New at Horizon3

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-23734

CVE-2026-23734 is a critical path traversal vulnerability affecting XWiki’s xwiki-commons-classloader-api component. The flaw may allow unauthenticated attackers to access sensitive configuration files through crafted ssx and jsx endpoint requests.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-44578

CVE-2026-44578 is a high-severity server-side request forgery vulnerability affecting self-hosted Next.js applications using the built-in Node.js server.
Read More →

WEBINAR REPLAY

SEARCH

CATEGORIES

TAGS

SEARCH

    Beyond the Perimeter: Why Deception is Critical to Protecting the World’s Most Sensitive Organisations

    January 21, 2026
    Insights from the UK NCSC Active Cyber Defence trials reveal why cyber deception, Tripwires, and attacker-centric defense are critical for protecting highly sensitive organisations.

    Introducing NodeZero® High-Value Targeting: Think Like an Attacker, Prioritize What Matters

    January 20, 2026
    High-Value Targeting (HVT) analyzes and prioritizes systems and accounts based on business impact, replicating how sophisticated attackers identify and prioritize targets after establishing initial access. It identifies domain controllers, privileged accounts, and critical infrastructure, directing NodeZero to test the most critical attack paths first. As NodeZero discovers new systems, credentials, and network relationships, HVT continuously…

    CVE-2025-11250

    January 15, 2026
    ManageEngine ADSelfService Plus Authentication Bypass

    CVE-2025-37164

    January 14, 2026
    HPE OneView Remote Code Execution Vulnerability | CISA KEV

    From Patch Tuesday to Pentest Wednesday®: When Proving Compliance Becomes Cyber Resilience

    January 14, 2026
    A Pentest Wednesday® story showing how one of the world’s largest payments providers replaced point-in-time compliance testing with continuous, attacker-aligned validation.

    CVE-2025-64155 | Fortinet FortiSIEM

    January 13, 2026
    Fortinet FortiSIEM Arbitrary File Write Remote Code Execution Vulnerability

    CVE-2025-64155: Three Years of Remotely Rooting the Fortinet FortiSIEM

    January 13, 2026
    CVE-2025-64155 chains argument injection and privilege escalation flaws in FortiSIEM to achieve remote root compromise.

    CVE-2026-22200

    January 12, 2026
    osTicket PHP Filter Chain Injection Vulnerability

    CVE-2025-52691

    January 12, 2026
    SmarterTools SmarterMail Remote Code Execution via Unauthenticated Arbitrary File Upload | Critical

    From Honeypots to Active Directory Tripwires

    January 9, 2026
    Traditional deception tools promised high signal but failed at scale. This page explores how NodeZero® Active Directory Tripwires transform deception into a practical, enterprise-ready detection strategy—using real attacker behavior to deliver early, high-fidelity alerts where identity attacks matter most.