Tomorrow: Join Keith Poyser, VP EMEA, and Frédéric Nakhlé, Solution Architect Director, EMEA, for a practical look at how to measure EDR effectiveness using proof over perception. Discover how safe adversary emulation in production can reveal the real behaviors your tools detect, prevent, or miss altogether. You’ll walk away knowing how to: 💡 Identify hidden #EDR blind spots that attackers exploit every day. 💡 Understand the business impact of a single misconfiguration. 💡 Measure detection and prevention coverage with forensic proof. 💡 Prioritize remediation to maximize EDR ROI and resilience. Seats are limited — register now: https://lnkd.in/gQ-z9cas. #NodeZero #OffensiveSecurity #EndpointSecurity
Horizon3.ai
Computer and Network Security
San Francisco, CA 23,544 followers
Improve your security posture and reduce risk with the NodeZero® platform.
About us
The NodeZero® platform empowers your organization to continuously find, fix, and verify your exploitable attack surface. Reduce your security risk by autonomously finding weaknesses in your network, knowing how to prioritize and fix them, and immediately verifying that your fixes work. NodeZero delivers production-safe autonomous pentests and other key assessment operations that scale across your largest internal, external, cloud, and hybrid cloud environments. No required agents, no code to write, and no consultants to hire. We are a fusion of former U.S. Special Operations cyber operators, startup engineers, and formerly frustrated cybersecurity practitioners. We're committed to helping solve our common security problems: ineffective security tools, false positives resulting in alert fatigue, blind spots, "checkbox” security culture, cybersecurity skills shortage, and the long lead time and expense of hiring outside consultants.
- Website
-
https://www.horizon3.ai
External link for Horizon3.ai
- Industry
- Computer and Network Security
- Company size
- 201-500 employees
- Headquarters
- San Francisco, CA
- Type
- Privately Held
- Founded
- 2019
- Specialties
- cybersecurity, penetrationtesting, AI, purpleteams, infosec, machinelearning, datasecurity, autonomouspentesting, attack surface management, red teams, offensive security, pentesting, security validation, security verification, and exploitable vulnerabilities
Products
NodeZero
Penetration Testing Tools
Continuously find, fix, and verify your exploitable attack surface with the NodeZero® platform. Reduce security risk with scalable, production-safe autonomous pentests, N-day testing, password audits, phishing impact tests, and more.
Locations
-
Primary
Get directions
San Francisco, CA 94118, US
-
Get directions
Durham, NC 27701, US
Employees at Horizon3.ai
Updates
-
Big news from Black Hat MEA: Horizon3.ai and CyberKnight have officially joined forces. 🤝 Demand for automated offensive security is surging across the region, and this partnership brings #NodeZero’s autonomous pentesting capabilities to enterprises that need continuous validation — not periodic assessments. With CyberKnight’s strong regional presence and trusted channel ecosystem, organizations across MENA can now integrate attacker-centric testing into their cloud, AI, and modernization programs and finally answer a critical question: Are we actually secure? Learn more about this partnership at https://lnkd.in/gjcxf9cW #BlackHatMEA #OffensiveSecurity #pentesting
-
The React Server Components vulnerability has dominated security discussions this week. CVE-2025-55182, also known as React2Shell, is a maximum-severity unauthenticated RCE affecting React 19, Next.js, and several related frameworks. As soon as details about CVE-2025-55182 (React2Shell) emerged, our team rapidly validated exposure across all customer environments. We immediately notified every impacted customer with guidance and mitigation steps, ensuring they were protected before public exploitation began. Our rapid response and verification workflows, powered by NodeZero, allowed us to move quickly and with confidence. If you need to upgrade, React patches are available in 19.0.1, 19.1.2, and 19.2.1. Next.js users should move to the patched releases, including 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, and 16.0.7. Before and after patching, use the new Rapid Response test for CVE-2025-55182 to confirm whether your instances are actually exploitable and to validate that your fixes are effective. Visit https://lnkd.in/gUk9PaGT to understand the issue and verify real exposure in minutes. More analysis from our research team is coming soon.
