Problems at Tenable (TENB)
Cyber Boom Leaves Behind Vulnerability Management
Yesterday, The Bear Cave published a primer on companies at risk of AI disruption. Today, we dive deeper on one in particular.
By: Sam Koppelman and Dhruv Patel
Editor: Vikas Kumar
The Bear Cave is now owned by Hunterbrook Media. Based on Hunterbrook Media’s reporting, at the time of publication Hunterbrook Capital is short $TENB and long a basket of comparable securities, including $CRWD and $S. Positions may change at any time. This article is not investment advice or any recommendation. See full disclosures on our website.
The need for cybersecurity is accelerating, but legacy vulnerability managers like Tenable ($TENB) seem to be on the wrong side of a revolution.
In addition to AI-equipped hackers deploying new tactics, incumbents face a quadruple threat of competitive pressure: 1) Industry giants like CrowdStrike, SentinelOne, and Microsoft adding vulnerability management to their platforms; 2) AI-native startups innovating and undercutting on price; 3) Open-source models lowering barriers to entry; and 4) Frontier AI companies launching their own products.
Tenable has tried to combat this narrative, partnering with Anthropic and debuting agentic tools to resist obsolescence. Will it work? Or will Tenable be the Chegg of Cyber? Interviews with over a dozen experts indicate vulnerability management is now “commoditized,” “in a serious pickle,” and “permanently impaired.”
Alongside our friends at Citrini Research, we also assigned an undergraduate computer science major and journalist with the task of vibe-coding our own vulnerability management tool, Untenable — which quickly found some important vulnerabilities that a Tenable tool missed.
Tenable did not respond to repeated requests for comment. Its competitor, Qualys ($QLYS), responded: “While traditional scanning and detection have indeed become table stakes, that’s not where we compete anymore… we’re actively managing the mix shift away from the commoditized layer toward outcomes: risk-based prioritization, exploit validation, and remediation.”
The full investigation is available exclusively to paid readers of The Bear Cave.
AI escaping confinement or trying to infect GitHub. Iranian cyberattackers allegedly breaching American water systems. Hackers stealing Bitcoin from crypto wallets.
With AI-driven threats rising, there are enormous opportunities for many cybersecurity companies, with customers redirecting budgets toward IT security. But according to over a dozen experts The Bear Cave interviewed, one category appears to be most, well, vulnerable: companies that identify (and sometimes remediate) vulnerabilities across websites and other digital surfaces.
“The vulnerability management companies — Qualys, Tenable, Rapid7 — feel genuinely at risk,” said Arpan Punyani, co-founder of Garuda Ventures. “The terminal value of those companies is permanently impaired.”
What happens to profit margins, customer retention, and user growth when competitors and AI agents can identify vulnerabilities that legacy vendors miss?
“The legacy players, especially the public companies, are in a serious pickle,” the founder and former CEO of a large cybersecurity company told us.
Rapid7’s ($RPD) market capitalization has already fallen 90% from its peak to under $700 million. The other two public vulnerability management incumbents — Tenable ($TENB, $4 billion) and Qualys ($QLYS, $6.5 billion) — recently launched agentic AI products. But these companies don’t solely face open-source and in-house alternatives: They’re also threatened by the competitive offerings of cybersecurity giants.
CrowdStrike ($CRWD), Palo Alto Networks ($PANW), and Google ($GOOG), via its acquisition of Wiz, have each begun bundling vulnerability management and application security into their broader security platforms. Microsoft ($MSFT) — which offers enterprise customers a low-cost alternative to vulnerability scanning — launched a system that identifies bugs before attackers can exploit them. In April, Anthropic launched Claude Code Security, which scans entire codebases for vulnerabilities and generates patches, no standalone security vendor required.
Qualys told The Bear Cave: “We are better insulated than a single-product pure-play,” citing its “native patch management capability” and that “organizations do not have to decide between best-of-breed tools and platformization, they can have the best of both worlds with Qualys.”
A wave of startups have also launched to deliver cybersecurity products, built with the help of AI agents.
Tobias Citron, a cybersecurity investor at Primary VC, said the vulnerability management market was already commoditized and has now “just become an even bigger commodity.”
Michael Meis, Associate CISO at The University of Kansas Health System, agreed: vulnerability management “will continue to see business” because it’s mandated in “pretty much every regulation and security framework that exists.” But it will also “face the most pressure to innovate or become a legacy player,” he said. Vulnerability management will be “more commoditized and largely relegated to a checkbox exercise as part of cyber hygiene…”
And if you can check the box with Microsoft or Crowdstrike or another major vendor you already work with — to say nothing of a cheaper, box-checking startup — why choose Tenable?
“There are a handful of start-ups emerging with a direct target to replace Qualys and Tenable,”said Jason Rebholz — a former Chief Information Security Officer (CISO) who co-founded and leads Evoke Security — referring to a new wave of startups.
There’s a lengthy list of potential vulnerability management (VM) competitors:
“The pillar cyber products — endpoint, cloud security, identity (where the enforcement happens) — won’t go anywhere,” said Punyani. “In fact, they probably strengthen.”
