytics and AI technology required to outpace today’s adversaries.”“It can’t be overstated: exposure management is foundational and thus necessary to understand, validate and prioritize exposures before they can be exploited by AI-enabled attackers,” said Michelle Abraham, VP of Research, Security and Trust, IDC. “Boards, insurers and regulators are pushing security teams from conversations about the number of vulnerabilities to how much risk remains. Organizations that embrace exposure management principles can reduce risk, improve remediation efficiency, and demonstrate measurable progress to stakeholders.”More information about the Tenable One Exposure Management Platform is available at: https://www.tenable.com/products/tenable-one&nbsp;&nbsp;About TenableTenable® is the expos

  • The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails
    Sep 10, 2026Tenable Blog

    Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environmentKey takeawaysAI models can quickly understand data, but not your business. While modern AI models are great at reasoning, they don’t automatically understand your unique environment or who is allowed to do what. The “harness” is the custom-built layer that translates AI intelligence into safe, controlled actions specific to your organization.AI requires a supervisor. Tenable treats our AI agents like untrusted insiders. Instead of relying on the AI to police itself, the harness strictly limits what the AI can see and do, and ensures a human reviews and approves any changes before they happen in your environment.Trust requires proof. The harness ensures that every action AI proposes or takes is fully recorded, giving you an audit trail to confidently hand off real work to AI without losing control.Every security vendor has an AI agent. The demos are good. They are supposed to be good, because a demo runs against data that nobody minds breaking.The questions worth asking a vendor about their AI agents are the ones that come after the demo:&nbsp;What happens when the agent is wrong?&nbsp;What happens when someone feeds the agent a prompt designed to manipulate it?&nbsp;If the agent changes something in our environment, what evidence exists afterward about what it did and who authorized its action?When developing Tenable Hexa AI, the agentic AI engine of the Tenable One Exposure Management Platform, we tackled a difficult and critical problem that often gets overlooked: building the underlying infrastructure, the governance layer that safely turns the AI's decisions into actual changes without putting your production data at risk.We call this layer the harness: the runtime control environment in which the model operates. The harness decides:&nbsp;What context the model can seeWhich tools it can callWhat has to be validated before an action executesWhen a human has to approve an actionWhat gets recorded afterwardThe model reasons. The harness holds the boundary.The model is the part you can subscribe to. The harness is the part that has to be built, and it represents most of the work of building an agentic AI capability.&nbsp;This blog presents what we learned building an agentic harness for Tenable Hexa AI.Agentic AI: What goes wrong without a harnessAbstract warnings about AI risk are easy to write and easy to ignore. Here is what actually went wrong during our own development phase. The failures were more mundane, and more instructive, than the ones people theorize about.The AI agent acted past its authority. Asking an agent to “clean up my criticals” is too ambiguous. Critical severity findings and critically rated assets are different objects, and “clean up” could mean remediate, accept the risk, or delete outright. A capable model will pick one and plan bulk changes across assets the requester cannot see, let alone modify. The model has no concept of who is asking. It does not know your entitlement model, and it will not infer one.The model was confidently wrong about the customer’s own environment. The model told users that tags did not exist when, in fact, they did. It missed asset searches by IP address. It used the wrong tag format, using underscore where the platform expects a colon, and then it reported the failure as an absence of data. A model that has read the entire internet still has not read your

  • Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI
    Sep 9, 2026Tenable Blog

    Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to the CyberAgents Exchange.Securing AI agents requires analyzing a broad attack surface that includes LLM instructions, tool-chaining permissions, and prompt injection risks, going far beyond traditional software security.The CyberAgents Exchange inspection process dynamically matches the appropriate AI model tier to each submission’s risk level, ensuring comprehensive vetting without excessive computational overhead.Recently at OpenAI's “Intelligence at Work: Cyber Summit,” Tenable and OpenAI announced a groundbreaking review process to vet the security of open-source AI agents, skills, MCP servers, and multi-agent playbooks, building on our June partnership. The new CyberAgents Exchange AI Inspector, which is built into our CyberAgents Exchange registry, will help security teams adopt agentic AI quickly and confidently.Powered by Tenable, the CyberAgents Exchange is a purpose-built, cybersecurity-native registry for AI agents, skills, MCP servers, and multi-agent playbooks. Launched in August as an open source and vendor-agnostic registry, the CyberAgents Exchange has already grown to host more than 100 AI listings, including a wave of contributions created at Tenable’s SWARM build event at Black Hat USA.From the CyberAgents Exchange’s inception, we understood the importance of a rigorous, comprehensive review process for agents submitted by contributors. Every submission to the CyberAgents Exchange gets a baseline review prior to being listed.&nbsp;Now, we are further strengthening the CyberAgents Exchange review capabilities by giving select high-risk submissions deeper scrutiny with the CyberAgents Exchange AI Inspector, which pairs OpenAI GPT Cyber models with Tenable's own security expertise. The CyberAgents Exchange AI Inspector, or Exchange Inspector for short, is expected to be available in September.Read on for a detailed overview of how we designed the Exchange Inspector and how it works.Review objectivesCyberAgents Exchange submissions come in many shapes and sizes. A submission may contain a single skill markdown file with instructions for an LLM. A more complex submission may contain full agents, MCP servers, external libraries, and may interact with remote services and APIs. This range of complexity is part of what makes reviewing AI agent submissions different from reviewing conventional software.In traditional software security, the attack surface is largely the code itself. In an AI agent, the attack surface extends to the instructions given to the model, the tools it is authorized to invoke, and the data it is permitted to access or transmit. Prompt injection is also a concern, and tool chaining can amplify risk across trust boundaries that no single component would cross on its own. We account for this in our approach to each review.Each submission points to a code repository containing source code files and commits (saved snapshots) that form the project's full history. Since a Git repository is a living codebase, Exchange Inspector reviews are anchored to a specific commit, ensuring fi

  • Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
    Sep 8, 2026Tenable Blog

    104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain ServicesActive Directory Federation Services (AD FS)Audio Video Control Transport ProtocolAzure ArcAzure CycleCloudAzure HDInsightsBranchCacheConnected Devices Platform Service (Cdpsvc)Data Sharing Service ClientGitHub Copilot and Visual Studio CodeGraphic FontsHID class driverIP HelperInternet Storage Name ServiceKernel Streaming WOW Thunk Service DriverMicrosoft AccountMicrosoft AuthenticatorMicrosoft Azure Attestation service and Device Health Attestation ServiceMicrosoft Azure CLIMicrosoft COM for WindowsMicrosoft Dynamics 365Microsoft Exchange ServerMicrosoft Graphics ComponentMicrosoft Install ServiceMicrosoft JScriptMicrosoft Local Security Authority Server (lsasrv)Microsoft OfficeMicrosoft Office AccessMicrosoft Office ExcelMicrosoft Office OutlookMicrosoft Office PowerPointMicrosoft Office PublisherMicrosoft Office SharePointMicrosoft Office WordMicrosoft Standard XPSMicrosoft Teams for AndroidMicrosoft Trace Data HelperMicrosoft UxTheme Library (uxtheme.dll)Microsoft WDAC OLE DB provider for SQLMicrosoft WebP Image ExtensionMicrosoft Windows Codecs LibraryMicrosoft Windows Media FoundationMicrosoft Windows PDFMicrosoft Windows SCSI Class System FileMicrosoft Windows Search ComponentMicrosoft Windows SpeechOpenSSH for WindowsPower AutomatePush Message Routing ServiceRPC RuntimeReliable Multicast Transport Driver (RMCAST)Remote Desktop ClientRemote Desktop Gateway ServiceRole: DNS ServerRole: Windows Fax ServiceSQL ServerSkype for BusinessSpring Cloud AzureStorage Port DriverTelnet ClientVirtual Hard Disk (VHD) Miniport DriverVisual StudioVisual Studio CodeVolume Manager DriverWindows AF_UNIX Socket ProviderWindows ALPCWindows Accounts ControlWindows Ancillary Function Driver for WinSockWindows Audio ServiceWindows Authentication MethodsWindows AutopilotWindows Bind Filter DriverWindows Biometric ServiceWindows BitLockerWindows Bluetooth Port DriverWindows Bluetooth ServiceWindows Boot ManagerWindows Broadcast DVR User ServiceWindows Broker Infrastructure ServiceWindows CD-ROM DriverWindows Camera Frame Server MonitorWindows Cloud Files Mini Filter DriverWindows

  • Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
    Sep 8, 2026Tenable Blog

    Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.Key takeawaysClaude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for research and evaluation, Tenable will now incorporate it within Tenable One, giving defenders access to frontier cyber reasoning to tackle complex exposure management challenges.&nbsp;Tenable One Adversary View is the first innovation we’ll deliver to our customers. Adversary View will use Claude Mythos 5 to help security teams uncover hidden vulnerability chains, see their environments from an attacker’s perspective, and identify the actions that can disrupt attacker progression.Adversary View is just the beginning. Combining Claude Mythos 5’s advanced cyber reasoning with the breadth and depth of Tenable One sets up a new generation of AI-powered capabilities across exposure management.Bringing Claude Mythos 5 into Tenable OneSecurity teams face more findings than they can possibly triage using conventional methods. Add cloud, operational technology (OT), shadow AI, and identity data to the attack surface, and the volume of signals keeps growing while the time to act keeps shrinking.Finding exposures is no longer the hardest part. The challenge is understanding which combinations of exposures create the greatest risk, how an attacker could exploit them, and what to fix first.While leveraging frontier models for improving security defenses is still relatively new, bringing those models into customer-facing products is at the leading edge. Today, we are sharing how Tenable is combining Claude Mythos 5 with the exposure intelligence in Tenable One. Mythos 5 provides frontier-scale adversarial reasoning, while Tenable’s agentic harness provides the context and controls to turn that reasoning into secure, controlled action.This expands on our work with Anthropic through Project Glasswing, which has focused on using Claude Mythos Preview for internal defensive research and evaluation. Claude Mythos 5 is now moving into the Tenable One Exposure Management Platform. The first innovation we’re planning to deliver to our customers will be Tenable One Adversary View, with additional capabilities planned.You already have the evidence. You just can’t always see the path.A netstat entry. A cached account. A line buried in plugin output that no product has ever read. Individually, each may look unremarkable, and none of them are findings. No rule was written for them. No severity was assigned. Nothing flagged them, because nothing was looking.Claude Mythos 5 reasons across exactly that kind of evidence: the scattered, low-signal detail that no single rule was ever written to catch. Rather than checking findings one at a time, it considers the broader environment as a whole.Introducing Tenable One Adversary View powered by Mythos 5Attackers don’t work from a findings list. They read the environment and reason about what's possible. Adversary View does the same thing. It reads the raw detail Tenable scanners already collect but that no rules engine could ever consume — active connections, service enumeration, ins

  • Tenable to Bring Claude Mythos 5 into the Tenable One Exposure Management Platform
    Sep 8, 2026Tenable News Feed

    Tenable® Holdings, Inc. (NASDAQ: TENB), the exposure management company, today announced it is bringing Anthropic’s Claude Mythos 5 directly into the Tenable One Exposure Management Platform. As adversaries use AI to move faster and operate at greater scale, defenders need equally advanced capabilities to stay ahead. This integration between Tenable and Mythos 5 will bring frontier cyber reasoning into Tenable One, enabling a new generation of AI-powered capabilities across exposure management.This step marks an expansion of Tenable’s existing work with Anthropic through Project Glasswing, moving from securing Tenable code and infrastructure to the availability of Claude Mythos 5 within Tenable One. The first innovation planned in this expanded work will be Tenable One Adversary View, a new capability that uses Claude Mythos 5 to help security teams discover hidden attack paths and how to best remediate them. Adversary View is expected to be available to initial customers in September, with additional innovations planned for Q4 and beyond.Security teams already have enormous amounts of information about their environments. The challenge is identifying how seemingly unrelated exposures combine to create a dangerous attack path. Teams must then determine which paths present the greatest risk and find the most effective way to break the chain. Claude Mythos 5 brings advanced cyber reasoning to these problems at the speed and scale these environments demand.“Bringing Claude Mythos 5 into Tenable One marks an important milestone for Tenable and our customers,” said Eric Doerr, chief product officer at Tenable. “By combining some of the world’s most advanced cyber reasoning with the breadth and depth of Tenable’s exposure intelligence, we can tackle complex security problems in entirely new ways. Adversary View is the first planned innovation to emerge from this work, helping customers see their environments as an attacker would and identify the actions that can reduce risk most effectively. And it is just the beginning.”Adversary View will complement Tenable One’s existing exposure prioritization and attack path analysis. It analyzes exposure data Tenable already collects to reconstruct how an attacker could move from an initial point of access toward critical systems. It then shows the evidence behind each step and provides guidance on the specific remediation that could break the path.&nbsp;About TenableTenable® is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company’s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for over 40,000 customers around the globe. Learn more at tenable.com.&nbsp;###&nbsp;Media Contact:Tenabletenablepr@tenable.com&nbsp;Forward-Looking StatementsThis press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including, without limitation, statements regarding: Tenable’s work with Anthropic; the anticipated capabilities, performance, and commercial availability of Claude

  • StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day
    Sep 8, 2026Tenable Blog

