Source: BleepingComputer Author: Sergiu Gatlan URL: https://www.bleepingcomputer.com/news/security/bad-tenable-plugin-updates-take-down-nessus-agents-worldwide/
ONE SENTENCE SUMMARY:
Tenable requires users to manually upgrade Nessus agents to resolve outages caused by buggy plugin updates affecting multiple regions.
MAIN POINTS:
- Customers must upgrade or downgrade Nessus agents to restore online functionality.
- Versions affected include Nessus Agent 10.8.0 and 10.8.1 globally.
- Tenable released version 10.8.2 to fix the plugin issue that caused outages.
- Plugin feed updates were disabled to prevent further system disruptions.
- A plugin reset is necessary if using agent profiles for changes.
- Manual installation of version 10.8.2 is required for affected users.
- A script or command is provided for resetting plugins before upgrading.
- The incident is reminiscent of a 2024 CrowdStrike outage impacting many organizations.
- Users in the Americas, Europe, and Asia experienced the service interruption.
- Tenable plans to resume plugin downloads by the day’s end.
TAKEAWAYS:
- Always keep software updated to avoid potential vulnerabilities and outages.
- Monitor vendor communications for fixes during major cybersecurity incidents.
- Have a clear rollback plan in place for software updates.
- Understand the importance of performing required resets after changes.
- Stay informed about similar incidents to prepare for potential disruptions.