惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threat Research - Cisco Blogs
量子位
L
LINUX DO - 热门话题
Jina AI
Jina AI
J
Java Code Geeks
U
Unit 42
V
Vulnerabilities – Threatpost
The Hacker News
The Hacker News
Blog — PlanetScale
Blog — PlanetScale
博客园 - 聂微东
WordPress大学
WordPress大学
D
Docker
T
The Exploit Database - CXSecurity.com
博客园 - Franky
Project Zero
Project Zero
F
Full Disclosure
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
NISL@THU
NISL@THU
D
Darknet – Hacking Tools, Hacker News & Cyber Security
MongoDB | Blog
MongoDB | Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
Simon Willison's Weblog
Simon Willison's Weblog
月光博客
月光博客
V
Visual Studio Blog
腾讯CDC
The Cloudflare Blog
V
V2EX
C
Cybersecurity and Infrastructure Security Agency CISA
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Security Latest
Security Latest
博客园 - 三生石上(FineUI控件)
Know Your Adversary
Know Your Adversary
I
Intezer
S
Securelist
A
Arctic Wolf
小众软件
小众软件
P
Privacy International News Feed
Spread Privacy
Spread Privacy
The GitHub Blog
The GitHub Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Cyberwarzone
Cyberwarzone
T
Tailwind CSS Blog
Latest news
Latest news
H
Help Net Security
S
Schneier on Security
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
P
Proofpoint News Feed
Scott Helme
Scott Helme
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org

Tenable Blog

wp2shell: WordPress Core Pre-Auth RCE FAQ | Tenable® SharePoint CVEs FAQ: CVE-2026-56164, CVE-2026-32201, CVE-2026-45659 | Tenable® Build agentic AI security at Tenable Swarm, Black Hat 2026 SonicWall CVE-2026-15409 and CVE-2026-15410 zero-day exploited | Tenable® Understanding Anthropic’s new AI agent Claude Tag’s access model in Slack 5 reasons to integrate AppSec data with your exposure management platform July 2026 Patch Tuesday: Largest Patch Tuesday 569 CVEs OMB M-26-14: Why federal agencies must fix asset visibility first CISO’s guide to CISA BOD 26-04 and risk-based security metrics for vulnerability management How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it. The Developer Credential Economy: An inside look at the Miasma worm campaign Oracle Critical Security Patch Update June 2026 | Tenable® How Tenable helps federal agencies comply with CISA BOD 26-04 Get critical cyber risk context: Understanding control validation, CTEM & Tenable One CISA BOD 26-04: Frequently asked questions about the new risk-based patching directive Microsoft’s June 2026 Patch Tuesday Addresses 198 CVEs ( CVE-2026-49160, CVE-2026-50507) The June 2026 AI Executive Order: What federal agencies need to know and how Tenable can help Tenable joins Anthropic’s Project Glasswing to advance AI-era cyber defense Tenable CTO Vlad Korsunsky Q&A: Countering AI threat multipliers with AI-powered exposure management | Tenable CTO Q&A: C-suite views AI as massive threat, as cyber teams adopt exposure management to counter AI attacks Oracle May 2026 Critical Security Patch Update Addresses 35 CVEs Download pumping: New npm deception technique for supply chain attacks Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect EXPOSURE 2026 prepares cybersecurity professionals for the AI era Mini Shai-Hulud: Frequently asked questions about the TeamPCP npm and PyPI supply chain campaign CVE-2026-9082: Highly Critical SQL Injection Vulnerability in Drupal Core (SA-CORE-2026-004) Tenable One deepens third-party integrations with new Open Connector for unified risk visibility Implement agentic AI in cybersecurity with Tenable Hexa AI: Reduce cyber risk at machine speed Key findings from the Verizon DBIR 2026: Slower vulnerability remediation meets faster exploitation Frequently asked questions about the continued exploitation of Cisco Catalyst SD-WAN vulnerabilities (CVE-2026-20182) Bring out your dead: How agentic AI for cybersecurity helps you rid your cloud of forgotten, risky assets Fragnesia (CVE-2026-46300): Frequently asked questions about new Linux Kernel XFRM ESP-in-TCP privilege escalation Securing data centers in the agentic AI era Microsoft’s May 2026 Patch Tuesday Addresses 118 CVEs (CVE-2026-41103) Dirty Frag (CVE-2026-43284, CVE-2026-43500): Frequently asked questions about this Linux kernel privilege escalation vulnerability chain Why the approaching flood of vulnerabilities changes everything — and what to do about it The AI-vs-AI battle is already happening. Watch it live at EXPOSURE 2026. Anthropic’s CEO warns the “moment of danger” is real. But most are looking in the wrong place. Security for AI: A strategic framework for closing the AI exposure gap Vulnerability remediation: Match CVEs to asset owners in seconds with Tenable Hexa AI Bridging the gap: How to integrate Claude Security into the Tenable One Exposure Management Platform Copy Fail (CVE-2026-31431): Frequently asked questions about Linux kernel privilege escalation vulnerability Mastering agentic AI security through exposure management As the NVD scales back CVE enrichment, here’s what Tenable customers need to know Five steps to become Mythos ready Oracle April 2026 Critical Patch Update Addresses 241 CVEs Beating the Mythos clock: Using Tenable Hexa AI custom agents for automated patching Unlocking foundational visibility for cyber-physical systems with OT vulnerability management Claude Mythos: Prepare for your board’s cybersecurity questions about the latest AI model from Anthropic Microsoft’s April 2026 Patch Tuesday Addresses 163 CVEs (CVE-2026-32201) Crushing the Axios supply chain threat with Tenable Hexa AI: Use cases for agentic AI What to Know About CyberAv3ngers: The IRGC-Linked Group Targeting Critical Infrastructure CVE-2026-35616: Fortinet FortiClientEMS improper access control vulnerability exploited in the wild The developer credential economy: Why exposure data is the new front line in the supply chain war Frequently Asked Questions About the Axios npm Supply Chain Attack by North Korea-Nexus Threat Actor UNC1069 Supply chain attack on Axios npm package: Scope, impact, and remediations What’s new in Tenable Cloud Security: Custom policies, AWS ABAC, and research-driven protection Uncover prompt injection, insider threats with the Tenable One Model Refusal Detection Security for AI: A guide to managing the risks of vibe coding and AI in software development Meet Tenable Hexa AI: Agentic AI for exposure management
FedRAMP High, IL5, and zero trust: How federal agencies can secure cloud environments
Zach Bennefield · 2026-07-13 · via Tenable Blog

