New at Horizon3

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-10520

CVE-2026-10520 is a critical pre-authenticated OS command injection vulnerability in Ivanti Sentry that allows remote attackers to execute arbitrary commands as root.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-0257

CVE-2026-0257 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect that allows unauthorized VPN access and is actively exploited in the wild.
Read More →

SEARCH

CATEGORIES

TAGS

SEARCH

    CVE-2026-21643

    April 15, 2026
    CVE-2026-21643 allows unauthenticated SQL injection in FortiClient EMS, enabling code execution. Patch immediately and validate exposure.

    From Patch Tuesday to Pentest Wednesday®: When “Clean” Didn’t Mean Secure

    April 15, 2026
    External tests looked clean—but internal pentesting revealed a full attack path to domain compromise despite active security controls.

    CVE-2026-20160

    April 8, 2026
    CVE-2026-20160 enables unauthenticated command execution in Cisco SSM On-Prem. Patch immediately and validate exposure.

    Incident Response Remediation: How to Eliminate Attack Paths After a Breach

    April 8, 2026
    Digital threat monitoring shows threats and exposure—but not whether attackers can exploit your environment. Here’s what matters next.

    10 Minutes with Claude: Remote Code Execution in Apache ActiveMQ (CVE-2026-34197)

    April 7, 2026
    CVE-2026-34197 enables remote code execution in ActiveMQ via Jolokia. Exploitation chains VM transport and remote config loading.

    CVE-2026-34197

    April 7, 2026
    CVE-2026-34197 allows code execution in ActiveMQ via Jolokia. Validate exposure, patch affected versions, and confirm remediation.

    CVE-2026-35616

    April 6, 2026
    CVE-2026-35616 Fortinet FortiClient EMS Improper Access Control Vulnerability | Active Exploitation

    SLED U.S. State, Local, & Education

    April 4, 2026
    State, local and education (SLED) organizations have unique pain points. Because they rely on taxpayer dollars, SLED organizations are often trying to do more with less.

    Best Tools for Digital Threat Monitoring and Cyber Threat Visibility

    April 1, 2026
    Digital threat monitoring reveals attacker activity and exposure across your environment—but does it show what’s actually exploitable?

    CVE-2026-20131

    March 31, 2026
    CVE-2026-20131 allows unauthenticated remote code execution in Cisco FMC via insecure deserialization. Exploited in ransomware campaigns—patch immediately.