Horizon3 promotes NodeZero Federal and validation results
Horizon3.ai is promoting FedRAMP High NodeZero Federal and cites a Zerologon retest plus an automotive rollout of more than 230 sites.
Between September 22 and 25, 2026, Horizon3.ai published three marketing posts about its NodeZero autonomous security-validation platform. On September 22 it introduced NodeZero Federal, a FedRAMP High Authorized edition pitched as production-safe autonomous penetration testing that chains weak credentials, misconfigurations, and control gaps, with proof of exploitation, prioritized remediation, one-click retesting, and audit-ready evidence for Zero Trust and Active Directory programs; the factsheet disclosed no new vulnerability or incident. A September 23 post argued that annual penetration tests miss continuously probing nation-state attackers and described a modeled engagement based on Iranian tradecraft in which NodeZero found Zerologon (CVE-2020-1472) on a domain controller that was patched and re-validated in just over 24 hours. That post also said one deployment reduced 18,000 scanner findings to 21 verified exploitable paths, a GOAD benchmark reached full Active Directory compromise in 14 minutes, and NodeZero Federal is on the NSA CSfC Approved Products List and is the engine for the NSA Continuous Autonomous Penetration Testing program. On September 25 a customer story said a global automotive technology manufacturer replaced appliance-based testing that had taken about four days a week across more than 200 sites; NodeZero onboarded more than 190 of 230-plus sites, covered over 80,000 assets, cut comparable test runtime by about 50 percent, and tracked more than 1,200 remediation tickets with 250-plus confirmed fixes. The reports do not contradict one another.
- On 2026-09-22 Horizon3.ai published a factsheet for NodeZero Federal, the FedRAMP High Authorized edition of NodeZero, marketed as production-safe autonomous penetration testing that chains weak credentials, misconfigurations, and control…
- A 2026-09-23 post says a modeled engagement based on Iranian tradecraft found Zerologon (CVE-2020-1472) on a domain controller, which was patched and re-validated in just over 24 hours.
- The same post says one deployment reduced 18,000 scanner findings to 21 verified exploitable paths, and a GOAD benchmark showed full Active Directory compromise in 14 minutes.
- NodeZero Federal is described as FedRAMP High authorized, listed on the NSA CSfC Approved Products List, and used as the engine for the NSA Continuous Autonomous Penetration Testing program.
- A 2026-09-25 customer story says a global automotive technology manufacturer replaced appliance-based testing that took about four days a week across more than 200 sites.
- That rollout onboarded more than 190 of 230-plus sites, covered over 80,000 assets, cut comparable test runtime by about 50 percent, and tracked more than 1,200 remediation tickets with 250-plus confirmed fixes.
- The three Horizon3.ai reports do not contradict each other; all figures come from the vendor's own marketing.
Coverage timelineoldest first · each row is one article
- · 4d agoNodeZero Federal
Horizon3.ai· 18
Horizon3 offers NodeZero Federal, a FedRAMP High autonomous penetration-testing platform for federal agencies.
- · 3d agoFederal & Mission-Critical Security Validation
Horizon3.ai· 24
Horizon3 pitches continuous NodeZero validation for federal teams, arguing annual pentests miss fast identity attacks.
- · 1d agoTrading Maintenance for Momentum: Scaling Security Validation Across 230+ Sites
Horizon3.ai· 22
An automotive manufacturer adopted Horizon3 NodeZero to validate security across more than 230 sites.
Vulnerabilities in this storyAll →
- CVE-2020-14725.599%Unauthenticated Privilege Escalation (Zerologon) in Microsoft Netlogon Domain Controllerspublished · Microsoft Windows Server (when acting as a domain controller) KEV ransomware PoC