Category: Attack Research

  • July 20, 2026
    Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut 
labore et dolore magna aliqua. Ut…
  • Attack path showing unauthorized VPN access through a vulnerable Check Point Security Gateway deployment

    June 16, 2026
    CVE-2026-50751 is an authentication bypass vulnerability affecting Check Point Security Gateway VPN services. Check Point has confirmed active exploitation against…
  • Attack path showing unauthenticated file creation and file overwrite activity against a vulnerable Splunk Enterprise deployment

    June 16, 2026
    CVE-2026-20253 is a critical unauthenticated arbitrary file write vulnerability affecting Splunk Enterprise. The flaw may allow attackers to create or…
  • Attack path showing unauthorized Technician account creation through vulnerable SimpleHelp OIDC authentication

    June 15, 2026
    CVE-2026-48558 is an authentication bypass vulnerability affecting SimpleHelp OIDC deployments. The flaw may allow attackers to create unauthorized Technician accounts…
  • Attack path showing unauthenticated remote code execution against a vulnerable Oracle PeopleSoft deployment

    June 12, 2026
    CVE-2026-35273 is a critical unauthenticated remote code execution vulnerability affecting Oracle PeopleSoft PeopleTools. Threat intelligence confirms active exploitation by ShinyHunters…
  • Security research illustrating CVE-2026-48558 authentication bypass affecting SimpleHelp OIDC deployments||||

    June 12, 2026
    Horizon3 details indicators of compromise, affected configurations, and mitigation guidance for CVE-2026-48558, a SimpleHelp OIDC authentication bypass vulnerability.
  • Attack path showing unauthenticated command execution against a vulnerable Ivanti Sentry appliance

    June 11, 2026
    CVE-2026-10520 is a critical pre-authenticated OS command injection vulnerability in Ivanti Sentry that allows remote attackers to execute arbitrary commands…
  • Horizon3.ai logo banner

    June 9, 2026
    New research reveals how to make AI-powered cyber defense safe, stable, and reliable for real-world deployment.
  • Visualization of CVE-2026-0257 affecting Palo Alto Networks PAN-OS GlobalProtect and enabling unauthorized VPN access

    June 5, 2026
    CVE-2026-0257 is a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect that allows unauthorized VPN access and is…
  • Attack path showing authentication to Apache Solr using hardcoded default credentials

    June 2, 2026
    CVE-2026-44825 is a hardcoded credentials vulnerability affecting Apache Solr Basic Authentication setup workflows. The flaw may allow attackers to gain…