Resource Center
Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.
LATEST VULNERABILITIES
CVE-2026-21589 is a critical vulnerability affecting multiple Atlassian Data Center products that allows unauthenticated attackers to read specific files within the web application root. NodeZero® Rapid Response safely validates exposure.
Read More →CVE-2026-76504 is a critical, actively exploited Cisco Catalyst SD-WAN Manager vulnerability that allows unauthenticated API access as the admin user. Horizon3 reverse engineered the flaw, and NodeZero® Rapid Response safely validates exposure.
Read More →WEBINAR REPLAY
SEARCH
CATEGORIES
TAGS
SEARCH
CATEGORIES
TAGS
Zammad CVE-2026-102489: Session Leak to RCE
October 7, 2026
Horizon3 reverse engineered CVE-2026-102489 in Zammad, reproduced the unauthenticated WebSocket session leak, traced the vulnerable code path, and demonstrated how a leaked admin session can lead to remote code execution.
CVE-2026-21589
October 6, 2026
CVE-2026-21589 is a critical vulnerability affecting multiple Atlassian Data Center products that allows unauthenticated attackers to read specific files within the web application root. NodeZero® Rapid Response safely validates exposure.
Horizon3 + CrowdStrike: Prove. Prioritize. Verify.
October 2, 2026
See how Horizon3 and CrowdStrike connect NodeZero exploitability intelligence with Falcon Next-Gen SIEM and Fusion SOAR to prove, prioritize, remediate, and verify exploitable risk.
HacktoberFest: A Fireside Chat with Horizon3 & GuidePoint Security
Continuous Validation, Real-World Risk, and Proving Security Impact Join top subject matter experts from Horizon3 and GuidePoint Security for a candid conversation on the evolving cybersecurity landscape and what organizations can do to strengthen their defenses.
What Security Metrics Actually Matter?
October 1, 2026
Security activity doesn’t always equal risk reduction. Learn how attack paths, business impact, verification, remediation speed, and recurrence can show whether CTEM is actually working.
CVE-2026-76504
September 30, 2026
CVE-2026-76504 is a critical, actively exploited Cisco Catalyst SD-WAN Manager vulnerability that allows unauthenticated API access as the admin user. Horizon3 reverse engineered the flaw, and NodeZero® Rapid Response safely validates exposure.
The ECB’s Deadline is Looming
Learn What a Credible Action Plan and Response Looks Like On 7 July 2026, the ECB made AI-enabled cyber risk a board-level, time-bound supervisory priority for significant institutions.With the 31 October 2026 deadline fast approaching, banks need to assess their exposure now and submit a concrete action plan to their Joint Supervisory Team. Join us…
Horizon3’s Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
September 30, 2026
Horizon3 researchers used Anthropic’s Mythos to uncover a chain of cryptographic weaknesses in Rejetto HFS, recover a predictable signing key, forge an admin session, and achieve remote code execution.
Your Password Policy Can Pass. Your Passwords Can Still Fail.
See Your Active Directory Passwords From an Attacker’s Perspective Join Horizon3 and Shaun Hunt, CIO of McKenney’s and a longtime NodeZero® customer, for a live conversation about Active Directory password exposure and how NodeZero AD Password Audit helps uncover credentials that could be targeted through password cracking, password spray, credential stuffing, and credential reuse.
CVE-2026-19490
September 28, 2026
CVE-2026-19490 is a critical Citrix NetScaler ADC and Gateway authentication bypass vulnerability included in CISA’s Known Exploited Vulnerabilities catalog. NodeZero® Rapid Response safely validates exposure.








