Good morning,
Yesterday (May 25, 2026), the Assura team began receiving reports that various Endpoint Detection and Response (EDR) platforms began quarantining systems running the Tenable Vulnerability Management agent for Windows. Because this is highly unusual, our Security Operations Center (SOC) team conducted a thorough investigation out of an abundance of caution to rule out a supply chain attack on the Tenable agent. To our knowledge, this affected systems running SentinelOne, CrowdStrike, and Microsoft Defender for Endpoint.
Late last night, Tenable confirmed to us that they released a new version of their Windows agent plugin feed with a plugin that behaves like a real exploit to identify vulnerable systems, rather than using another, less direct means. They have confirmed to us that plugin set 202605242249 deactivates the offending plugin. The purpose of plugins is to provide agents with a means to identify device vulnerabilities semi-autonomously, without communicating with the cloud platform. They do this to conserve network bandwidth in customer environments and reduce load on their cloud platform.
If you’re an Assura Managed Detection & Response (MDR) client, and your systems were quarantined due to this issue, they are now all back online. If you are not an Assura MDR client, the most expedient way to get affected systems back online is to mark the incident as a false positive and un-quarantine the systems.
If you are an Assura Vulnerability Management-as-a-Service (VMaaS) client with Tenable agents on your Windows assets, we are temporarily deactivating the offending plugin and expect plugin set 202605242249 to be downloaded during the periodic automatic update cycle. We will reactivate the plugin once Tenable releases a verified fix that does not trigger EDR platforms.
If you are neither an Assura MDR nor a VMaaS client, you can check the plugin feed in an elevated command prompt and issue the command:
"C:\Program Files\Tenable\Nessus Agent\nessuscli.exe" plugins --info
The agents will automatically update the plugin feed based on a schedule set by the Tenable VM platform. However, if you want to force the download of the plugins, issue the following command:
"C:\Program Files\Tenable\Nessus Agent\nessuscli.exe" plugins --reset
Caution: Use these commands at your own risk. Assura disclaims any responsibility for the downstream effects of issuing these commands by non-Assura personnel.
We (along with many others, I’m sure) are pursuing an explanation from Tenable about this, and will provide updates as we receive them.
Sincerely,
Joshua Cole
CTO
Assura, Inc.