-
-
Hundreds of organizations have used #NodeZero to run over 170,000 autonomous pentests across EDR-protected environments. The result? Real data to validate coverage, tune performance, and benchmark vendors before renewal. See what your EDR is missing, and prove ROI with evidence, not assumptions. 🔗 Run your EDR Healthcheck: https://lnkd.in/g--XVzre #EndpointSecurity #pentesting #infosec
-
-
Every organization has exposed data. The question is: does it matter? 🤔 Advanced Data Pilfering (ADP) uses GenAI reasoning to classify data risk, revealing which exposures lead to IP theft, operational disruption, or compliance impact. ADP turns DSPM theory into proof-driven prioritization. Learn how this fits into Risk-Based Vulnerability Management at https://lnkd.in/gGQZrEmY #RBVM #OffensiveSecurity #NodeZero
-
-
Threat Informed Perspectives helps organizations truly understand risk from an attacker’s viewpoint, then measurably reduce the blast radius over time. Security teams gain continuous, evidence-based visibility into how their controls perform in the real world, enabling faster prioritization, smarter investments, and provable resilience. At Horizon3.ai, we’re committed to giving defenders the advantage of clarity, speed, and certainty.
“If an attacker gets in, how bad is it, and are we getting better at containing the damage?” That question plagues CIO’s and CISO’s, at least it kept me up at night when I was in the seat. That’s why I’m excited to announce Threat Informed Perspectives (TIP), a new capability available to all NodeZero customers TIP is a simple idea with big implications: Assume breach from different footholds inside your environment, measure the blast radius, and use our find–fix–verify loop to shrink that blast radius over time “How much damage could an attacker cause if they gained access to the DMZ?” “What about insider threat with customer support credentials?” “Is my EDR getting better at detection and response?” These aren’t point-in-time questions, you want to understand how the answers to these questions change over time. Are you getting better? Did you suddenly regress? Why? What are the consequences (critical impacts) of a breach from that initial access point? Within NodeZero: - you can create different perspectives that represent risks you’re concerned about - schedule pentests to give you the attackers perspective from that initial access point. (With no creds, with specific roles iniected, etc) - and report on your results over time, including: 1. Exploitable vulnerabilities accurately prioritized based on threat actor pressure and business impact 2. Blast radius – number and criticality of assets reachable from that foothold 3. Time-to-impact – how quickly an attacker can achieve meaningful objectives 4. Control effectiveness – where segmentation, identity, and detection actually hold the line — and where they don’t 5. Improvements over time – how each find–fix–verify cycle shrinks blast radius and lengthens the path to impact CIO’s and CISO’s can then shift from activity-based security to outcome-based security: - From “We ran a pentest” → to “We proved that an attacker starting here can no longer reach those systems.” - From “We fixed 10,000 vulnerabilities” → to “We eliminated three high-consequence attack paths from our most likely footholds.” - From “We deployed tools” → to “We verified that identity, segmentation, and EDR actually contain real attacks.” For our partners - MSSP’s, GSI’s, etc - you can create a prebuilt set of perspectives as “campaigns” aligned to specific verticals like financial services or healthcare and create a repeatable vCISO advisory service powered by our insights over time Check it out: https://lnkd.in/gt3FDKeB #cybersecurity #infosec #ctem #vulnerabilitymanagement Horizon3.ai
-
Here’s a question from Graham Cluley, host of Smashing Security: “Let’s say I’m a normal company. I do an annual pentest, I get a PDF report, I put it in my drawer, and file it away. Are you suggesting that’s not enough?” The simple answer is no, not if you want to stay out of the news. 👀 In this Smashing Security episode, Horizon3.ai CEO Snehal Antani and Graham discuss how autonomous pentesting, attacker reasoning, and AI are transforming modern #cybersecurity. They cover: • Why the attacker’s perspective is the only one that matters • How #NodeZero emulates real attack chains — not just vulnerabilities • What happens when AI can reach domain admin in 77 seconds • Why “one misconfigured endpoint” is all it takes to take the keys to the kingdom. • How defenders can adopt continuous, precision defense to keep up 🎧 Listen to the whole conversation at https://lnkd.in/gNm5fUvh. #OffensiveSecurity #pentesting #infosec
-
-
We’re proud to be recognized as a Customers’ Choice in the October 2025 Gartner Peer Insights™ “Voice of the Customer”: Adversarial Exposure Validation report! 🏆 This recognition reflects the voices of verified end users who’ve shared their experiences with AEV technologies over the past 18 months — and we’re honored to see Horizon3.ai among the most highly rated vendors. 💡 Read the report to explore what customers are saying: https://lnkd.in/gzMDqWRj. #VoiceOfTheCustomer #CustomersChoice #OffensiveSecurity #NodeZero
-
-
Strong lineup for CIO+CISO X San Francisco 2025. Horizon3.ai is looking forward to engaging with industry leaders on the future of cybersecurity, AI, and resilience.