Beyond IT compliance, cloud security is now the backbone of civilian agency resilience, national defense, and warfighter safety, as cloud environments become increasingly complex.

Key takeaways

  1. For the Department of War (DoW), cloud security is an IT concern and a requirement for operational readiness and national security.
  2. Achieving a mature zero trust architecture requires deep, real-time visibility across seven critical pillars, including users, data, and workloads.
  3. FedRAMP High and IL5 authorizations provide the rigorous vendor validation that federal agencies need to ensure the protection of their controlled unclassified information (CUI) and the support of their tactical edge deployments.
  4. Tenable One Cloud Exposure, which now has FedRAMP High and IL5 authorizations, delivers a unified cloud native application protection platform (CNAPP) approach within a strictly regulated environment. As part of the Tenable One Exposure Management Platform, it helps teams to visualize and mitigate risk in federal cloud ecosystems without compromising strict data isolation requirements.

The transformation of federal cybersecurity: A new mission frontier

In nearly two decades of working with and within civilian, Department of War (DoW), and intelligence community customers, Tenable has watched the conversation around cloud move through several phases. Early on, the questions were about whether to adopt cloud at all. More recently, the questions have shifted to how to secure what has been deployed, often at a scale and pace that outran the security planning meant to support it. That shift explains why so many federal cloud programs find themselves reactively managing risk rather than by design.

The stakes could not be higher. A misconfigured workload, an overprivileged service account, or a storage bucket quietly exposing sensitive data go beyond compliance findings to be addressed in the next plan of action and milestones (POA&M) cycle. In a federal context, those conditions translate directly into operational risk, potentially leading to compromised citizen data, disrupted public services, and degraded mission readiness. When framing cloud security for customers, we try to position it where it belongs.

For both civilian and defense agencies, cloud security isn’t just an IT concern; it’s mission imperative. 

How the cloud has changed the federal threat landscape

Federal cloud environments are fundamentally different from what they were five years ago. Multi-cloud architectures, containerized workloads, DevSecOps pipelines, and AI-powered applications have created environments of staggering complexity. And complexity is an adversary’s best friend.

Today’s threats don’t announce themselves with an obvious attack on the perimeter. They exploit the gaps between tools, like: 

  • The over-permissioned service account no one is watching 
  • The misconfigured S3 bucket quietly exposing sensitive data 
  • The lateral movement path buried in an identity relationship no human analyst would think to trace 

Siloed security tools, alert fatigue, and a shortage of cloud expertise mean many of these risks go undetected until it’s too late.

