Tenable, Inc. - Experts & Thought Leaders

Latest Tenable, Inc. news & announcements

Tenable Launches CyberAgents Exchange For Security AI

Tenable® Holdings, Inc., the exposure management company, launches the CyberAgents Exchange, a new open-source AI exchange created to foster industry collaboration and improve collective cyber defense. The CyberAgents Exchange, powered by Tenable, is the only purpose-built, cybersecurity-native registry for AI agents, skills, MCP servers and multi-agent playbooks in the current market.  Security teams are increasingly turning to AI to scale security operations and manage risk overload, but end up building AI agents in isolation, repeatedly reinventing the wheel. Existing AI exchanges are either general-purpose or vendor-gated, forcing security teams to wade through irrelevant use cases, waste time on duplicate design and build efforts, or accept restrictive vendor lock-in. To improve the cybersecurity industry’s collective defense and outpace AI-generated threats, defenders need a unified, cyber-specific hub to accelerate development and share collective agentic tooling. Peer-supported AI components The CyberAgents Exchange eliminates these development silos and empowers industry collaboration with a truly open, free-to-use exchange. Built for trust and transparency, the Exchange provides code-level visibility into who built each AI component, when it was created and its peer-supported status. This transparency enables members to deploy AI components tailored to their specific organizational needs confidently. Additionally, the Exchange is a career asset for practitioners to build verifiable expertise in an emerging discipline and develop a catalog of peer-supported AI components.  Autonomous security operations "The CyberAgents Exchange fills a major and pressing industry need, especially as cybersecurity remains a growing issue and AI-enabled attacks rise," said Seth Fogie, Director of Security for Baptist Memorial Health Care. "Its core philosophy of working together is what made the threat intelligence community so invaluable. My team has benefited greatly from the Exchange, and we look forward to contributing and collaborating with the wider community." Underscoring the industry’s commitment to collaborative, open-source AI defense, industry pioneers SentinelOne and Recorded Future have joined the initiative as founding members of the CyberAgents Exchange. By contributing their deep expertise in autonomous security operations and threat intelligence, these industry pioneers will help anchor the Exchange as a truly unified, vendor-agnostic ecosystem. As founding members, both organizations will actively contribute secure AI agents, integration frameworks and playbooks to accelerate the community's defense capabilities against rapidly evolving AI-driven threats. Open-source security agents In conjunction with the launch, Tenable is hosting “SWARM: The Cybersecurity Agentic AI Build Event,” a hands-on, multi-day event at Black Hat USA 2026 sponsored by AWS and presented with support from Anthropic. At the event, security practitioners will build open-source security agents, skill files or MCP servers. Winners will be announced on Thursday, August 6, 2026.  More than 50 AI components, released under open-source licenses, are available, including: Navi (Agent): A command-line tool that leverages the Tenable One Vulnerability Management APIs to automate common vulnerability management and cyber exposure workflows. SentinelOne Purple AI (MCP Server): Allows users to access SentinelOne services with any MCP client.  Recorded Future MITRE APT Attack Path Analysis (Skill): Pulls an organization’s Recorded Future threat map, maps an APT group's MITRE ATT&CK techniques and cross-references against live Tenable findings to identify which attack path nodes are actively exploitable.  SOC-Hunter (Skill): Leveraged daily by Tenable’s internal security operations team, SOC-Hunter provides proactive, hypothesis-driven threat hunting using the LOCK pattern across SIEM, EDR, VM, CSPM, CASB and code search. The Hounds Pack (Playbook): A skill-packaged playbook for The Hounds — 18 exposure-management specialists that hunt, tag and calibrate risk.  Outpace modern adversaries “Security is a team sport. We’ve addressed a gaping hole in the ecosystem of AI Agents, built for defenders, by defenders. With the CyberAgents Exchange, we’re creating a collaborative 'town square' where cybersecurity practitioners can build, test, improve and share the best in agentic defense,” said Vlad Korsunsky, Chief Technology Officer, Tenable. “With our deep roots in the open source community and our global ecosystem of customers and partners, Tenable is uniquely positioned to steward this collaborative effort to help scale security teams' capabilities and outpace evolving threats.” "To truly scale defences against autonomous, AI-driven threats, the security community must move past isolated development and vendor-locked silos," said Braden Preston, vice president of product management, SentinelOne. "As a founding member of the CyberAgents Exchange, SentinelOne is proud to champion a transparent, open-source foundation for agentic security. By sharing trusted, autonomous components and collaborative playbooks, we are empowering security teams globally to innovate faster, defend smarter and outpace modern adversaries together." Open-source community "Joining the CyberAgents Exchange as a founding member lets us bring world-class threat intelligence directly into the open-source frameworks security teams are building today," said Jamie Zajac, Chief Product Officer at Recorded Future. "But the promise of AI agents in security depends entirely on whether they can be trusted. Intelligence doesn't just make agents smarter. It makes them traceable, auditable and repeatable. That's the foundation the community needs to build autonomous defense that's not only fast, but reliable." The Tenable CyberAgents Exchange is a free, open-source community with no fees for listing or using agents.

