New at Horizon3

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-9586

CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox that can lead to remote code execution. Horizon3 has observed active exploitation attempts in the wild.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-81578 + CVE-2026-82078

CVE-2026-81578 and CVE-2026-82078 can be chained to achieve unauthenticated remote code execution in PaperCut NG/MF. NodeZero® Rapid Response safely validates whether the attack chain is exploitable.
Read More →

SEARCH

CATEGORIES

TAGS

SEARCH

    What Fal.Con 2026 Reinforced: AI Makes Proving Exposure More Important Than Ever

    September 4, 2026
    AI is accelerating vulnerability discovery, but security teams still need to know which exposures actually matter. Here’s what Fal.Con 2026 reinforced about offensive security, validation, and proving risk.
    Fal.Con 2026 recap on AI, offensive security, and exposure validation

    How Virginia Tech Connected Pentesting to Its Engineering Workflow

    September 3, 2026
    See how Virginia Tech used the NodeZero GraphQL API, GitLab, and ServiceNow to automate external pentesting and create a repeatable workflow from attack validation to remediation.
    Virginia Tech customer story about integrating NodeZero with GitLab and ServiceNow to automate external pentesting and remediation workflows.

    CTEM Is Not About the Stages. It’s About the Outcome.

    September 2, 2026
    CTEM is not about filling five technology boxes. It is about continuously reducing exploitable exposure, proving remediation worked, and measuring whether the environment is becoming harder to attack.
    CTEM focused on continuous exposure reduction and measurable security outcomes

    CVE-2026-9586

    September 1, 2026
    CVE-2026-9586 is a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox that can lead to remote code execution. Horizon3 has observed active exploitation attempts in the wild.
    CVE-2026-9586 Sangoma Switchvox SQL injection and remote code execution vulnerability

    CVE-2026-81578 + CVE-2026-82078

    September 1, 2026
    CVE-2026-81578 and CVE-2026-82078 can be chained to achieve unauthenticated remote code execution in PaperCut NG/MF. NodeZero® Rapid Response safely validates whether the attack chain is exploitable.
    PaperCut NG/MF vulnerabilities CVE-2026-81578 and CVE-2026-82078 leading to remote code execution

    Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586

    September 1, 2026
    Horizon3 researchers discovered CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox that leads to remote code execution and is now being actively exploited.
    Switchvox CVE-2026-9586 validation demonstrating remote code execution

    Frontier AI Changes Vulnerability Discovery. It Doesn’t Change How Breaches Happen.

    August 31, 2026
    Frontier AI is accelerating vulnerability discovery, but breaches still depend on what attackers can do after initial compromise. See how Horizon3 and CrowdStrike connect attacker-derived evidence to defender action.

    Frontier Models Changed the Rules for Exposure Management. Now What?

    Join Brinqa and Horizon3 for a fireside chat on how frontier AI is reshaping exposure management. Learn what’s changed in attacker behavior, how to prioritize the exposures that matter most, and how validated attack-path intelligence can help security teams make faster, more defensible remediation decisions.

    How a Real Estate Company Turned a SQL Lockout Into Actionable Security Insight

    August 25, 2026
    See how a large real estate company used NodeZero to trace a SQL account lockout to a deeper privilege path and drive immediate remediation.
    Real estate customer story on uncovering privilege and service-account risk with NodeZero

    Operationalize CTEM with NodeZero®

    August 24, 2026
    Learn how the Horizon3 CTEM Operating Loop and NodeZero turn Continuous Threat Exposure Management into a repeatable process for discovering, validating, prioritizing, remediating, and verifying exploitable exposure.
    Horizon3 CTEM Operating Loop with NodeZero