appsec.fyi · Sources

tenable.com

5 curated AppSec resources from tenable.com across 3 topics on appsec.fyi.

tenable.com

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-04-11.

Date Added Resource Excerpt
2026-04-11 2026Google Cloud SIEM Service Account Token LeakSecretsGoogle Cloud SIEM Service Account Token Leak
2026-04-10 2026GCP SSRF on Action Hub Extension - TenableSSRFGCP SSRF on Action Hub Extension - Tenable
2026-04-06 2026CVE-2026-29924: XXE VulnerabilityXXECVE-2026-29924: XXE Vulnerability
2025-08-14 2025Critical SSRF vulnerability in Microsoft Copilot StudioSSRFA critical Server-Side Request Forgery (SSRF) vulnerability has been discovered in Microsoft Copilot Studio. This vulnerability poses a significant security risk and could potentially be exploited by attackers. It is crucial for users of Copilot Studio to take immediate action to address this vulnerability to prevent unauthorized access or manipulation of sensitive data.
2024-10-17 2024Exfiltrated, Signed, Delivered – What Can Go Wrong When an Amazon Elastic Compute Cloud (EC2) Instance is Exposed to SSRFSSRFThe content discusses the risks of exposing an Amazon Elastic Compute Cloud (EC2) instance to Server-Side Request Forgery (SSRF). By using CNAPPgoat, users can explore how SSRF can be exploited to make unauthorized calls to AWS services from within an EC2 instance. This highlights the potential security vulnerabilities that can arise when SSRF is not properly mitigated, emphasizing the importance of securing EC2 instances to prevent such attacks.