ZeroHour
Story · 1 source · 1 articlefirst updated ()

AI compresses discovery-to-exploitation window; vendors push CTEM and attacker-based validation, with Horizon3-CrowdStrike integration reported at Fal.Con 2026

infoIndustryimportance 15
What's new: First merged summary for this story (no prior baseline). Newest development: Horizon3's Fal.Con 2026 announcements (Project QuiltWorks membership, NodeZero data into Falcon Next-Gen SIEM, Fusion SOAR 1-Click Verify trigger) reported 2026-09-04T17:46:19Z, one day after the sponsored CTEM explainer published 2026-09-03T15:00:00Z.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Two vendor-published reports (a sponsored Register piece and Horizon3's own Fal.Con 2026 recap) argue AI-driven vulnerability discovery is outpacing CVE/CVSS-based triage and manual patching, promoting Gartner's Continuous Threat Exposure Management (CTEM)…

A sponsored article in The Register (2026-09-03) and Horizon3.ai's Fal.Con 2026 recap (2026-09-04) converge on the claim that AI is accelerating vulnerability discovery and shrinking the time to exploitation, overwhelming traditional CVE triage. The sponsored piece cites surging CVE volumes, Microsoft patch cycles exceeding 500 fixes, an NVD backlog, and a Commerce Department report critical of NVD management that suggested dropping CVSS; it outlines Gartner's five CTEM steps (scoping, discovery, prioritization, validation, mobilization) and describes NodeZero as performing chain-of-attack penetration testing with attacker-style lateral pivoting, using a deterministic machine learning expert system rather than general LLMs, with generative AI confined to scoped tasks via AWS Bedrock. Horizon3's recap frames the show's central themes as 'vulnerable does not mean exploitable' and continuous self-attack ('hack, fix, verify, repeat'), announces Horizon3's membership in CrowdStrike's Project QuiltWorks with NodeZero exploitability intelligence feeding Falcon Next-Gen SIEM and Falcon Fusion SOAR able to trigger NodeZero 1-Click Verify to confirm remediated attack paths are closed, reports 1,200+ NodeZero demos run at the show, and notes CrowdStrike CEO George Kurtz's keynote emphasizing AI red teaming and offense-informing-defense. Caveats: both sources are promotional, all figures are as reported by the vendors with no independent confirmation, no CVE identifiers or product versions are provided, and the two reports do not directly conflict on any stated fact.

  • Sources: The Register sponsored article (2026-09-03T15:00:00Z) and Horizon3.ai's own Fal.Con 2026 recap (2026-09-04T17:46:19Z); all claims are vendor-reported.
  • Per the sponsored piece: Microsoft patch cycles exceed 500 fixes; an NVD backlog exists; a Commerce Department report criticized NVD management and suggested dropping CVSS.
  • Gartner's CTEM framework as described: scoping, discovery, prioritization, validation, and mobilization.
  • Horizon3 says NodeZero performs chain-of-attack penetration testing with attacker-style lateral pivoting, uses a deterministic machine learning expert system rather than general LLMs, and limits generative AI to scoped tasks via AWS…
  • At Fal.Con 2026, Horizon3 announced it joined CrowdStrike's Project QuiltWorks; NodeZero exploitability intelligence flows into Falcon Next-Gen SIEM, and Falcon Fusion SOAR can trigger NodeZero 1-Click Verify to confirm remediated attack…
  • Horizon3 reports running 1,200+ NodeZero demos at Fal.Con 2026; CrowdStrike CEO George Kurtz's keynote emphasized AI red teaming and offense-informing-defense.
  • Recurring vendor framing: 'vulnerable does not mean exploitable' and continuous self-attack (hack, fix, verify, repeat).
  • No CVE identifiers, product versions, or independently verified dates or counts appear in either report.

Coverage timeline

  1. · 12d ago
    The Register · Security· 15
    Drowning in CVEs and thirsty for answers? Try CTEM

    Sponsored Register piece argues traditional vulnerability management cannot scale with CVE volume and promotes Continuous Threat Exposure Management via Horizon3's NodeZero.