    A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different attack campaigns.Adobe released Hotfix VULN-39341 on September 7, 2026, and Tenable detection plugins will be published as they become available.BackgroundTenable's Research Special Operations Team (RSO) has compiled this blog to answer Frequently Asked Questions (FAQ) regarding CVE-2026-75650, a zero-day remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that has been actively exploited in the wild.FAQWhen was CVE-2026-75650 first disclosed?On September 5, 2026, the Sansec Forensics Team published research detailing an actively exploited zero-day vulnerability in Magento and Adobe Commerce that it named StyleSmuggler.What is CVE-2026-75650?CVE-2026-75650 is a remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Successful exploitation grants an unauthenticated attacker the ability to execute arbitrary code on a vulnerable server. CVE-2026-75650 carries a CVSSv3 score of 10.0, the highest possible rating. Additionally, its scope is changed, meaning exploitation can impact resources beyond the vulnerable component itself.CVEDescriptionCVSSv3CVE-2026-75650Adobe Commerce and Magento Open Source Remote Code Execution10.0&nbsp;The following products and versions are affected:ProductAffected versionsAdobe Commerce2.4.4 through 2.4.9Adobe Commerce B2B1.3.3 through 1.5.3Magento Open Source2.4.6 through 2.4.9&nbsp;How does StyleSmuggler work?StyleSmuggler exploits a flaw in how Magento's template engine processes style-related properties. An attacker crafts a malicious payload containing PHP code and injects it through the styles properties within the template system. Magento writes this attacker-controlled content to disk as part of its normal operations. The injected code is then executed when the platform renders a transactional email template, specifically the “Payment Transaction Failed Reminder” notification. Because this injection path does not sit behind any authentication gate, a remote attacker can trigger it without credentials, and the technique works regardless of which session storage backend is configured.Once a server is compromised, the attacker deploys a persistent implant. The malware binary is installed at ~/.local/share/.gvfsd/gvfsd-user and masquerades as a Linux kernel thread using the process name [kworker/u:8:0]. It also disguises itself using the process names fc-cache and chronyd, both legitimate system utilities. A cron job restarts the implant

  • Tenable Uses OpenAI GPT Cyber Models to Help Defenders Inspect Community-Built AI Components
    Sep 3, 2026Tenable News Feed

    Tenable® Holdings, Inc. (NASDAQ: TENB), the exposure management company, today announced that it is collaborating with OpenAI to create the CyberAgents Exchange AI Inspector (Exchange Inspector), a new security review process for AI agents, skills, MCP servers and multi-agent playbooks available through the CyberAgents Exchange, powered by Tenable.Unveiled today at OpenAI’s Intelligence at Work: Cyber Summit, Exchange Inspector combines frontier assessment using OpenAI GPT cyber models, skills inspection powered by Tenable One AI Exposure and expert review from Tenable researchers, helping to enable security teams to safely accelerate enterprise adoption of agentic AI. The collaboration grew from Tenable’s participation in the OpenAI Daybreak Defense Network. Exchange Inspector is expected to be available in September.Launched in August 2026, the CyberAgents Exchange is an open-source, cybersecurity-native registry for AI agents, skills, MCP servers and multi-agent playbooks in the current market. Following its recent SWARM build event, hosted by Tenable at Black Hat USA, the Exchange now includes more than 100 community-submitted AI components.&nbsp;“Agentic AI will only reach its potential in the enterprise if security teams can trust the components being introduced into their environments,” said Eric Doerr, chief product officer at Tenable. “By combining OpenAI GPT cyber models with Tenable’s security expertise and researcher review, we’re building a more rigorous way to inspect community-built AI components before they’re used in enterprise environments. This is an important step in applying frontier AI to help defenders identify and prioritize risk across the growing agent ecosystem.”The Intelligence at Work: Cyber Summit event convened top cybersecurity leaders to discuss how frontier AI can help defenders move faster, strengthen enterprise resilience and turn threat findings into actionable fixes at enterprise scale. Hosted by OpenAI, the event highlighted defensive security applications being developed with cybersecurity companies, including ways to bring advanced cyber reasoning into the platforms and workflows defenders already use.For more information and to contribute to the CyberAgents Exchange, please visit: exchange.tenable.comAbout TenableTenable® is the exposure management company, exposing and closing the cybersecurity gaps that erode business value, reputation and trust. The company’s AI-powered exposure management platform radically unifies security visibility, insight and action across the attack surface, equipping modern organizations to protect against attacks from IT infrastructure to cloud environments to critical infrastructure and everywhere in between. By protecting enterprises from security exposure, Tenable reduces business risk for over 40,000 customers around the globe. Learn more at tenable.com.&nbsp;###&nbsp;Media Contact:Tenabletenablepr@tenable.comForward-Looking StatementsThis press release contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including, without limitation, statements regarding: Tenable’s partnership with OpenAI; the anticipated capabilities, performance, and commercial availability of OpenAI’s models within the Tenable

  • Overview
  • Financial statements
  • Metrics
  • Quarterly earnings
  • Similar companies
  • History
  • News
  • Insider Transactions