New at Horizon3

Resource Center

Welcome to our cybersecurity resource center where we uncover how malicious actors exploit weaknesses in systems, while going beyond the technical aspects and examining real-world perspectives across various industries.

LATEST VULNERABILITIES

Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-44825

CVE-2026-44825 is a hardcoded credentials vulnerability affecting Apache Solr Basic Authentication setup workflows. The flaw may allow attackers to gain administrative access to vulnerable SolrCloud deployments.
Read More →
Bomb Streamline Icon: https://streamlinehq.com

CVE-2026-42271 Chained with CVE-2026-48710

CVE-2026-27771 is a high-severity authentication bypass vulnerability affecting Gitea’s built-in package and container registry functionality. The flaw may allow unauthenticated attackers to retrieve private container images and package artifacts without valid credentials.
Read More →

WEBINAR REPLAY

SEARCH

CATEGORIES

TAGS

SEARCH

    Best Tools for Digital Threat Monitoring and Cyber Threat Visibility

    April 1, 2026
    Digital threat monitoring reveals attacker activity and exposure across your environment—but does it show what’s actually exploitable?

    CVE-2026-20131

    March 31, 2026
    CVE-2026-20131 allows unauthenticated remote code execution in Cisco FMC via insecure deserialization. Exploited in ransomware campaigns—patch immediately.

    CVE-2026-3055

    March 30, 2026
    CVE-2026-3055 is a critical Citrix NetScaler vulnerability allowing unauthenticated memory disclosure in SAML IdP configurations. Validate exposure and patch immediately.

    CVE-2026-20079

    March 24, 2026
    CVE-2026-20079 is a critical Cisco FMC authentication bypass vulnerability enabling remote attackers to gain root access. Learn how to validate and remediate exposure.

    When Conflict Extends Into Cyberspace: What Security Leaders Should Expect

    March 16, 2026
    Iranian cyber operators are increasingly targeting critical infrastructure and enterprise systems. Here’s what security leaders should expect and how to prepare.

    From Patch Tuesday to Pentest Wednesday®: A University’s Journey to Measure Blast Radius

    March 11, 2026
    A university moved beyond phishing click rates to measure real-world blast radius, validate domain compromise, and prove measurable risk reduction with Pentest Wednesday®.

    CVE-2026-20127

    March 5, 2026
    CVE-2026-20127 is a critical authentication bypass in Cisco Catalyst SD-WAN that allows remote attackers to gain administrative access to network infrastructure. Learn how to detect exposure and validate remediation using NodeZero Rapid Response.

    Preemptive Exposure Management Is the Goal. Autonomous Attack Validation Is How You Get There.

    March 4, 2026
    Reacting to cyberattacks has never been a winning strategy. Most organizations know this, yet many still find themselves responding after the fact, investigating incidents, explaining impact, and rebuilding trust with leadership. What’s changed is a growing recognition that risk must be reduced before attackers act, not measured after the damage is done. That’s the promise…

    When “Read-Only” Isn’t: K8s nodes/proxy GET to RCE

    February 27, 2026
    A Kubernetes service account with “read-only” nodes/proxy GET permission can execute arbitrary commands across pods via the kubelet API. This post breaks down how WebSocket behavior turns monitoring access into cluster-wide RCE—and how NodeZero detects it.
    Kubernetes nodes/proxy GET permission leading to kubelet remote code execution attack path

    How Do I Choose the Best Pentesting Solution for My Business?

    February 25, 2026
    Choosing a penetration testing solution isn’t a box-checking exercise. When the approach doesn't fit the need, teams often waste budget and time while walking away with a false sense of security. A clean pentest report might look reassuring, but it doesn’t automatically mean defenses are effective or that risk is actually being reduced. A better…