New at Horizon3

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-50751

CVE-2026-50751 is an authentication bypass vulnerability affecting Check Point Security Gateway VPN services. Check Point has confirmed active exploitation against vulnerable deployments.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-20253

CVE-2026-20253 is a critical unauthenticated arbitrary file write vulnerability affecting Splunk Enterprise. The flaw may allow attackers to create or truncate files and potentially achieve remote code execution.
Read More →

SEARCH

CATEGORIES

TAGS

SEARCH

    AI Has Ideas. sqlmap Has Receipts.

    May 29, 2026
    AI can identify potential SQL injection opportunities, but deterministic validation is what builds trust. Learn how NodeZero® combines LLM-guided discovery with sqlmap to deliver high-confidence findings.

    Third-Party Risk Management

    May 27, 2026
    NodeZero for TPRM: NodeZero proactively secures your supply chain by replacing assumptions with proof. It empowers you to find, fix, and validate third-party risks before they disrupt your business.

    CVE-2026-9082

    May 21, 2026
    CVE-2026-9082 is a highly critical SQL injection vulnerability in Drupal core affecting PostgreSQL-backed deployments. The flaw allows unauthenticated attackers to execute arbitrary SQL queries and potentially compromise affected environments.

    CVE-2026-23734

    May 21, 2026
    CVE-2026-23734 is a critical path traversal vulnerability affecting XWiki’s xwiki-commons-classloader-api component. The flaw may allow unauthenticated attackers to access sensitive configuration files through crafted ssx and jsx endpoint requests.

    CVE-2026-44578

    May 20, 2026
    CVE-2026-44578 is a high-severity server-side request forgery vulnerability affecting self-hosted Next.js applications using the built-in Node.js server.

    The 2026 Buyer’s Guide to Penetration Testing

    May 20, 2026
    Most pentesting evaluations focus on compliance. This guide explains how to assess modern testing programs based on exploitability, coverage, attack-path validation, and risk reduction.

    From Point-in-Time Testing to Continuous Security Validation

    May 18, 2026
    Learn how Mid Devon District Council moved beyond annual pentests to continuously validate exploitable risk, strengthen identity security, and accelerate remediation with autonomous pentesting.

    Strengthen Supply Chain Security for CMMC

    May 18, 2026
    This whitepaper explains how organizations can move beyond CMMC compliance to continuously validate real-world security across the supply chain.

    You’re Only as Secure as Your Last Evaluation

    May 18, 2026
    CMMC is shifting cybersecurity from periodic compliance to continuous validation across the Defense Industrial Base supply chain.

    CVE-2026-0300

    May 15, 2026
    CVE-2026-0300 enables unauthenticated remote code execution in PAN-OS, posing a critical risk to enterprise and government networks.