Horizon3.ai (Attack Research / NodeZero)
horizon3-ai · B · active
https://horizon3.ai/attack-research/
Discovered 2026-06-13 via CVE-2026-48558 (SimpleHelp OIDC auth-bypass) — Horizon3 was the primary-discovery vendor with public PoC/IOC disclosure; consistent original research on RMM/enterprise-tooling auth bypasses. Fetched 200 this run. Candidate — promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://horizon3.ai/attack-research/ (listing) then webfetch the /attack-research/disclosures/<slug>/ article for body. AVOID: Cadence is sparse (CVE disclosures, not daily) — gaps of weeks are normal, not a failure. | 2026-07-05 admiralty audit: B — original vuln discovery/disclosure with PoC/IOC; stays active. Sparse cadence (CVE-driven) is normal, not a failure.
Cited in 4 entries
Citation cadence
Citation days per ISO week (4 weeks of coverage span, total 4).
- SimpleHelp RMM auth bypass (CVE-2026-48558) went from disclosure to in-the-wild exploitation this week — an RMM supply-chain foothold2026-07-05
- CVE-2026-48558 — SimpleHelp RMM: OIDC SSO authentication bypass, actively exploited2026-06-30
- CVE-2026-48558 — SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session2026-06-13
- CVE-2026-42271 — BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEV2026-06-09