Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Tenable 博客


Oracle January 2022 Critical Patch Update Addresses 266 CVEs

Oracle addresses 266 CVEs in its first quarterly update of 2022 with 497 patches, including 25 critical updates. Background On January 18, Oracle released its Critical Patch Update (CPU) for Januar...
Satnam Narang Satnam Narang
January 19, 2022

The 2021 Threat Landscape Retrospective: Targeting the Vulnerabilities that Matter Most

A review of the year in vulnerabilities and breaches, with insights to help guide cybersecurity strategy in 2022 and beyond.

Security Response Team
January 19, 2022

CVE-2021-44757: ZoHo Patches Authentication Bypass in ManageEngine Desktop Central

ZoHo patches authentication bypass in ManageEngine Desktop Central that could allow attackers to write arbitrary zip files to the server. Background On January 17, ZoHo issued an advisory and patche...

Claire Tills Claire Tills
January 18, 2022

YouTube Shorts: Stolen TikTok Videos Manipulated in Adult Dating, Dubious Products Scams for Views and Subscribers

As Google's TikTok competitor YouTube Shorts gains viewers, hordes of scammers are quick to follow.

Satnam Narang Satnam Narang
January 12, 2022

Microsoft’s January 2022 Patch Tuesday Addresses 97 CVEs (CVE-2022-21907)

Microsoft addresses 97 CVEs in its January 2022 Patch Tuesday release, including four zero-day vulnerabilities that were publicly disclosed but not exploited in the wild. 9Critical 88Important...

Security Response Team
January 11, 2022

One in 10 Assets Assessed Are Vulnerable to Log4Shell

If not addressed now, it will define computing in 2022.

Amit Yoran Amit Yoran
December 22, 2021

Assess Log4Shell Like an Attacker With Tenable’s Dynamic Detections

Defenders need to pull out all the stops when it comes to Log4Shell. Tenable provides dynamic remote Log4Shell vulnerability detections to incorporate the attacker’s perspective of your organization.

Team Tenable
December 21, 2021

CVE-2021-44228,CVE-2021-45046,CVE-2021-4104: Frequently Asked Questions About Log4Shell and Associated Vulnerabilities

A list of frequently asked questions related to Log4Shell and associated vulnerabilities.

Satnam Narang Satnam Narang
December 17, 2021

Microsoft’s December 2021 Patch Tuesday Addresses 67 CVEs (CVE-2021-43890)

Microsoft addresses 67 CVEs in its December 2021 Patch Tuesday release, including a zero-day vulnerability that has been exploited in the wild.

Security Response Team
December 14, 2021

Log4Shell:OT 社区应立即采取的 5 大步骤

Operational technology (OT) environments are equally at risk from the Apache Log4j flaw. Here's what you can do today.

Marty Edwards Marty Edwards
December 14, 2021

Apache Log4j Flaw: A Fukushima Moment for the Cybersecurity Industry

Organizations around the world will be dealing with the long-tail consequences of this vulnerability, known as Log4Shell, for years to come.

Renaud Deraison Renaud Deraison
December 13, 2021

Apache Log4j 缺陷让第三方软件成为关注焦点

Even in the most mature organizations, addressing the issue, also known as Log4Shell, requires a complex mix of software development practices, vulnerability management and web application scanning.

Robert Huber Robert Huber
December 12, 2021

Apache Log4j 缺陷让第三方软件成为关注焦点

获取详细信息 >


输入您的电子邮件以在收件箱中接收最新的 Cyber Exposure 警报。

Tenable.io 免费试用 30 天

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。 立即注册。

Tenable.io 购买

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。 立即购买年度订阅。

65 项资产



免费试用 Nessus Professional

免费试用 7 天

Nessus® 是当今市场上功能最全面的漏洞扫描器。Nessus Professional 可帮助自动化漏洞扫描流程、节省合规周期的时间,并让您调动起 IT 团队的积极性。

购买 Nessus Professional

Nessus® 是当今市场上功能最全面的漏洞扫描器。Nessus Professional 可帮助自动化漏洞扫描流程、节省合规周期的时间,并让您调动起 IT 团队的积极性。

购买多年期许可,即享优惠价格添加高级支持功能,获取一年 365 天、一天 24 小时的电话、社区和聊天支持。




试用 Tenable.io Web Application Scanning

免费试用 30 天

完整享有专为现代化应用程序而设、属于 Tenable.io 平台组成部分的最新 Web 应用程序扫描功能。可安全扫描全部在线资产组合的漏洞,具有高度准确性,而且无需繁重的手动操作或中断关键的 Web 应用程序。 立即注册。

购买 Tenable.io Web Application Scanning

可全面访问基于云的现代化漏洞管理平台,从而以无可比拟的精确度发现并追踪所有资产。 立即购买年度订阅。

5 个 FQDN



试用 Tenable.io Container Security

免费试用 30 天

完整获得已集成至漏洞管理平台之唯一容器安全产品的功能。监控容器映像中的漏洞、恶意软件和策略违规。与持续集成和持续部署 (CI/CD) 系统进行整合,以支持 DevOps 实践、增强安全性并支持企业政策合规。

购买 Tenable.io Container Security

Tenable.io Container Security 经由与构建流程的集成,可供全面了解容器映像的安全性,包括漏洞、恶意软件和策略违规,借以无缝且安全地启用 DevOps 流程。

试用 Tenable Lumin

免费试用 30 天

通过 Tenable Lumin 直观呈现及探索 Cyber Exposure,长期追踪风险降低状况,并比照同行业者进行基准度量。

购买 Tenable Lumin

联系销售代表,了解 Lumin 如何帮助获取整个企业的洞见并管理网络安全风险。