Problems at Tenable ($TENB): Cyber Boom Leaves Behind Vulnerability Management
Based on Hunterbrook Media’s reporting, at the time of publication Hunterbrook Capital is short $TENB and long a basket of comparable securities, including $CRWD and $S. Positions may change at any time. This article is not investment advice or any recommendation. See full disclosures below.
AI escaping confinement or trying to infect GitHub. Iranian cyberattackers allegedly breaching American water systems. Hackers stealing Bitcoin from crypto wallets.
With AI-driven threats rising, there are enormous opportunities for many cybersecurity companies, with customers redirecting budgets toward IT security. But according to over a dozen experts we interviewed, one category appears to be most, well, vulnerable: companies that identify (and sometimes remediate) vulnerabilities across websites and other digital surfaces.
“The vulnerability management companies — Qualys, Tenable, Rapid7 — feel genuinely at risk,” said Arpan Punyani, co-founder of Garuda Ventures. “The terminal value of those companies is permanently impaired.”
What happens to profit margins, customer retention, and user growth when competitors and AI agents can identify vulnerabilities that legacy vendors miss?
“The legacy players, especially the public companies, are in a serious pickle,” the founder and former CEO of a large cybersecurity company told us.
Rapid7’s ($RPD) market capitalization has already fallen 90% from its peak to $700 million. The other two public vulnerability management incumbents — Tenable ($TENB, $4 billion) and Qualys ($QLYS, $6.5 billion) — recently launched agentic AI products. But these companies don’t solely face open-source and in-house alternatives: They’re also threatened by the competitive offerings of cybersecurity giants.
CrowdStrike ($CRWD), Palo Alto Networks ($PANW), and Google ($GOOG), via its acquisition of Wiz, have each begun bundling vulnerability management and application security into their broader security platforms. Microsoft ($MSFT) — which offers enterprise customers a low-cost alternative to vulnerability scanning — launched a system that identifies bugs before attackers can exploit them. In April, Anthropic launched Claude Code Security, which scans entire codebases for vulnerabilities and generates patches, no standalone security vendor required.
Qualys told The Bear Cave: “We are better insulated than a single-product pure-play,” citing its “native patch management capability” and that “organizations do not have to decide between best-of-breed tools and platformization, they can have the best of both worlds with Qualys.”
A wave of startups have also launched to deliver cybersecurity products, built with the help of AI agents.
Tobias Citron, a cybersecurity investor at Primary VC, said the vulnerability management market was already commoditized and has now “just become an even bigger commodity.”
Michael Meis, Associate CISO at The University of Kansas Health System, agreed: vulnerability management “will continue to see business” because it’s mandated in “pretty much every regulation and security framework that exists.” But it will also “face the most pressure to innovate or become a legacy player,” he said. Vulnerability management will be “more commoditized and largely relegated to a checkbox exercise as part of cyber hygiene..."
And if you can check the box with Microsoft or Crowdstrike or another major vendor you already work with — to say nothing of a cheaper, box-checking startup — why choose Tenable?
"There are a handful of start-ups emerging with a direct target to replace Qualys and Tenable," said Jason Rebholz — a former Chief Information Security Officer (CISO) who co-founded and leads Evoke Security — referring to a new wave of startups.
There’s a lengthy list of potential vulnerability management (VM) competitors:
"The pillar cyber products — endpoint, cloud security, identity (where the enforcement happens) — won’t go anywhere,” said Punyani. “In fact, they probably strengthen.”
But when it comes to vulnerability management, the client decision-makers — typically led by a CISO at larger companies — now need more than basic data and scanning. They also need context for prioritization, translation of data into business risk, and ideally, fast, automated remediation of problems.
Tenable, for its part, appears to be aware of the changing landscape, and the company has invested in products that don’t just identify vulnerabilities but remediate them. One, called Hexa AI, is “built to turn exposure intelligence into coordinated action at machine speed.” Tenable is partnered with Anthropic on the initiative. But as need has ballooned, Tenable’s rate of sequential quarterly revenue growth has declined.
The stakes are extremely high, according to the companies on the frontier.
Earlier in 2026, there was a temporary but sharp sell-off in cybersecurity stocks after Anthropic revealed that its model, Mythos, had identified previously unknown vulnerabilities. After a brief government intervention, Anthropic now sells a Mythos-like model called Fable with strict limits, especially on cybersecurity-related prompts.
Then, in July, an experimental agent at OpenAI escaped a sandboxed containment. The agent exploited a vulnerability in third-party software and orchestrated a sophisticated campaign. It accessed the internet and hacked Hugging Face, an AI tools company with information that the agent wanted.
Soon after, Anthropic announced several of its latest models had engaged in comparable misbehavior. News broke this week of a similar breach at Meta.
In the case of OpenAI’s rogue agent, the victim pivoted away from traditional cybersecurity and eschewed the leading AI companies because their guardrails rendered domestic models insufficient. Hugging Face instead used an open-source AI model from China.
The properties and capabilities that made a Chinese open-source model the right tool for Hugging Face also make it a game-changer for would-be attackers. A new era of AI-enabled, semi- and fully-autonomous cyberattacks will only increase demand for the products of most of the leading public cybersecurity vendors.
