New at Horizon3

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-3324

CVE-2026-3324 allows authentication bypass in Log360 via exposed APIs. Patch affected builds and validate exposure.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-21643

CVE-2026-21643 allows unauthenticated SQL injection in FortiClient EMS, enabling code execution. Patch immediately and validate exposure.
Read More →

WEBINAR REPLAY

SEARCH

CATEGORIES

TAGS

SEARCH

    CVE-2025-61757

    November 24, 2025
    Oracle Identity Manager Pre-Auth RCE | CISA KEV

    Endpoint Detection and Response: What It Is and How to Know Yours Is Working

    November 24, 2025
    EDR tools offer visibility, but visibility isn’t protection. Learn why credential-driven attacks often bypass EDR and how NodeZero validates real-world detection, blocking, and effectiveness across your endpoints.

    NodeZero Fact Sheet

    November 24, 2025
    The NodeZero platform empowers your organization to reduce your security risk by autonomously finding exploitable weaknesses in your network, giving you detailed guidance about how to prioritize and fix them, and helping you immediately verify that your fixes are effective.

    Supercharging Enterprise AI with Real-World Exploitability Data: The NodeZero MCP Server Advantage

    Learn how the NodeZero MCP Server supercharges enterprise AI ecosystems with attacker-validated exploitability data, continuous validation, and automated security workflows.

    Prioritize What’s Proven: The NodeZero® Approach to Risk‑Based Vulnerability Management

    November 18, 2025
    Horizon3’s NodeZero® redefines Risk-Based Vulnerability Management by connecting exploitability, business context, and attacker behavior. With new capabilities for High-Value Targeting, Advanced Data Pilfering, Threat Actor Intelligence, and Vulnerability Risk Intelligence, NodeZero moves vulnerability management from noise to proof—helping security teams prioritize, fix, and verify what truly matters.

    N-able N-central: From N-days to 0-days

    Horizon3 discovered two critical vulnerabilities in N-able N-central — CVE-2025-9316 and CVE-2025-11700 — that can be chained to leak credentials and fully compromise the appliance. This in-depth analysis details how the flaws were found, exploited, responsibly disclosed, and patched in version 2025.4, turning N-days into true 0-days.

    CVE-2025-64446

    November 14, 2025
    Fortinet FortiWeb Authentication Bypass via Path Traversal Vulnerability

    CVE-2025-9316, CVE-2025-11700

    November 13, 2025
    N-able N-central Vulnerabilities

    CVE-2025-12480

    November 13, 2025
    Gladinet Triofox Improper Access Control Vulnerability | Active Exploitation

    Hack The Box – Retro

    November 10, 2025
    NodeZero® autonomously solved Hack The Box Retro in just 11 minutes, chaining SMB guest access and weak credentials into an ADCS privilege escalation. This demonstration highlights how autonomous pentesting uncovers exploit chains and validates real attack paths, proving Horizon3’s commitment to evidence-based, attacker-validated security.