Zero trust requires cloud visibility

The federal government has made zero trust the strategic framework for its cyber future. Whether aligning with the Office of Management and Budget (OMB) mandates or the DoW Zero Trust Capability Execution Roadmap, agencies face an ambitious set of capabilities across seven pillars: 

  1. Users
  2. Devices
  3. Applications and workloads
  4. Data 
  5. Network and environment
  6. Automation and orchestration
  7. Visibility and analytics

Together, these pillars define what a mature, trust-nothing architecture looks like. But zero trust is more than a policy; it is a continuous operational discipline. Execution is impossible without deep, real-time visibility into the cloud environment.

Consider what zero trust requires in practice:

  • Identity and least privilege: You cannot enforce least privilege if you do not know who has access to what. This requires continuously discovering all identities (human and non-human, federated, and third-party) and understanding their effective permissions rather than just the permissions granted on paper. Over-provisioned accounts are among the most common and dangerous vulnerabilities in cloud environments, and they compound over time as personnel rotate and missions evolve. This is amplified in cloud environments by human and non-human identities gaining permission sprawl. 
  • Continuous authorization: Static, point-in-time assessments no longer suffice. Federal civilian and defense agencies need the ability to continuously monitor workloads, validate compliance posture, and make real-time access decisions based on current risk rather than last year’s audit. Continuous Authorization to Operate (cATO) is only achievable when you have the telemetry to support it.
  • Data protection: Knowing where sensitive data lives and who can reach it is foundational to any zero trust data strategy. This involves:
    • Identifying personally identifiable information (PII), payment card industry (PCI) data, and protected health information (PHI) across cloud data stores
    • Understanding access patterns
    • Detecting encryption gaps
    • Ensuring that only authorized entities can interact with the most sensitive assets. 
  • Network segmentation: Whether at the macro or micro level, segmenting the network requires understanding what is connected to what. Cloud environments make this harder because virtualized networking is dynamic, and misconfigurations can silently open pathways that policy dictates should not exist.

None of this is possible without a platform built to deliver full-stack cloud visibility at scale.

What FedRAMP High and IL5 mean for federal and defense agencies

Ensuring compliance with federal cybersecurity requirements is about trust as much as capability. Federal agencies operate under strict compliance mandates, and the tools they deploy must meet equally rigorous standards.

This is why FedRAMP High authorization and Impact Level 5 (IL5) designations matter. 

  • FedRAMP High provides the rigorous validation civilian agencies need to protect sensitive, unclassified citizen and operational data 
  • IL5 meets the strict requirements for DoW workloads 

Together, they support mission environments where the stakes are highest, from civilian infrastructure to tactical edge deployments.

For federal components, this means a cloud security solution that doesn’t require a tradeoff between capability and compliance. It means being able to enforce zero trust principles across sensitive workloads with the confidence that the platform itself has been rigorously vetted.

Tenable One Cloud Exposure has achieved FedRAMP High and IL5 authorization, building on its existing FedRAMP Moderate status. This milestone expands Tenable’s ability to support highly sensitive federal environments, including those intelligence agencies use, and opens the door to new mission-critical use cases that previously required separate tooling.

A unified approach to cloud risk: Advancing the exposure management journey for federal agencies

One of the most persistent challenges facing federal security teams is tool sprawl. When cloud infrastructure security, identity security, workload protection, data security, and compliance monitoring all live in separate products, the result is fragmented visibility and gaps that attackers can exploit.

A unified cloud native application protection platform (CNAPP) changes that equation. To truly maximize the value of Tenable One Cloud Exposure’s new IL5 and FedRAMP High authorizations, your teams cannot evaluate cloud risk in silos. 

As part of the Tenable One Exposure Management Platform, Tenable One Cloud Exposure acts as a unified vehicle for risk reduction for federal cloud environments. It allows agencies to comprehensively map their cloud attack surface by analyzing workloads, identities, and infrastructure together inside a single, rigorously vetted security boundary. This approach ensures that high-compliance cloud environments achieve maximum visibility without risking cross-domain data contamination.

How federal agencies can shift from reactive to proactive risk reduction

The federal zero trust journey is a continuous operational posture rather than a static destination. By achieving milestones like IL5 and FedRAMP High authorization, Tenable One Cloud Exposure is positioned to help agencies shift from reactive firefighting to proactive risk reduction in their most sensitive environments. The result: security teams can see across their cloud infrastructure, prioritize what matters most to national defense, and act fast.

To learn how to guide your cloud exposure management journey and see how Tenable One Cloud Exposure supports federal zero trust requirements, visit https://www.tenable.com/solutions/government/us-fed.