Cohesity Expands Industry's Only Data Security Alliance And Announces New Integrations With Cybersecurity Leaders

Cohesity, a pioneer in data security and management, announced at Catalyst, the company’s three-day virtual summit, expansion and rapid innovation with the Data Security Alliance.  Cohesity added new members to the alliance including Netskope, ServiceNow, and Zscaler. The company delivered new integrations with CrowdStrike, ServiceNow, and announced an updated integration with Tenable. The alliance, announced in November 2022, also includes BigID, Cisco, CyberArk, Mandiant, Okta, Palo Alto Networks, PwC UK, Qualys, Securonix, and Splunk. Data Security Alliance Data Security Alliance offers a unique and comprehensive approach to security The Data Security Alliance offers a unique and comprehensive approach to security. Through this one-of-a-kind alliance, leading cyber security, data security and management, and services vendors partner to seamlessly bridge enterprise IT and security by sharing context and enabling new workflows. This collaboration can help customers detect threats and respond to attacks faster, improve remediation, and advance cyber resilience-all while utilising their existing security and data management investments.  Global research study This type of alliance is in high demand by enterprises globally. In a soon-to-be-released global research study commissioned by Cohesity, with partners BigID and Tenable, 87% of the more than 3,000 IT and security respondents polled believe that in order to help win the war against ransomware, it is important that data security and management and cyber security companies team to provide complete and integrated anti-ransomware solutions.  The following are new Data Security Alliance partners: Netskope: Cohesity and Netskope will provide enhanced data protection to tackle the challenges of double-extortion ransomware attacks. Cohesity’s zero-trust protection of immutable backup data helps ensure data is available for recovery if production data is encrypted. When coupled with instant mass restore, organizations will be able to recover from ransomware attacks in hours versus days. Zero-trust principles Enterprises can reduce the attack surface by applying zero-trust principles to unmanaged networks Netskope's Intelligent Security Service Edge (SSE) platform, with its Zero Trust Engine, provides AI-powered visibility and control of sensitive data across web, SaaS, and private apps. Enterprises can reduce the attack surface by applying zero-trust principles to unmanaged networks and protect all traffic through real-time data and threat protection.  Through this integration, enterprises can thwart data exfiltration by ransomware attacks that can expose customer, employee, and partner data, as well as intellectual property, for extortion purposes. ServiceNow: ServiceNow® Security Operations (SecOps) brings incident data from the Cohesity Data Cloud into a structured response engine that uses intelligent workflows, automation, and a deep connection with IT to prioritise and resolve threats based on the impact they pose to organizations. Zscaler: Data protection is top of mind for customers to protect. Cohesity integration with Zscaler provides customers with industry-pioneering Zero Trust security in the world's most deployed cloud data protection solution. Cohesity will classify backup data and share information about sensitive files with Zscaler. Zscaler's data protection platform not only fortifies cloud-based communication channels but also incorporates functionalities such as automated data discovery powered by AI and machine learning (ML), as well as seamless deployment requiring no manual configuration. These capabilities enable precise enforcement of outbound traffic policies, aligning them effectively with customer data protection guidelines. Furthermore, the integrated workflow optimizes the allocation of security team resources while