Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Horizon3.ai expands NodeZero with automated web application attack path testing

Дата публикации: 31-07-2026 08:06:59

Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure. Web applications have never been more exposed or more critical to secure. The rapid deployment of “vibe-coded” applications built with generative AI has introduced a wave of systems riddled with exploitable flaws. At the same time, threat actors are … More →
The post Horizon3.ai expands NodeZero with automated web application attack path testing appeared first on Help Net Security.


Основное содержимое страницы с новостью.

Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure.

Horizon3.ai NodeZero WebApp Pentesting

Web applications have never been more exposed or more critical to secure. The rapid deployment of “vibe-coded” applications built with generative AI has introduced a wave of systems riddled with exploitable flaws. At the same time, threat actors are using AI to rapidly find and weaponize those weaknesses faster than defenders can patch them.

Traditional approaches that test web applications in isolation fall short because a web app is rarely the final objective, but instead the front door into the business. Once inside, attackers live off the land. They steal credentials, move laterally across the network, pivot into cloud environments, and reach the sensitive data that matters to the business.

NodeZero WebApp Pentesting closes the gap by delivering production-safe autonomous testing that spans web applications, infrastructure, cloud, data, and identity. It proves what is actually exploitable, quantifies the business consequence of each attack path, and maps those paths to the tactics of known threat actors, enabling companies to accurately prioritize and urgently fix vulnerabilities that matter.

“Legacy web application security tools are notoriously noisy. They flood teams with theoretical findings that lack context or business impact,” said Snehal Antani, CEO of Horizon3.

“The first generation of AI-driven web app pentesting performed well in cyber ranges, Capture the Flag (CTF) labs, and on bug-bounty leaderboards, but it wasn’t built to run safely against real enterprise production systems. Until now, no technology could chain vulnerabilities across application, infrastructure, cloud, and identity at scale. That’s where NodeZero is different. We built the World’s Best AI Hacker by running hundreds of thousands of production-safe tests against the largest, most sensitive networks in the world. With each test the system gets smarter, and that same engine now operates end-to-end from the web app all the way to business impact,” Antani continued.

NodeZero WebApp Pentesting delivers:

  • Continuous, autonomous testing of pre-production and production applications, using the same production safe engine that already powers NodeZero’s internal, external, and cloud pentesting.
  • Full attack-path chaining that demonstrates how weaknesses such as SQL injection and broken access control can escalate into host compromise, domain control, or data exposure.
  • Evidence of exploitability and business risk to accurately prioritize and urgently remediate, versus the legacy approach that is noisy, theoretical risk.
  • Coverage of the OWASP Top 10, complex access-control failures that traditional scanners routinely miss, and the credential-based attack techniques that mirror how modern adversaries actually operate.

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Novee brings continuous AI pentesting to mobile apps06.6630-07-2026
2Dropzone AI turns threat hunting into a routine SOC operation06.9630-07-2026
3PortSwigger introduces Burp AT for agentic AI security testing07.3430-07-2026
4Stairwell launches Backstory, pioneering agentic investigation for malware blast radius08.4429-07-2026
5Traefik Labs introduces Distro Zero secure runtime for API and AI gateways08.9831-07-2026
6Jscrambler launches Unified Client-Side Security Platform012.1430-07-2026
7Orca Security secures AI-built and developer-created applications012.1430-07-2026
8AttackIQ targets CTEM execution with AVA Agentic OS07.1331-07-2026
9Global Cyber Conference 20260702-07-2026
10Webinar: The IT Leader’s Guide to AI Governance08.815-04-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 8.44. Источник: www.helpnetsecurity.com.