New at Horizon3

Frontier AI Changes Vulnerability Discovery. It Doesn’t Change How Breaches Happen.

Stephen Gates
August 31, 2026

Frontier AI is changing the economics of vulnerability discovery. Models are increasingly capable of finding, chaining, and exploiting vulnerabilities at machine speed, compressing timelines that once gave defenders more time to understand and remediate newly discovered weaknesses.

CrowdStrike’s Project QuiltWorks is bringing together frontier AI, security technology, services, cloud infrastructure, and other capabilities to help organizations respond to this new reality. CrowdStrike is now expanding QuiltWorks across its technology ecosystem, bringing data from Horizon3 and other security providers into Falcon® Next-Gen SIEM to deepen attack-path analysis, enrich prioritization, and accelerate remediation.

For Horizon3, there is a simple idea behind our participation:

Frontier AI changes how vulnerabilities are discovered. It doesn’t change how breaches happen.

Finding a vulnerability is only the beginning. The outcome depends on what an attacker can do after gaining access.

The real question starts after initial compromise

Security teams have spent decades trying to identify and remediate vulnerabilities before attackers exploit them. That remains essential, but frontier AI makes it increasingly unrealistic to assume organizations will find and fix every vulnerability before an attacker gets there.

There will always be another vulnerability, another exposed system, another path to initial access.

So the more important question is not simply whether a vulnerability can be exploited. It is:

If one of my systems is compromised, what happens next?

Can the attacker harvest credentials and use them elsewhere? Can they escalate privileges or move laterally? Can they cross network or identity boundaries? Can they reach Active Directory, Entra ID, cloud environments, or sensitive data? Do endpoint and other security controls detect and stop their activity? How large is the potential blast radius?

Those questions determine whether an initial compromise remains contained or becomes a business-impacting breach.

Consider two organizations running the same vulnerable technology. An attacker compromises the same type of system in both environments. In the first, harvested credentials and excessive privileges provide a path into critical infrastructure and sensitive data. In the second, segmentation, identity controls, endpoint security, and least privilege stop the attacker from progressing.

The vulnerability is the same. The consequences are not.

That difference is cyber resilience.

Cyber resilience starts with assumed breach

The accelerating pace of vulnerability discovery makes an assumed-breach mindset even more important.

Assumed breach does not mean abandoning prevention or vulnerability remediation. Organizations should continue identifying and fixing vulnerabilities as quickly as practical. But cyber resilience cannot depend on eliminating every possible path to initial compromise before an attacker finds it.

Instead, assume initial compromise is possible and continuously test what happens next.

This mindset is already fundamental to how NodeZero® tests environments. Internal pentesting provides a clear example because the test begins from the perspective of an attacker or malicious insider who already has access to the network. From there, NodeZero tests the opportunities available to the attacker and chains weaknesses together to determine what they can ultimately compromise.

The same principle extends across the attack surface. Initial access might come through an internet-facing system, a web application, exposed credentials, an identity weakness, a cloud misconfiguration, or another exploitable condition. Once access is established, the question becomes what that access enables.

The entry point may change. What matters is what the attacker can do next.

Weak credentials, excessive privileges, misconfigurations, ineffective segmentation, exposed secrets, identity weaknesses, and security control gaps can transform an initial compromise into a path to critical systems and sensitive data. Breaking those paths can contain an attacker regardless of how they initially gained access.

As frontier models discover vulnerabilities faster than organizations can remediate them, the more durable approach is to continuously reduce the opportunities attackers can use to progress through the environment.

That changes the objective. Instead of measuring security primarily by how many vulnerabilities were found or patched, organizations can ask whether they are systematically reducing attacker opportunity. Can attackers move as far as they could last month? Can they still reach the same critical assets? Are security controls stopping the techniques they are supposed to stop? Did remediation actually eliminate the attack path?

Those questions require evidence from the attacker’s perspective.

Why the attacker’s perspective matters to QuiltWorks

That is the role Horizon3 brings to Project QuiltWorks.

QuiltWorks brings together frontier AI vulnerability discovery with threat intelligence, telemetry, exposure data, remediation capabilities, and other security context. Horizon3 adds another critical layer of evidence: what an attacker can actually accomplish in a specific environment.

The NodeZero® Proactive Security Platform autonomously validates what happens after an initial compromise by continuously testing how far attackers can move, determining which security controls stop them, identifying what critical assets remain at risk, and proving that remediation efforts have measurably reduced attacker opportunity.

That attacker-derived evidence helps put potential exposure into environmental context. Vulnerable does not necessarily mean exploitable, and exploitable does not necessarily mean business-impacting. A vulnerability may provide an opportunity for initial access, but the ultimate risk depends on the environment behind it. NodeZero shows whether an attacker can use the opportunities available in that environment to escalate privileges, move laterally, cross trust boundaries, reach critical assets, or access sensitive data. Just as importantly, it identifies where security controls stop the attack and verifies whether remediation has broken the path.

This distinction becomes increasingly valuable as AI expands the universe of known vulnerabilities. More vulnerability intelligence does not eliminate the need to understand what those weaknesses mean inside a specific environment. It makes that context more important.

As QuiltWorks expands what defenders can discover, understand, and act on, Horizon3 brings evidence of what attackers can actually do, giving teams the context to determine what needs to be fixed now.

That is the attacker’s perspective.

Connecting attacker evidence to defender action

Through the Horizon3 and CrowdStrike integration, that evidence becomes part of the workflows defenders already use.

NodeZero’s exploitability intelligence flows into Falcon Next-Gen SIEM, bringing proven attack-path evidence alongside other security telemetry, threat intelligence, and exposure data. CrowdStrike workflows can use that context to inform prioritization and response, helping teams focus on the weaknesses and attack paths that create meaningful risk in their environment.

The integration also connects remediation back to validation. Falcon Fusion SOAR workflows can trigger NodeZero 1-Click Verify to retest specific remediated weaknesses and confirm whether the attack path has been closed.

The result is not simply more vulnerability data. It connects the attacker’s perspective to the defender’s workflow.

NodeZero provides evidence of what an attacker can actually do. CrowdStrike brings that evidence into the workflows teams use to investigate, prioritize, and respond. Verification closes the loop by proving whether the action taken actually reduced risk.

Hack. Fix. Verify. Repeat.

Security in the AI era requires evidence of resilience

Frontier AI will continue to accelerate vulnerability discovery. Visibility into newly discovered vulnerabilities remains essential, but visibility alone cannot tell security leaders how resilient their environment is when an attacker gets in.

They need continuous evidence that security controls are working as intended, that attackers cannot move freely through the environment, that critical assets remain protected, and that remediation efforts are producing measurable security outcomes.

That is why Horizon3 is part of Project QuiltWorks.

As AI expands what defenders can discover and understand, Horizon3 provides the attacker-derived evidence needed to understand what happens after initial compromise. Together with CrowdStrike, that evidence can be connected to the workflows teams use to prioritize risk, take action, and verify that the action worked.

Organizations cannot build cyber resilience on the assumption that attackers will never find a way in. They can build it by continuously testing what happens when they do.

The measure of resilience is not whether your environment has vulnerabilities. It is whether an attacker can turn one of them into a breach.

How can NodeZero help you?
Let our experts walk you through a demonstration of NodeZero®, so you can see how to put it to work for your organization.
Get a Demo
Share: