Tenable folds application security into Tenable One exposure platform
Exposure management company Tenable Holdings Inc. today expanded its Tenable One Exposure Management Platform to pull application security risk into the same view as the rest of an organization’s exposure data. By adding static code vulnerability information, the platform now tracks risk from code through to runtime across the attack surface.
The addition targets a gap that has grown as software ships faster. Vulnerable code often reaches production before anyone can review it, a problem Tenable says generative artificial intelligence is making worse. Developers using AI assistants write code three to four times faster while introducing flaws at up to 10 times the rate, according to a research note from the Cloud Security Alliance.
Application security teams have typically worked from tools that flag code flaws without the infrastructure context needed to judge whether a given vulnerability actually threatens the business. Tenable argues that disconnect leaves an exploitable blind spot, with security staff unable to tell which of thousands of findings matter.
Tenable One now ingests and normalizes data from application development and security sources, including AI-powered application security tools such as Claude Security. It then links that data to the wider exposure picture Tenable already collects, spanning endpoint protection, cloud security, vulnerability management and operational technology security, along with business context drawn from sources such as configuration management databases.