🔥 San Francisco. This is your 24 hour warning. Tomorrow, the Bay Area’s strongest CIO and CISO energy hits one room. No filler. No noise. Just the leaders who actually move the needle across AI, cyber, digital strategy, engineering, privacy and enterprise transformation. The speaker line up speaks for itself 🔊 Snehal Antani, Nish Malik, Emilee Tellez, Brian Yoon, Anastasia D., Raj S., Auston Davis, CISM, Tony Batalla, David Bridgman, Herman Brown, Jamie Knobles, Dave Bachechi, Christiana S., Kevin Kirkwood, Sagar Jain, Sathish Kuppuswamy CISSP, CISM, Navin Prakash, Jason Aloia, Umesh Jagannatha, Monisha Coelho, Kyle Johnson, Ph.D., Shivakumar Gopalakrishnan, Aman Grover, plus more shaping tomorrow’s intelligence. ⚡ Powering the day, our fantastic partners Veeam Software, Exabeam, Horizon3.ai, Freshworks, Ping Identity, Singtel, Sprinto, Absolute Security, HiddenLayer, Immersive, and more behind the scenes driving tomorrow’s innovation. If you are not in the room, here is what you will miss 🎯 ● AI that actually lands, not theory ● Cyber strategy from leaders who live the threat surface ● Identity and trust rebuilt for 2026 and beyond ● Governance shifts that will catch teams sleeping ● Engineering built for speed, resilience and uptime ● The CIO and CISO alliance tightening the organisation ● Leadership sharpened for high pressure decision making 📡 See tomorrow’s agenda CIO Track: https://lnkd.in/eV43kZjA CISO Track: https://lnkd.in/epsZUHEj 🌎 Explore upcoming Xseries gatherings across the US and Europe https://lnkd.in/eQYpK45t 🤝 Partner with us for future CIO and CISO leadership Xseries https://lnkd.in/eVydJsUr San Francisco, we are nearly live. 🔋 Loud voices. Big conviction. Real influence. 📣 See what happens when the right leaders share one room. #CIOCISOXSanFrancisco #CIO #CISO #AI #CyberSecurity #DigitalLeadership #SanFranciscoTech #Xseries #Xperiential #CXOSecrets #EDS
-
Most organizations still treat #pentesting as a point-in-time event. Teams run a test once or twice a year, collect a long list of findings, and hope that means security is improving. It rarely does. Without a structured way to plan tests, retest fixes, or compare results over time, CISOs can’t answer the question their board keeps asking: “Is our exposure shrinking?” Threat Informed Perspectives change that. By viewing your environment through attacker-aligned lenses and tracking results over time, #NodeZero transforms pentesting from snapshots into a measurable security program. See how continuous, threat informed pentesting actually works → https://lnkd.in/g-Ztxc6W #OffensiveSecurity #infosec
-