Ultimately, though, Citron said of vulnerability management that “Claude's going to be able to do a lot of and is already able to do a lot of what they do … People just use open-source scanners now and the scanning technology itself is obviously a complete commodity and it's just become an even bigger commodity with the Claude stuff.”
“You’ll see more of the existing players basically offer that vulnerability management checkbox for you,” one CISO explained. “We’ve already seen CrowdStrike moving into the vulnerability management space. If you’ve already got CrowdStrike on your endpoint… you can get rid of your existing vulnerability management space and still check the regulation checkbox.”
Two sources who previously worked for Tenable said they expect the company to lose business.
“I’m not naive to say that the legacy vulnerability management players are going to die tomorrow, but the reason you see their stock decline, some of it is fear, some of it is real,” said Itamar Mizrahi, a former Tenable executive. “They’re slowly going to decline.”
Based on Tenable’s quarterly SEC filings, the growth rate has already collapsed, even as Tenable raised its guide this quarter —archetypal of a melting ice cube.
A salesperson at a multibillion-dollar cybersecurity reseller put it bluntly. When he runs CrowdStrike deals, he tells clients to “get rid of your Tenable.”
He says that in the CrowdStrike and SentinelOne deals he works on, those companies ask how much customers are paying for Tenable, and then try to undercut it. Sometimes, a customer will have an allegiance to Tenable because they have a customized Tenable One environment, he said. In other cases, CISOs prefer to “take a line item off my budget” by consolidating.
“I think they’ll lose 50% to CrowdStrike and SentinelOne,” he said, referring to Tenable’s market share.
Tenable didn’t respond to repeated requests for comment. Qualys said that “organizations that might go for these bundled deals are not the type of enterprise customer that we are pitching and winning, which are the complex, heterogeneous, or compliance-heavy environments.”
Qualys pitched itself as “one of the only major vendors that can provide a true platform approach to cyber risk management.” The company’s spokesperson highlighted its competitor to Tenable’s Hexa, called Agent Val, which “does exploit validation to check if a vulnerability is indeed exploitable,” as opposed to “most tools,” which it said “can only check if you have a vulnerability in your environment, but not test it safely, so security teams have to do exploit validation manually.”
“Competitors may flag risk, but Agent Val proves it and proves it's gone,” said the company.
To figure out the winners and losers of this new AI cybersecurity paradigm, Hunterbrook Media — and its new subsidiary The Bear Cave — partnered with Citrini Research, an industry veteran, and a freelance coder to test what’s become possible with open-source tools; and whether Tenable could match up to the new AI tools that are rapidly improving.
We began by testing Tenable — or rather, Untenable: a vibe-coded tool to detect vulnerabilities that Tenable missed.
Mizrahi threw down the gauntlet to the latest AI models: “If you would take Opus or Mythos or whatever model it is and compare it nowadays to those of the vulnerability management incumbents, they would lose. But over time it’s only a natural step they would become better and eventually even surpass Tenable.”
Hunterbrook Media journalist and undergraduate software engineer Dhruv Patel picked up that gauntlet for The Bear Cave, testing whether it was time for that “natural step.”
The tl;dr — The Bear Cave didn’t build a better tool than Tenable in a week. That would be pretty ridiculous, though we did get surprisingly close to the product we benchmarked against. And we did not try to compete with Tenable One, the full enterprise stack offered by Tenable. But the vibe-coded tool we spun up found several vulnerabilities that Tenable missed.
Which is to say: If the code base were protected only by Tenable, we maybe — just maybe — even could have hacked it.
To read our full analysis, subscribe here to our sister publication, The Bear Cave.
Authors
Dhruv Patel is an investigative journalist based in Cambridge, Massachusetts, specializing in data-driven reporting. He helps spearhead investigative coverage at The Harvard Crimson, and his reporting has been cited and discussed by The New York Times, CNN, The Boston Globe, ABC News, and BBC, where he also frequently contributes commentary. A John Harvard Scholar at Harvard College, he studies computer science and economics to leverage machine learning for accountability journalism.
Sam Koppelman is a New York Times best-selling author who has written books with former United States Attorney General Eric Holder and former United States Acting Solicitor General Neal Katyal. He helped build Fenway Strategies into one of the preeminent strategic communications firms in the country—with side quests speechwriting for Michael Bloomberg, running the surrogate remarks operation on the Biden-Harris campaign, and co-founding Mayday, which is now one of the leading information providers on how to access reproductive health care in states with bans. Sam has published in the New York Times, Washington Post, Boston Globe, Time Magazine, and other outlets — and occasionally volunteers on a fire speech for a good cause. He has a BA in Government from Harvard, where he was named a John Harvard Scholar and wrote op-eds like “Shut Down Harvard Football,” which he tells us were great for his social life.
Editors
Vikas Kumar joined Hunterbrook from The Capitol Forum, where he led the corporate investigations team for a decade as a senior editor. He was previously an attorney at Gordon Feinblatt, a trial attorney for the Department of Justice, and a law clerk for a federal judge. He has a J.D. from University of Virginia School of Law and a bachelor's from Emory University. Vikas is based in Maryland.