Source: BleepingComputer
Author: Sergiu Gatlan
URL: https://www.bleepingcomputer.com/news/security/bad-tenable-plugin-updates-take-down-nessus-agents-worldwide/
# ONE SENTENCE SUMMARY:
Tenable requires users to manually upgrade Nessus agents to resolve outages caused by buggy plugin updates affecting multiple regions.
# MAIN POINTS:
1. Customers must upgrade or downgrade Nessus agents to restore online functionality.
2. Versions affected include Nessus Agent 10.8.0 and 10.8.1 globally.
3. Tenable released version 10.8.2 to fix the plugin issue that caused outages.
4. Plugin feed updates were disabled to prevent further system disruptions.
5. A plugin reset is necessary if using agent profiles for changes.
6. Manual installation of version 10.8.2 is required for affected users.
7. A script or command is provided for resetting plugins before upgrading.
8. The incident is reminiscent of a 2024 CrowdStrike outage impacting many organizations.
9. Users in the Americas, Europe, and Asia experienced the service interruption.
10. Tenable plans to resume plugin downloads by the day’s end.
# TAKEAWAYS:
1. Always keep software updated to avoid potential vulnerabilities and outages.
2. Monitor vendor communications for fixes during major cybersecurity incidents.
3. Have a clear rollback plan in place for software updates.
4. Understand the importance of performing required resets after changes.
5. Stay informed about similar incidents to prepare for potential disruptions.