But when it comes to vulnerability management, the client decision-makers — typically led by a CISO at larger companies — now need more than basic data and scanning. They also need context for prioritization, translation of data into business risk, and ideally, fast, automated remediation of problems.
Tenable, for its part, appears to be aware of the changing landscape, and the company has invested in products that don’t just identify vulnerabilities but remediate them. One, called Hexa AI, is “built to turn exposure intelligence into coordinated action at machine speed.” Tenable is partnered with Anthropic on the initiative. But as need has ballooned, Tenable’s rate of sequential quarterly revenue growth has declined.

The stakes are extremely high, according to the companies on the frontier.
Earlier in 2026, there was a temporary but sharp sell-off in cybersecurity stocks after Anthropic revealed that its model, Mythos, had identified previously unknown vulnerabilities. After a brief government intervention, Anthropic now sells a Mythos-like model called Fable with strict limits, especially on cybersecurity-related prompts.
Then, in July, an experimental agent at OpenAI escaped a sandboxed containment. The agent exploited a vulnerability in third-party software and orchestrated a sophisticated campaign. It accessed the internet and hacked Hugging Face, an AI tools company with information that the agent wanted.
Soon after, Anthropic announced several of its latest models had engaged in comparable misbehavior. News broke this week of a similar breach at Meta.
In the case of OpenAI’s rogue agent, the victim pivoted away from traditional cybersecurity and eschewed the leading AI companies because their guardrails rendered domestic models insufficient. Hugging Face instead used an open-source AI model from China.
The properties and capabilities that made a Chinese open-source model the right tool for Hugging Face also make it a game-changer for would-be attackers. A new era of AI-enabled, semi- and fully-autonomous cyberattacks will only increase demand for the products of most of the leading public cybersecurity vendors.
Ultimately, though, Citron said of vulnerability management that “Claude’s going to be able to do a lot of and is already able to do a lot of what they do … People just use open-source scanners now and the scanning technology itself is obviously a complete commodity and it’s just become an even bigger commodity with the Claude stuff.”
“You’ll see more of the existing players basically offer that vulnerability management checkbox for you,” one CISO explained. “We’ve already seen CrowdStrike moving into the vulnerability management space. If you’ve already got CrowdStrike on your endpoint… you can get rid of your existing vulnerability management space and still check the regulation checkbox.”
Two sources who previously worked for Tenable said they expect the company to lose business.
“I’m not naive to say that the legacy vulnerability management players are going to die tomorrow, but the reason you see their stock decline, some of it is fear, some of it is real,” said Itamar Mizrahi, a former Tenable executive. “They’re slowly going to decline.”
Based on Tenable’s quarterly SEC filings, the growth rate has already collapsed, even as Tenable raised its guide this quarter —archetypal of a melting ice cube.
A salesperson at a multibillion-dollar cybersecurity reseller put it bluntly. When he runs CrowdStrike deals, he tells clients to “get rid of your Tenable.”
He says that in the CrowdStrike and SentinelOne deals he works on, those companies ask how much customers are paying for Tenable, and then try to undercut it. Sometimes, a customer will have an allegiance to Tenable because they have a customized Tenable One environment, he said. In other cases, CISOs prefer to “take a line item off my budget” by consolidating.
“I think they’ll lose 50% to CrowdStrike and SentinelOne,” he said, referring to Tenable’s market share.
Tenable didn’t respond to repeated requests for comment. Qualys said that “organizations that might go for these bundled deals are not the type of enterprise customer that we are pitching and winning, which are the complex, heterogeneous, or compliance-heavy environments.”
Qualys pitched itself as “one of the only major vendors that can provide a true platform approach to cyber risk management.” The company’s spokesperson highlighted its competitor to Tenable’s Hexa, called Agent Val, which “does exploit validation to check if a vulnerability is indeed exploitable,” as opposed to “most tools,” which it said “can only check if you have a vulnerability in your environment, but not test it safely, so security teams have to do exploit validation manually.”
“Competitors may flag risk, but Agent Val proves it and proves it’s gone,” said the company.
To figure out the winners and losers of this new AI cybersecurity paradigm, The Bear Cave partnered with Citrini Research, an industry veteran, and a freelance coder to test what’s become possible with open-source tools; and whether Tenable could match up to the new AI tools that are rapidly improving.
We began by testing Tenable — or rather, Untenable: a vibe-coded tool to detect vulnerabilities that Tenable missed.
Mizrahi threw down the gauntlet to the latest AI models: “If you would take Opus or Mythos or whatever model it is and compare it nowadays to those of the vulnerability management incumbents, they would lose. But over time it’s only a natural step they would become better and eventually even surpass Tenable.”
Hunterbrook Media journalist and undergraduate software engineer Dhruv Patel picked up that gauntlet for The Bear Cave, testing whether it was time for that “natural step.”
The tl;dr — The Bear Cave didn’t build a better tool than a multi-billion dollar company in a week. That would be pretty ridiculous, though we did get surprisingly close to the product we benchmarked against. And we did not try to compete with Tenable One, the full enterprise stack offered by Tenable. But the vibe-coded tool we spun up found several vulnerabilities that Tenable missed.
More on how that test went — and key takeaways — available exclusively to The Bear Cave’s paid subscribers.




