Opens in a new tab
The Attack Path Tour

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-23734

CVE-2026-23734 is a critical path traversal vulnerability affecting XWiki’s xwiki-commons-classloader-api component. The flaw may allow unauthenticated attackers to access sensitive configuration files through crafted ssx and jsx endpoint requests.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-44578

CVE-2026-44578 is a high-severity server-side request forgery vulnerability affecting self-hosted Next.js applications using the built-in Node.js server.
Read More →

WEBINAR REPLAY

SEARCH

CATEGORIES

Filter - Checkbox

TAGS

Filter - Checkbox

SEARCH

Filter - Checkbox
Filter - Checkbox

    CVE-2025-64155: Three Years of Remotely Rooting the Fortinet FortiSIEM

    January 13, 2026
    CVE-2025-64155 chains argument injection and privilege escalation flaws in FortiSIEM to achieve remote root compromise.

    CVE-2026-22200

    January 12, 2026
    osTicket PHP Filter Chain Injection Vulnerability

    CVE-2025-52691

    January 12, 2026
    SmarterTools SmarterMail Remote Code Execution via Unauthenticated Arbitrary File Upload | Critical

    From Honeypots to Active Directory Tripwires

    January 9, 2026
    Traditional deception tools promised high signal but failed at scale. This page explores how NodeZero® Active Directory Tripwires transform deception into a practical, enterprise-ready detection strategy—using real attacker behavior to deliver early, high-fidelity alerts where identity attacks matter most.

    The Ni8mare Test: n8n RCE Under the Microscope (CVE-2026-21858)

    CVE-2026-21858, the so-called “Ni8mare” n8n RCE, drew significant attention—but real-world impact appears limited. Horizon3 breaks down the technical prerequisites, observed exposure, and why most organizations are unlikely to be affected.

    CVE-2025-14847

    January 6, 2026
    MongoDB Server Uninitialized Heap Memory Disclosure (MongoBleed) | Active Exploitation

    CVE-2025-14733

    January 5, 2026
    WatchGuard Fireware OS VPN Vulnerability | Active Exploitation

    CVE-2025-14611

    December 19, 2025
    React Server Components RCE | Rapid Response

    How Horizon3 is Supporting the DoW Cybersecurity Risk Management Construct (CSRMC)

    December 17, 2025
    The DoW’s new Cybersecurity Risk Management Construct demands continuous, evidence-driven security. Learn how Horizon3’s NodeZero delivers real-time, attacker-validated proof to support mission resilience.

    UPDATED: CVE-2025-57819, CVE-2025-66039, CVE-2025-61675, CVE-2025-61678

    December 11, 2025
    Sangoma FreePBX Authentication Bypass and Remote Code Execution Vulnerabilities