New at Horizon3
Fal.Con 2026 recap on AI, offensive security, and exposure validation

What Fal.Con 2026 Reinforced: AI Makes Proving Exposure More Important Than Ever

Horizon3
September 4, 2026

For three days at Fal.Con 2026, Horizon3 was hard to miss across the show floor. Our booth stayed packed, our team ran demo after demo of NodeZero®, dozens of people packed into Snehal Antani’s two sessions, and Ward Holloway’s theater session was standing room only. 

But the biggest takeaway wasn’t the traffic, the sessions, or even the more than 1,300 Go Hack Yourself shirts we handed out. It was the conversations behind all of it.

AI is accelerating vulnerability discovery and compressing the time between discovery and potential exploitation, but security teams already have more vulnerabilities than they can reasonably fix. Finding more of them, faster, only makes one question more important:

Which exposures actually matter in my environment?

This is a question that came up again and again at Fal.Con.

Horizon3 team at the Fal.Con 2026 booth in Las Vegas

Offense is increasingly informing defense

That same thinking showed up on Fal.Con’s biggest stage.

In his keynote, CrowdStrike CEO George Kurtz spoke about AI as the new cyber battlefield, offense informing defense, AI red teaming, and the need for a continuous approach to security. Those themes closely reflect something Horizon3 has believed from the beginning: the best way to understand whether your defenses will stand up to an attacker is to attack them yourself.

As AI increases attacker speed and scale, defenders need offensive capabilities that continuously test real environments and provide evidence of what attackers can exploit, how far they can get, which controls stop them, and whether remediation worked.

That attacker-derived evidence is also central to Horizon3’s integration with Falcon Next-Gen SIEM and the perspective we bring to CrowdStrike’s Project QuiltWorks.

AI is accelerating discovery. That makes validation more important.

Ward Holloway presenting Beyond the Mythos Hype at Fal.Con 2026

Ward tackled this directly in his session, “Beyond the Mythos Hype.”

AI is getting better at finding and validating vulnerabilities, compressing work that once required significant time and expertise. That changes the speed of the problem, but it doesn’t change a fundamental reality for defenders: you cannot fix everything.

Security teams already have vulnerability scanners, attack surface management tools, threat intelligence, endpoint telemetry, identity data, and plenty of other signals telling them what could represent risk. Accelerating vulnerability discovery adds even more pressure to an already overloaded system.

The challenge is determining which weaknesses create real exposure in your environment, how they can be chained together, and where those attack paths can lead. The standing-room-only crowd for Ward’s session reinforced what we were hearing throughout the show: this challenge is very much on defenders’ minds.

Vulnerable does not mean exploitable

Snehal approached the same problem from the attacker’s perspective in “Go Hack Yourself. With AI.”

His message was straightforward: instead of waiting for attackers to tell you whether your defenses work, continuously attack yourself to find out.

Snehal Antani presenting Go Hack Yourself With AI at Fal.Con 2026

That means testing the environment to answer questions vulnerability data alone cannot. Can a vulnerability actually be exploited? Can a credential be abused? Can an attacker move laterally or escalate privileges? Do your security controls stop them? Can several seemingly unrelated weaknesses be chained together to reach something that matters?

The answers can materially change what gets fixed first. A critical vulnerability that isn’t proven exploitable in your environment may deserve a very different response from a weakness buried somewhere in a scanner backlog that provides a proven path to critical systems or data.

The goal isn’t another score. It’s evidence security teams can use to decide what matters, take action, and then prove that action worked. That closed loop is what continuous exposure management ultimately requires.

That’s the idea behind Hack. Fix. Verify. Repeat.

The booth conversations made it real

Fal.Con attendees watching a NodeZero autonomous pentesting demo at the Horizon3 booth

What resonated with session attendees carried directly onto the show floor.

Traffic at our booth stayed heavy throughout Fal.Con, and our team ran at least 1,200 NodeZero demos during the show. What stood out wasn’t simply how many people wanted a demo, but what they wanted to understand.

How far could an attacker get? Which weaknesses created meaningful attack paths? Would the security controls they had already invested in stop those attacks? And after remediation, could they prove the exposure was gone?

We also met plenty of people who were encountering proactive offense for the first time. Once they saw autonomous pentesting in action, the value clicked quickly: organizations could continuously test their environments and scale their exposure management programs without having to scale testing infrastructure or resources at the same rate.

There was also strong interest in how Horizon3 and CrowdStrike work together, particularly around how attacker-derived evidence from NodeZero could complement the telemetry and security context SOC teams already use to make decisions. That conversation was especially timely following the announcement that Horizon3 had joined CrowdStrike’s Project QuiltWorks.

NodeZero exploitability intelligence can flow into Falcon Next-Gen SIEM, adding exploitability and attack-path context to the information SOC teams use to prioritize and respond. Falcon Fusion SOAR workflows can also trigger NodeZero 1-Click Verify, allowing teams to retest remediated weaknesses and determine whether the validated attack path has been closed.

Taken together, these weren’t simply vulnerability management questions. They were exposure management questions.

Security teams want to discover potential exposure, validate what attackers can exploit, use that evidence to prioritize what matters most, remediate with clarity, and then verify that the validated exposure has been removed.

Discover. Validate. Prioritize. Remediate. Verify. Repeat.

That’s how organizations move from managing findings to continuously managing exposure.

What we brought home from Vegas

AI is going to keep accelerating vulnerability discovery, while attackers will continue looking for the weaknesses, credentials, misconfigurations, and gaps in security controls that give them a path through an environment. Trying to keep pace by simply adding more findings to the queue isn’t a strategy for managing exposure.

Security teams need evidence of what attackers can actually do, clarity about what matters most, and proof that remediation worked.

Hack. Fix. Verify. Repeat.

That was our message going into Fal.Con. After three days of packed sessions, nonstop demos, and conversations with security teams from across the industry, we came home even more convinced of it.

Attendees gathering at the Horizon3 Lounge during Fal.Con 2026 in Las Vegas
How can NodeZero help you?
Let our experts walk you through a demonstration of NodeZero®, so you can see how to put it to work for your organization.
Get a Demo
Share: