The Attack Path Tour

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-86218

CVE-2026-86218 is a critical, actively exploited N-able N-central vulnerability that can allow unauthenticated remote code execution. NodeZero® Rapid Response safely validates exposure.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-85706

CVE-2026-85706 is a critical GitLab CE/EE path traversal vulnerability that can allow unauthenticated attackers to read arbitrary server-side files. NodeZero® Rapid Response safely validates exposure.
Read More →

SEARCH

CATEGORIES

TAGS

SEARCH

    CTEM Technology Evaluation Scorecard

    September 16, 2026
    Use the CTEM Technology Evaluation Scorecard to assess technologies across the CTEM operating model, score capabilities based on demonstrated evidence, and identify critical validation and verification gaps.

    CISO’s CTEM Evaluation Checklist

    September 16, 2026
    Use the CISO’s CTEM Evaluation Checklist to assess whether technologies supporting your CTEM program can prove exploitability, demonstrate attack impact, verify remediation, and show measurable exposure reduction.

    CVE-2026-86218

    September 16, 2026
    CVE-2026-86218 is a critical, actively exploited N-able N-central vulnerability that can allow unauthenticated remote code execution. NodeZero® Rapid Response safely validates exposure.
    CVE-2026-86218 N-able N-central pre-authentication remote code execution vulnerability

    Security Data Isn’t the Problem. Security Context Is.

    September 15, 2026
    Security teams don't need more data. They need context. See how Horizon3 and CrowdStrike connect validated exposure evidence with security telemetry to help teams prioritize what matters most.
    Horizon3 and CrowdStrike integration bringing validated exposure context into security operations

    CVE-2026-85706

    September 11, 2026
    CVE-2026-85706 is a critical GitLab CE/EE path traversal vulnerability that can allow unauthenticated attackers to read arbitrary server-side files. NodeZero® Rapid Response safely validates exposure.
    CVE-2026-85706 GitLab repository commits API path traversal vulnerability

    Patch Tuesday to Pentest Wednesday: How an Equipment Rental Company Is Turning Continuous Testing Into Continuous Exposure Management

    September 9, 2026
    See how an equipment rental company moved beyond point-in-time pentesting with NodeZero®, continuously validating exploitable risk, driving remediation, and measuring whether exposure is actually decreasing.

    What Fal.Con 2026 Reinforced: AI Makes Proving Exposure More Important Than Ever

    September 4, 2026
    AI is accelerating vulnerability discovery, but security teams still need to know which exposures actually matter. Here’s what Fal.Con 2026 reinforced about offensive security, validation, and proving risk.
    Fal.Con 2026 recap on AI, offensive security, and exposure validation

    How Virginia Tech Connected Pentesting to Its Engineering Workflow

    September 3, 2026
    See how Virginia Tech used the NodeZero GraphQL API, GitLab, and ServiceNow to automate external pentesting and create a repeatable workflow from attack validation to remediation.
    Virginia Tech customer story about integrating NodeZero with GitLab and ServiceNow to automate external pentesting and remediation workflows.

    CTEM Is Not About the Stages. It’s About the Outcome.

    September 2, 2026
    CTEM is not about filling five technology boxes. It is about continuously reducing exploitable exposure, proving remediation worked, and measuring whether the environment is becoming harder to attack.
    CTEM focused on continuous exposure reduction and measurable security outcomes

    CVE-2026-9586

    September 1, 2026
    CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox that can lead to remote code execution. Horizon3 has observed active exploitation attempts in the wild.
    CVE-2026-9586 Sangoma Switchvox SQL injection and remote code execution vulnerability