ZeroHour
Story · 1 source · 1 articlefirst updated ()

CTEM pitched as the answer to CVE overload and AI-speed exploitation; Horizon3 joins CrowdStrike's Project QuiltWorks at Fal.Con 2026

infoIndustryimportance 15
What's new: First merged summary — no prior baseline to diff against. Within the Sept 2–4, 2026 window the story escalated from strategy argument (Horizon3's outcomes-over-stages post, Sept 2) to market-pressure framing (sponsored Register piece on CVE overload and NVD/CVSS problems, Sept 3) to the first concrete product and integration news at Fal.Con 2026 (Sept 4): Horizon3 joined CrowdStrike's Project…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Two Horizon3.ai posts and a sponsored Register article (Sept 2–4, 2026) converge on one pitch: continuous threat exposure management (CTEM) should be measured by continuously reduced attacker-reachable exposure — not stage-mapping or CVSS-only triage — as AI…

Horizon3.ai (2026-09-02) argues CTEM is about the outcome, not the stages: programs should demonstrate continuously reducing attacker-reachable exposure, with validation and verification — not visibility or closed tickets — proving attack paths are actually broken. It describes its motion as Discover, Validate, Prioritize, Remediate, Verify, Repeat, claims validation-based prioritization can shrink backlogs versus severity-score-only approaches, and says remediation must be retested because drift can reintroduce eliminated exposures. Both Horizon3's post and a sponsored article in The Register (2026-09-03) consistently list Gartner's five CTEM stages — scoping, discovery, prioritization, validation, and mobilization. The Register piece frames the pressure: surging CVE volume, CVSS triage shortcomings, an NVD backlog, and AI-driven discovery creating an asymmetric vulnerability cycle; it cites Microsoft patch cycles exceeding 500 fixes and a Commerce Department report critical of NVD management that it says suggested dropping CVSS. It presents Horizon3's NodeZero — chain-of-attack penetration testing with attacker-style lateral pivoting — as the validation mechanism, noting Horizon3's claim that NodeZero uses a deterministic machine learning expert system rather than general LLMs, with generative AI confined to scoped tasks via AWS Bedrock. The window's hard news came in Horizon3's Fal.Con 2026 recap (2026-09-04): Horizon3 joined CrowdStrike's Project QuiltWorks, with NodeZero exploitability intelligence flowing into Falcon Next-Gen SIEM and Falcon Fusion SOAR workflows able to trigger NodeZero 1-Click Verify to confirm remediated attack paths are closed. Horizon3 reported running over 1,200 NodeZero demos at the show, and its recap cites CrowdStrike CEO George Kurtz's keynote themes of AI red teaming and offense-informing-defense. Recurring framing across the pieces: 'vulnerable does not mean exploitable' and continuous self-attack — hack, fix, verify, repeat. No factual conflicts were found among the three reports; the difference is emphasis — Horizon3 argues against mapping technology to Gartner's stages, while the Register piece outlines those stages as a framework. Note that all three pieces are Horizon3-authored or Horizon3-sponsored, so product capabilities (NodeZero's expert-system architecture, Bedrock usage, 1,200+ demos) are vendor statements.

  • Gartner's CTEM framework consists of five stages — scoping, discovery, prioritization, validation, and mobilization — listed consistently in both Horizon3's Sept 2, 2026 post and The Register's sponsored article.
  • Horizon3 (2026-09-02) argues CTEM should be measured by one outcome: continuously reducing attacker-reachable exposure, not by mapping technology to Gartner's stages.
  • Horizon3 says validation and verification — not visibility or closed tickets — provide the evidence that attack paths are broken, via a Discover, Validate, Prioritize, Remediate, Verify, Repeat motion.
  • Horizon3 claims validation-based prioritization can shrink remediation backlogs versus severity-score-only approaches, and that remediation should be retested because drift can reintroduce eliminated exposures.
  • The sponsored Register article (2026-09-03) argues traditional vulnerability management cannot scale with surging CVE volume, citing CVSS triage shortcomings and an NVD backlog.
  • The Register piece cites Microsoft patch cycles exceeding 500 fixes as overwhelming manual prioritization.
  • The Register piece says a Commerce Department report criticized NVD management and suggested dropping CVSS.
  • Horizon3 says NodeZero performs chain-of-attack penetration testing with attacker-style lateral pivoting, validating exploitable attack paths with evidence (vendor claim).

Coverage timeline

  1. · 13d ago
    Horizon3.ai· 12
    CTEM Is Not About the Stages. It’s About the Outcome.

    Horizon3 argues CTEM programs should measure continuously reduced exposure rather than mapping technologies to Gartner's five stages.