Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

Blogs Tenable

June 17, 2025

GerriScary: Hacking the Supply Chain of Popular Google Products (ChromiumOS, Chromium, Bazel, Dart & More)

Tenable Cloud Research discovered a supply chain compromise vulnerability in Google's Gerrit code-collaboration platform which we dubbed GerriScary. GerriScary allowed unauthorized code submission to at least 18 Google projects including ChromiumOS (CVE-2025-1568), Chromium, Dart and Bazel, which are now remediated. Third-party organizations that use Gerrit may also be at risk from GerriScary.

December 22, 2021

Un asset évalué sur dix est vulnérable à Log4Shell

If not addressed now, it will define computing in 2022....


December 21, 2021

Assess Log4Shell Like an Attacker With Tenable’s Dynamic Detections

Defenders need to pull out all the stops when it comes to Log4Shell. Tenable provides dynamic remote Log4Shell vulnerability detections to incorporate the attacker’s perspective of your organization....


December 17, 2021

CVE-2021-44228, CVE-2021-45046, CVE-2021-4104 : Questions fréquentes sur Log4Shell et les vulnérabilités associées

A list of frequently asked questions related to Log4Shell and associated vulnerabilities....


December 14, 2021

Microsoft’s December 2021 Patch Tuesday Addresses 67 CVEs (CVE-2021-43890)

Microsoft addresses 67 CVEs in its December 2021 Patch Tuesday release, including a zero-day vulnerability that has been exploited in the wild....


December 14, 2021

Log4Shell : 5 mesures que la communauté OT devrait prendre immédiatement

Les environnements de technologie opérationnelle (OT) peuvent également pâtir de la faille Apache Log4j. Here's what you can do today....


December 13, 2021

Faille Apache Log4j : un moment digne de Fukushima pour l'industrie de la cyber sécurité (en anglais)

Organizations around the world will be dealing with the long-tail consequences of this vulnerability, known as Log4Shell, for years to come....


December 12, 2021

Faille Apache Log4j : les applications tierces sous le feu des projecteurs

Even in the most mature organizations, addressing the issue, also known as Log4Shell, requires a complex mix of software development practices, vulnerability management and web application scanning....


December 10, 2021

CVE-2021-44228 : Démonstration de faisabilité (PoF) pour la vulnérabilité d'exécution de code à distance (RCE) Apache Log4j (Log4Shell)

Une vulnérabilité critique dans la célèbre bibliothèque de journalisation Log4j 2, frappe de nombreux servies et applications, dont Minecraft, Steam et Apple iCloud. Attackers have begun actively scanning for and attempting to exploit the flaw....


December 9, 2021

How to Start Up Your Cloud Security

Startups may think they can postpone implementing a cloud security program but should in fact take early action — here’s why, and easy steps for doing so....


Des actualités utiles sur la cyber-sécurité

Saisissez votre adresse e-mail et ne manquez plus aucune alerte ni aucun conseil en matière de sécurité de la part de nos experts Tenable.

Coup d’œil sur l'écosystème des ransomwares

Téléchargez le rapport >