Tenable warns users to update now following possible plugin security issue

An abstract image of digital security.
(Image credit: Shutterstock) (Image credit: Shutterstock)

  • Tenable urges users to update their Nessus instances to avoid a potential plugin security issue
  • A previous plugin update saw agents going offline
  • The earliest clean version is 10.8.2, so users should update now

Tenable has urged users to update their Nessus instances to avoid a potential plugin security issue.

Tenable Nessus is a widely used vulnerability scanner that helps identify and assess security vulnerabilities, misconfigurations, and compliance issues in networks, applications, and systems.

However, in the final hours of December 2024, the company said it was “aware of and actively investigating” an issue with Nessus agents going offline after plugin updates for certain users on all sites - and as a result, the company temporarily stopped plugin updates.

Resetting plugins

The incident apparently affected Nessus Agent versions 10.8.0 and 10.8.1, for users in North and Latin America, Europe, and Asia. To address the issue, Tenable released Nessus Agent version 10.8.2.

"There is a known issue which can cause Tenable Nessus Agent 10.8.0 and 10.8.1 to go offline when a differential plugin update is triggered. To prevent such an issue, Tenable has disabled plugin feed updates for these two agent versions. Additionally, Tenable has disabled the 10.8.0 and 10.8.1 versions to prevent further issues," the release notes detailed.

Now, users are called to either upgrade to 10.8.2, or downgrade to 10.7.3 to bring their Nessus agents online. However, they also need to reset their plugins.

“If you are using agent profiles for agent upgrades or downgrades, you must perform a separate plugin reset to recover any offline agents," the company concluded.

To adress the bugs, users first need to reset agent plugins via a script or a nessuscli reset command, and then manually upgrade the Tenable Nessus Agent using the 10.8.2 install package.

Tenable claims to have more 44,000 customers worldwide, including 65% of the Fortune 500. While the exact number of Nessus users isn't publicly disclosed, it is safe to assume that Nessus is quite popular in the cybersecurity community.

Via BleepingComputer

You might also like

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
coding
Popular open source vulnerability scanner Nuclei forced to patch worrying security flaw
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Best free Linux firewalls
SonicWall tells admins to patch worrying SSLVPN flaw immediately
Digital image of a lock.
Ivanti warns it has found another major security flaw in its systems
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Top WordPress plugins found to have some serious security flaws, so make sure you're protected
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
Latest in Security
Woman shocked by online scam, holding her credit card outside
Cybercriminals used vendor backdoor to steal almost $600,000 of Taylor Swift tickets
Woman using iMessage on iPhone
UK government guidelines remove encryption advice following Apple backdoor spat
Cryptocurrencies
Ransomware’s favorite Russian crypto exchange seized by law enforcement
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
HTTPS in a browser address bar
Malicious "polymorphic" Chrome extensions can mimic other tools to trick victims
ransomware avast
Hackers spotted using unsecured webcam to launch cyberattack
Latest in News
MacBook Air mute key
The new M4 MacBook Air finally fixes an Apple keyboard annoyance that's been around for decades
A collage of Ellie and Joel in The Last of Us season 2
The Last of Us season 2's new trailer teases a huge showdown between Bella Ramsey's Ellie and Pedro Pascal's Joel, but the big moment I'm waiting for is still being held back
Apple iPhone 16 Pro Max REVIEW
New iPhone 17 Air leak may have revealed some key specs – and how it compares to the iPhone 17 Pro Max
Gaming with AI
I asked Gemini to play a text-based adventure game with me and the AI whisked me away to a word-based fantasy
Apple iPhone 16 Review
Three iPhone 17 model dummy units appear in a hands-on video leak
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
New Samsung Galaxy S25 Edge may have revealed some key details – including its price