Security Practitioner
SEARCH
CATEGORIES
TAGS
Webinar: External Autonomous Pentesting
With the announcement of the addition of external penetration testing capabilities to NodeZero, Horizon3.ai is hosting a webinar to introduce this enhancement to our autonomous penetration testing platform. This extension of NodeZero’s capabilities makes Horizon3.ai the first cybersecurity company to offer both internal and external penetration testing in one self-service platform. Join Naveen Sunkavally, Horizon3.ai’s…
Horizon3.ai Adds NodeZero App for Splunk on Splunkbase
June 23, 2022
Horizon3.ai adds NodeZero app to Splunkbase to improve the effectiveness of your Splunk deployments and ensure you’re logging the right data.
Tech Talk: The Attackers Journey Pt. 4
This journey's 4th installment is now up! As usual, this series stars up-in-coming ethical hacker Noah King. He's joined this time by Horizon3.ai Director of Customer Success, Monti Knode, and Senior Offensive Security Consultant from our alliance partner Echelon Risk + Cyber, James Stahl. During this Tech Talk you'll learn all about NTLM Relay.
The Wartime Security Mindset w/ Snehal Antani
Snehal Antani, CEO and Co-founder of Horizon3.ai, presented The Wartime Security Mindset: the evolution of attack at a briefing at the SOFIC Conference in conjunction with our alliance partner Carahsoft.
Horizon3.ai Expands NodeZero to Include External Autonomous Pentesting
June 1, 2022
NodeZero is the first autonomous penetration testing platform to offer both internal and external pentesting in one self-service platform.
VMware Authentication Bypass Vulnerability (CVE-2022-22972) Technical Deep Dive
May 26, 2022
VMware recently patched a critical authentication bypass vulnerability in their VMware Workspace ONE Access, Identity Manager and vRealize Automation products (CVE-2022-22972). This vulnerability allows an attacker to login as any known local user.
Log4Shell RCE Vulnerability in Apache Log4j: The Gift No One Wished For
May 16, 2022
The Log4Shell RCE vulnerability in Apache Log4j, CVE-2021-44228, dates to 2013 when Log4j 2.0-beta9 was released. An analysis of our pentesting data using NodeZero identified and provided proof of exploit for over 105 unique instances of the CVE within our customers’ environments.
Tech Talk: The Attackers Journey Pt. 3
Noah King, Brad Hong, and Jake Murphy were back at it again with this third installment of 'The Attackers Journey'. This series has focused on Noah King on his journey to become an ethical hacker. Pt. 3 was no different, with a focus on Server-Side Request Forgery!
Horizon3.ai Researchers Able to Create Exploit for Critical F5 BIG-IP Flaw
May 10, 2022
It took just two days for a pair of researchers from Horizon3.ai to discover exploits for the new F5 BIG-IP vulnerability, and have called for devices to be immediately updated to protect against bad actors.
F5 iControl REST Endpoint Authentication Bypass Technical Deep Dive
May 9, 2022
F5 recently patched a critical vulnerability in their BIG-IP iControl REST endpoint CVE-2022-1388. This vulnerability particularly worrisome for users because it is simple to exploit and provides an attacker with a method to execute arbitrary system commands.