actively shaping user behavior pertaining to the handling of sensitive data. Author's quote Increasingly sophisticated cyber threats cannot be solved by one vendor alone" “With the addition of new security partners Netskope, ServiceNow, and Zscaler and our growing portfolio of security integrations, we have one of the most robust data security ecosystem in the industry to help fight the threat of attacks,” said Sanjay Poonen, CEO and president, Cohesity. “Today’s increasingly sophisticated cyber threats cannot be solved by one vendor alone. It takes an integrated network of cyber security, data security and management, and services experts to thwart the persistence of bad actors. We’re excited to be fulfilling our vision via new and expanded integrations with our valued partners and look forward to working together to help enterprises win the war against cyber threats.”  New or advanced integrations The following are new or advanced integrations with Data Security Alliance members to increase the speed and efficiency of threat detection. CrowdStrike: Integration with Cohesity provides closed-loop detection and response for attacks directly within the CrowdStrike Falcon platform. Customers obtain enriched visibility in their CrowdStrike Falcon LogScale dashboard–the platform’s modern observability and log management offering–with insights from Cohesity, allowing fast correlation, investigation, and response to incidents in one location. ServiceNow: ServiceNow® Security Operations provides closed-loop detection and response for ransomware attacks via SOAR integration adding to the existing capability to create workflows through their IT service management (ITSM) solution. This allows teams to rapidly access and address threats based on the potential impact to the business. Tenable: Cohesity is pleased to launch a new, re-architected integration with Tenable, that powers our marketplace app CyberScan. The updated Tenable integration provides improved scalability to meet the demands of growing workloads so that snapshots can be scanned rapidly and support demanding SLA and RTO requirements. The improved scalability also improves vulnerability scanning used proactively, as part of cyber resilience best practices. Log management solution With the increasing sophistication of cyberattacks, powerful integrations help defeat the bad guys “CrowdStrike’s modern, scalable observability and log management solution is an ideal complement to Cohesity’s exceptional data management capabilities. Together, we help customers rapidly advance cyber resilience within their organizations,” said Daniel Bernard, chief business officer at CrowdStrike. He adds, “With the increasing sophistication of cyberattacks, powerful integrations help defeat the bad guys and offer customers the most comprehensive and advanced approaches to protecting their people, organizations, and data.” Cohesity’s Data Security Alliance “We welcome the opportunity to innovate with Cohesity to help our customers strengthen their cyber resilience and contribute to the momentum of Cohesity’s Data Security Alliance,” said Ray Komar, vice president of technical alliances, Tenable. “We're excited to support the newly re-architected integration of marketplace app CyberScan powered by Tenable, which provides greater scalability so large workloads can be scanned more efficiently and rapidly. Proactive, rapid vulnerability scanning is a critical part of cyber resilience best practices.” Sophisticated cyberattacks “Improved collaboration between data management and security providers, and tighter integration of their respective services, is critical in meeting the threat of ever more sophisticated cyberattacks such as ransomware,” said Johnny Yu, research manager, Storage and Computing, IDC. “Cohesity has shown strong momentum in adding key security providers to its alliance and making more integrations available to customers to help defend against cybercrime.”

Akto Secures $4.5M In Seed Round To Build The World’s First Plug-N-Play API Security Platform

Over 30 million mobile and web app developers around the world use thousands of APIs every day. These APIs carry sensitive data of users which if leaked can cause irreparable damage to companies. Securing these APIs during the development cycle becomes paramount, especially with the movement towards a more agile and continuous release cycle. To solve this problem, Akto is building a plug-and-play API security platform and is announcing a $4.5M seed funding round led by Accel India with participation from angel investors Akshay Kothari (co-founder and COO of Notion), Renaud Deraison ( co-founder Tenable) and Milin Desai (CEO of Sentry) among others. Plug-n-play API security platform Akto is the world's first plug-n-play API security platform which helps security teams and developers secure their APIs in the development pipeline. Akto deploys in less than a minute to create an inventory of APIs, detects PII data leaks, and misconfiguration, and continuously tests these APIs for business logic flaws like broken authentication and authorization in CI/CD pipeline. Akto is the most lightweight API security platform, requiring zero manual configuration to get started within a minute. It mirrors traffic from customers’ cloud - AWS and GCP and provides instant visibility to security teams which otherwise would have taken months of back and forth with developers. Akto currently discovers more than 100,000 APIs for its customers around the world.  Robust module  Akto is currently securing thousands of APIs of some of the largest fintech and SaaS companies across the globe Ankita Gupta and Ankush Jain co-founded Akto in January 2022 with a mission to develop the fastest API security platform. After having worked together for 2 years, they left their jobs last year and talked to 200+ security engineers across the globe before writing a single line of code. Akto is currently securing thousands of APIs of some of the largest fintech and SaaS companies across the globe. Akto has identified more than 100 leaks with credit card information and found over 1,000 broken authorization issues through its robust testing module. Instant inventory  Ankita Gupta, co-founder, at Akto commented, “We learned that the biggest challenge facing teams seeking API security solutions is that it takes months to try them. We have set out to create a solution that is not only fast to act but super easy to deploy. The plug-and-play element means that our customers can get an instant inventory of APIs within 2 minutes.” API attack traffic has grown 700% in the last year. According to Gartner, by 2022 API abuses will be the most frequent attack vector resulting in data breaches. Last month, Optus, one of the biggest telcos in Australia had a massive data breach because of an unauthenticated API left exposed. If Optus was using Akto, they would have received an alert on this vulnerability and could have prevented this breach.  API security testing  We have built an engine that can process Google-scale traffic with 0 performance impact in real-time" Ankush Jain, co-founder at Akto added, “I've worked for ten years developing big data applications handling billions of data points at Morgan Stanley and CleverTap. Current solutions give high false positives and to solve this problem I strongly believe that API security testing must be context-aware and should discover deep business logic vulnerabilities." "To derive context, we apply AI/ML to analyze all of the application traffic. We have built an engine that can process Google-scale traffic (10B requests/day) with 0 performance impact in real-time.”  AKTO MINI In addition to Akto’s API security platform, Akto has developed a free chrome extension called AKTO MINI to generate a quick inventory of APIs and detect PII data leaks without having to deploy anything. AKTO MINI has already generated interest from security engineers and developers who have generated their API inventory instantly for free.  We have just launched the chrome extension - AKTO MINI and are extending it as a full-fledged open-source project.  CI/CD tool integration Today APIs are pervasive, they are the glue that enables any software to provide rich functionality" The new investment will allow Akto to integrate with all CI/CD tools enabling developers to run checks before deploying APIs, provide comprehensive coverage of business logic tests and improve the platform by building stronger AI/ML capabilities. Our vision is to enable the 30 million developers and security engineers to secure their APIs in less than 60 seconds. Prayank Swaroop, Partner, Accel India commented, “Today APIs are pervasive, they are the glue that enables any software to provide rich functionality. However, till recently not much thought was given to securing APIs." Scalable & accurate API security solution "Securing APIs requires identifying complex patterns of API misuse moreover this has to be done in the DevSecOps pipeline following a Shift-Left approach, without taking a lot of time from engineering teams." "In the current market, all the solutions overwhelm security teams by throwing a lot of false positives. Akto’s approach and tech address all of these problems and provide a reliable, scalable, easy-to-install & accurate API security solution. We are very excited to be a part of their journey.”