Source: BleepingComputer Author: Sergiu Gatlan URL: https://www.bleepingcomputer.com/news/security/bad-tenable-plugin-updates-take-down-nessus-agents-worldwide/
-
ONE SENTENCE SUMMARY: Tenable requires users to manually upgrade Nessus agents to resolve outages caused by buggy plugin updates affecting multiple regions.
-
MAIN POINTS:
-
Customers must upgrade or downgrade Nessus agents to restore online functionality.
-
Versions affected include Nessus Agent 10.8.0 and 10.8.1 globally.
-
Tenable released version 10.8.2 to fix the plugin issue that caused outages.
-
Plugin feed updates were disabled to prevent further system disruptions.
-
A plugin reset is necessary if using agent profiles for changes.
-
Manual installation of version 10.8.2 is required for affected users.
-
A script or command is provided for resetting plugins before upgrading.
-
The incident is reminiscent of a 2024 CrowdStrike outage impacting many organizations.
-
Users in the Americas, Europe, and Asia experienced the service interruption.
-
Tenable plans to resume plugin downloads by the day’s end.
-
TAKEAWAYS:
-
Always keep software updated to avoid potential vulnerabilities and outages.
-
Monitor vendor communications for fixes during major cybersecurity incidents.
-
Have a clear rollback plan in place for software updates.
-
Understand the importance of performing required resets after changes.
-
Stay informed about similar incidents to prepare for potential disruptions.