New at Horizon3

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-27771

CVE-2026-27771 is a high-severity authentication bypass vulnerability affecting Gitea’s built-in package and container registry functionality. The flaw may allow unauthenticated attackers to retrieve private container images and package artifacts without valid credentials.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-9082

CVE-2026-9082 is a highly critical SQL injection vulnerability in Drupal core affecting PostgreSQL-backed deployments. The flaw allows unauthenticated attackers to execute arbitrary SQL queries and potentially compromise affected environments.
Read More →

WEBINAR REPLAY

SEARCH

CATEGORIES

TAGS

SEARCH

    When “Read-Only” Isn’t: K8s nodes/proxy GET to RCE

    February 27, 2026
    A Kubernetes service account with “read-only” nodes/proxy GET permission can execute arbitrary commands across pods via the kubelet API. This post breaks down how WebSocket behavior turns monitoring access into cluster-wide RCE—and how NodeZero detects it.
    Kubernetes nodes/proxy GET permission leading to kubelet remote code execution attack path

    How Do I Choose the Best Pentesting Solution for My Business?

    February 25, 2026
    Choosing a penetration testing solution isn’t a box-checking exercise. When the approach doesn't fit the need, teams often waste budget and time while walking away with a false sense of security. A clean pentest report might look reassuring, but it doesn’t automatically mean defenses are effective or that risk is actually being reduced. A better…

    CVE-2026-1603

    February 18, 2026
    Ivanti Endpoint Manager (EPM) | Authentication Bypass Vulnerability

    CVE-2026-1281 & CVE-2026-1340

    February 11, 2026
    Ivanti Endpoint Manager Mobile | Actively Exploited Remote Code Execution

    CVE-2026-1731

    February 11, 2026
    BeyondTrust Privileged Remote Access and Remote Support | Pre-Auth Remote Code Execution

    From Patch Tuesday to Pentest Wednesday®: Continuous Validation in a Regulated Environment

    February 11, 2026
    By moving from annual snapshots to continuous validation, this organization replaced assumptions with proof. Findings became easier to prioritize. Remediation became easier to justify. Fixes could be verified instead of assumed.

    How Horizon3’s NodeZero® Platform Supports the Realtime Evaluation of the Effectiveness of Zero Trust Functionality for the US Federal Government.

    February 5, 2026
    NodeZero® enables federal agencies to continuously validate Zero Trust controls in production environments, delivering real-time, adversary-driven proof aligned to FedRAMP, NIST, CMMC, and DoD Zero Trust mandates.

    CVE-2025-40551

    January 28, 2026
    SolarWinds Web Help Desk Deserialization Vulnerability | Active Exploitation

    CVE-2025-40551: Another Solarwinds Web Help Desk Deserialization Issue

    January 28, 2026
    CVE-2025-40551 details multiple chained vulnerabilities in SolarWinds Web Help Desk that allow unauthenticated attackers to achieve remote code execution on vulnerable instances.

    Defending with AD Tripwires: GOAD Walkthrough

    January 26, 2026
    This walkthrough shows how AD Tripwires turn quiet Active Directory reconnaissance into deterministic, low-noise detections. Using a GOAD (Game of Active Directory) environment, we demonstrate how exposed-credentials, Kerberoasting, and AS-REP Roasting tripwire accounts surface attacker behavior early in the attack path—mapping real techniques to Windows Security Events and platform alerts so defenders can see exactly…