Aggregator
Please support the site operations by clicking ads.
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.
Key takeaways- Claude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for research and evaluation, Tenable will now incorporate it within Tenable One, giving defenders access to frontier cyber reasoning to tackle complex exposure management challenges.
- Tenable One Adversary View is the first innovation we’ll deliver to our customers. Adversary View will use Claude Mythos 5 to help security teams uncover hidden vulnerability chains, see their environments from an attacker’s perspective, and identify the actions that can disrupt attacker progression.
- Adversary View is just the beginning. Combining Claude Mythos 5’s advanced cyber reasoning with the breadth and depth of Tenable One sets up a new generation of AI-powered capabilities across exposure management.
Security teams face more findings than they can possibly triage using conventional methods. Add cloud, operational technology (OT), shadow AI, and identity data to the attack surface, and the volume of signals keeps growing while the time to act keeps shrinking.
Finding exposures is no longer the hardest part. The challenge is understanding which combinations of exposures create the greatest risk, how an attacker could exploit them, and what to fix first.
While leveraging frontier models for improving security defenses is still relatively new, bringing those models into customer-facing products is at the leading edge. Today, we are sharing how Tenable is combining Claude Mythos 5 with the exposure intelligence in Tenable One. Mythos 5 provides frontier-scale adversarial reasoning, while Tenable’s agentic harness provides the context and controls to turn that reasoning into secure, controlled action.
This expands on our work with Anthropic through Project Glasswing, which has focused on using Claude Mythos Preview for internal defensive research and evaluation. Claude Mythos 5 is now moving into the Tenable One Exposure Management Platform. The first innovation we’re planning to deliver to our customers will be Tenable One Adversary View, with additional capabilities planned.
You already have the evidence. You just can’t always see the path.A netstat entry. A cached account. A line buried in plugin output that no product has ever read. Individually, each may look unremarkable, and none of them are findings. No rule was written for them. No severity was assigned. Nothing flagged them, because nothing was looking.
Claude Mythos 5 reasons across exactly that kind of evidence: the scattered, low-signal detail that no single rule was ever written to catch. Rather than checking findings one at a time, it considers the broader environment as a whole.
Attackers don’t work from a findings list. They read the environment and reason about what's possible. Adversary View does the same thing. It reads the raw detail Tenable scanners already collect but that no rules engine could ever consume — active connections, service enumeration, installed software, configuration output — and reasons its way to the vulnerability chains that are actually viable in your environment. Not the patterns we anticipated and encoded, but the ones nobody thought to look for.
Adversary View applies Claude Mythos 5 reasoning to your Tenable scan data to surface the defensive actions that disrupt those vulnerability chains fastest. We’ll share more on availability in the coming weeks.
Scattered signals become a short list of decisive actionYou won’t need to work directly with Claude Mythos 5 to get a result. It starts with a conversation in Tenable One.
Step 1: Confirm your scope. You identify the assets you want examined, and Adversary View walks you through confirming that scope so the results are worth acting on.
Step 2: The harness delivers and validates the context. The Tenable harness pulls together the evidence, plugin output, critical and high severity vulnerabilities, recently discovered findings, live connections between hosts, and lower-confidence signals that never rose to a finding on their own, and validates them before Claude Mythos 5 reasons across them. This is all data that Tenable already collects. Nothing new to deploy.
Set 3: Act on a ranked list of actions. What comes back isn't more findings. It's a ranked set of the vulnerability chains that actually matter, each with the evidence behind it and the fix that breaks it. You can act on those recommendations in Tenable Hexa AI.
The bottom lineBringing Claude Mythos 5 into Tenable One is more than providing access to another model. It combines frontier-scale adversarial reasoning with the exposure intelligence Tenable has built over decades.
The result is your ability to find connections that were previously difficult to see, understand which vulnerability chains matter most, and take action faster.
Tenable One Adversary View is the first capability built from this work. More will follow.
Forward-Looking Statements
This blog post contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including, without limitation, statements regarding: Tenable’s work with Anthropic; the anticipated capabilities, performance, and commercial availability of Claude Mythos 5 within the Tenable One Exposure Management Platform; the planned launch and timing of Tenable One Adversary View; the integration of frontier AI models with the Tenable Exposure Data Fabric; and Tenable’s overall AI product strategy and roadmap. These statements involve risks and uncertainties that could cause actual results to differ materially, including, among others: risks related to the development, deployment, accuracy, and customer adoption of emerging and unproven artificial intelligence technologies; technical and operational challenges in integrating third-party AI models into commercial software; the risk of delays in product development or commercial rollout schedules; intense competition in the cybersecurity market; and other factors detailed under the caption 'Risk Factors' in Tenable's most recent Annual Report on Form 10-K and subsequent filings with the Securities and Exchange Commission. Tenable undertakes no obligation, and expressly disclaims any duty, to update or revise these forward-looking statements to reflect events or circumstances arising after the date hereof, except as required by law.
FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA portal and the backend destination website. Tracked as CVE-2026-84393 and documented under advisory FG-IR-26-174, the issue was published on September 8, 2026, and carries a […]
The post FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack appeared first on Cyber Security News.
Не берёте трубку с незнакомых номеров? Не важно! Ваш телефон всё равно взломают
Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) that turns compromised perimeter devices into long-term footholds for espionage and data theft. The SOCRadar Threat Research Unit (STRU) has identified, with high confidence, that threat actors are actively exploiting CVE-2025-25249, a […]
The post Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware appeared first on Cyber Security News.
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
CVE-2026-18744 | CERT/CC VINCE up to 3.0.43 test_func member authorization
CVE-2026-18749 | CERT/CC VINCE up to 3.0.43 Attachment Authorization t_attach.case _is_my_case authorization
CVE-2026-18750 | CERT/CC VINCE up to 3.0.43 Email Notification vinny/views.py ModifyEmailNotifications authorization
CVE-2026-1199 | Zabbix up to 6.0.46/7.0.27/7.4.11 Login Lockout Mechanism improper authentication
CVE-2026-23922 | Zabbix up to 7.4.8 Email Media OAuth Token endpoint information disclosure
CVE-2026-23930 | Zabbix up to 6.0.46/7.0.26/7.4.10 Frontend resource consumption (Nessus ID 338048)
CVE-2026-23929 | Zabbix up to 6.0.45/7.0.24/7.4.8 Maps searchParamsToObject prototype pollution
CVE-2026-76647 | Leantime up to 3.9.0 Dispatcher Jsonrpc.php editOwn authorization
CVE-2026-75501 | Calix EXOS up to 6.6.47 UPnP WANIPConnection service missing authentication
CVE-2026-19874 | Konami Metal Gear Online 3 1.1.2.8 Lobby Data Processing kick_num/kicked_id_%i heap-based overflow
Linux 7.3 неожиданно раздулся, Торвальдс предложил винить ИИ
OpenAI says ChatGPT outage causes image generation errors
CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks. CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used by Chromium-based browsers. The vulnerability stems from type confusion, classified under CWE-843, a weakness that […]
The post CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.