Homepage
Open in app
Sign in
Get started
Tenable TechBlog
Learn how Tenable finds new vulnerabilities and writes the software to help you find them
Research
Engineering
Follow
CVE-2024–8182 : Accidental Discovery of an Unauthenticated DoS
CVE-2024–8182 : Accidental Discovery of an Unauthenticated DoS
While reviewing some LLM related products with the team, we came across FlowiseAI.
Joshua Martinelle
Sep 13
IoT firmware emulation and device fingerprinting challenges
IoT firmware emulation and device fingerprinting challenges
Gathering information on a device could be tricky if you don’t have direct access to exposed services like SNMP, HTTP, FTP, or any other…
Gabriel Compan
Aug 6
Using conflicting objects in Active Directory to gain privileges
Using conflicting objects in Active Directory to gain privileges
Why CNF objects may be more dangerous than you think
Antoine Cauchois
Jul 31
Solidus — Code Review
Solidus — Code Review
As a Research Engineer at Tenable, we have several periods during the year to work on a subject of our choice, as long as it represents an…
Joshua Martinelle
Jun 10
Stealthy Persistence with “Directory Synchronization Accounts” Role in Entra ID
Stealthy Persistence with “Directory Synchronization Accounts” Role in Entra ID
“Directory Synchronization Accounts” Entra role is very powerful while being hidden to admins, making it a perfect stealthy backdoor 🙈
Clément Notin [Tenable]
Jun 3
WordPress : From vulnerability identification to compromising
WordPress : From vulnerability identification to compromising
WordPress Core is the most popular web Content Management System (CMS). This free and open-source CMS written in PHP allows developers to…
Joshua Martinelle
May 29
Another Path to Exploiting CVE-2024-1212 in Progress Kemp LoadMaster
Another Path to Exploiting CVE-2024-1212 in Progress Kemp LoadMaster
Intro
Ben Smith
Apr 2
Stealthy Persistence & PrivEsc in Entra ID by using the Federated Auth Secondary Token-signing Cert.
Stealthy Persistence & PrivEsc in Entra ID by using the Federated Auth Secondary Token-signing Cert.
How attackers can add a 2nd token-signing certificate to an Entra ID federated authentication config for stealthy persistence & privesc 🙈
Clément Notin [Tenable]
Jan 31
Entra Roles Allowing To Abuse Entra ID Federation for Persistence and Privilege Escalation
Entra Roles Allowing To Abuse Entra ID Federation for Persistence and Privilege Escalation
Which Entra ID (ex-Azure AD) roles allow configuring federated authentication, thus allowing persistence and privilege escalation 💥
Clément Notin [Tenable]
Jan 9
WordPress MyCalendar Plugin — Unauthenticated SQL Injection(CVE-2023–6360)
WordPress MyCalendar Plugin — Unauthenticated SQL Injection(CVE-2023–6360)
WordPress Core is the most popular web Content Management System (CMS). This free and open-source CMS written in PHP allows developers to…
Joshua Martinelle
Jan 2
About Tenable TechBlog
Latest Stories
Archive
About Medium
Terms
Privacy
Teams