The Attack Path Tour

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-0300

CVE-2026-0300 enables unauthenticated remote code execution in PAN-OS, posing a critical risk to enterprise and government networks.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-41940

CVE-2026-41940 allows unauthenticated access to cPanel and WHM, posing a critical risk to hosting environments and managed infrastructure.
Read More →

WEBINAR REPLAY

SEARCH

CATEGORIES

TAGS

SEARCH

    CVE-2025-14847

    January 6, 2026
    MongoDB Server Uninitialized Heap Memory Disclosure (MongoBleed) | Active Exploitation

    CVE-2025-14733

    January 5, 2026
    WatchGuard Fireware OS VPN Vulnerability | Active Exploitation

    CVE-2025-14611

    December 19, 2025
    React Server Components RCE | Rapid Response

    How Horizon3 is Supporting the DoW Cybersecurity Risk Management Construct (CSRMC)

    December 17, 2025
    The DoW’s new Cybersecurity Risk Management Construct demands continuous, evidence-driven security. Learn how Horizon3’s NodeZero delivers real-time, attacker-validated proof to support mission resilience.

    UPDATED: CVE-2025-57819, CVE-2025-66039, CVE-2025-61675, CVE-2025-61678

    December 11, 2025
    Sangoma FreePBX Authentication Bypass and Remote Code Execution Vulnerabilities

    The FreePBX Rabbit Hole: CVE-2025-66039 and others

    December 11, 2025
    We dive into a new set of FreePBX issues beyond CVE-2025-57819: an authentication bypass in webserver mode (CVE-2025-66039), multiple SQL injections (CVE-2025-61675), and an arbitrary file upload bug leading to remote code execution (CVE-2025-61678). Together, they allow authenticated or unauthenticated attackers to achieve code execution on vulnerable FreePBX instances using risky auth settings. This write-up…

    From Patch Tuesday to Pentest Wednesday®: Proof That Redefined Security for a Manufacturer

    December 10, 2025
    Patch Tuesday is a known event, but attackers are moving faster than ever. For a leading U.S. manufacturer, shifting from simple patching to continuous validation became the key to proving their fixes worked, turning uncertainty into confidence.

    CVE-2025-55182

    December 5, 2025
    React Server Components RCE | Rapid Response

    Horizon3 is named a Customer’s Choice in the October 2025 Gartner® Peer Insights™ “Voice of the Customer”: Adversarial Exposure Validation report

    December 4, 2025
    Horizon3 has been named a Customers’ Choice in the October 2025 Gartner® Peer Insights™ “Voice of the Customer”: Adversarial Exposure Validation report, reflecting strong peer satisfaction and real-world impact.

    Introducing Threat Informed Perspectives: A More Strategic Way to Measure Security Posture

    Threat Informed Perspectives give organizations a structured, attacker-aligned way to measure exposure, track real security improvement, and validate remediation over time using continuous, evidence-driven insights from NodeZero.