cd /news/ai-products/horizon3-expands-nodezero-with-webap… · home topics ai-products article
[ARTICLE · art-81762] src=letsdatascience.com ↗ pub= topic=ai-products verified=true sentiment=· neutral

Horizon3 Expands NodeZero With WebApp Pentesting

Horizon3 announced on July 29 that its NodeZero platform now includes AI-powered web-application pentesting, enabling continuous testing of pre-production and production applications and chaining application flaws into broader infrastructure, cloud, identity, and data attack paths. The company reports that 95 customers, including Fortune 10 enterprises, tested the capability during early access across hundreds of production applications, though these beta results are vendor-reported and not independently benchmarked. The product covers the OWASP Top 10 and aims to demonstrate exploitability and business impact for prioritized remediation.

read3 min views1 publishedJul 31, 2026
Horizon3 Expands NodeZero With WebApp Pentesting
Image: Letsdatascience (auto-discovered)

Horizon3 announced on July 29 that NodeZero can now test web applications and chain application flaws into broader infrastructure, cloud, identity and data attack paths. The company says 95 customers tested the capability during early access across hundreds of production applications; those beta results are vendor-reported rather than an independent benchmark.

Horizon3 announced on July 29 that its NodeZero platform now includes AI-powered web-application pentesting. The company says the capability can test pre-production and production applications, then connect application weaknesses with credential theft, host compromise, lateral movement, cloud access and sensitive-data exposure.

The product extends NodeZero beyond testing web findings in isolation. Its stated goal is to show whether a weakness can become part of an exploitable path across applications, infrastructure, cloud, data and identity.

What the product is designed to test

Horizon3 says NodeZero WebApp Pentesting covers the OWASP Top 10, including SQL injection and broken access control, as well as credential-based techniques. The platform is intended to run continuously and produce evidence of exploitability and business impact so teams can prioritize findings that lead to a demonstrated attack path.

The accompanying factsheet describes coverage for authenticated and unauthenticated applications, attack-path chaining and verification after remediation. These are product capabilities described by Horizon3, not the result of an independent comparative evaluation.

Help Net Security independently reported the July 31 product expansion and summarized the same focus on web apps as an entry point into cloud, identity and infrastructure systems.

Evidence and operational limits

Horizon3 says 95 customers, including Fortune 10 enterprises, used the capability during early access to test hundreds of production web applications. It also reports that one major social-media company found a broken-access-control flaw that human reviewers had missed. The company did not identify that customer or publish enough detail for outsiders to reproduce the result, so the example should be treated as vendor-reported evidence.

For security teams, the relevant change is the attempt to join application testing with the rest of an environment rather than returning a standalone list of web findings. Any production use still requires explicit authorization, tight scope, test accounts, traffic and rate controls, logging, rollback plans and review of exploit evidence. Autonomous testing can add continuous validation, but it does not by itself replace independent penetration testing, secure code review or compliance-specific assessment.

Key Points #

  • 1NodeZero now tests web applications and chains application flaws into infrastructure, cloud, identity and data attack paths.
  • 2Horizon3 says the capability covers the OWASP Top 10 and supports continuous testing of pre-production and production applications.
  • 3The company reports a 95-customer early-access program, but its beta outcomes have not been independently benchmarked.

Scoring Rationale #

The launch materially broadens an autonomous security-testing platform into web-application attack paths and is operationally relevant to security teams, but the performance evidence remains vendor-reported and lacks an independent benchmark.

Sources #

Primary source and supporting public references used for this report.

Practice with real Telecom & ISP data

90 SQL & Python problems · 15 industry datasets

[Active Residential CustomersEasy](/problems/sql/active-residential-customers)

[Unlimited Fiber Plans 500Mbps+Medium](/problems/sql/unlimited-fiber-plans-above-500mbps)

[Customer Churn Risk AssessmentHard](/problems/sql/customer-churn-risk-assessment)

250 free problems · No credit card

See all Telecom & ISP problems

── more in #ai-products 4 stories · sorted by recency
── more on @horizon3 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/horizon3-expands-nod…] indexed:0 read:3min 2026-07-31 ·