Horizon3.ai (Attack Research / NodeZero)
horizon3-ai · B · active
https://horizon3.ai/attack-research/
Discovered 2026-06-13 via CVE-2026-48558 (SimpleHelp OIDC auth-bypass); Horizon3 was the primary-discovery vendor with public PoC/IOC disclosure; consistent original research on RMM/enterprise-tooling auth bypasses. Fetched 200 this run. Candidate; promote to active after 3 runs with content contribution. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://horizon3.ai/attack-research/ (listing) then webfetch the /attack-research/disclosures/<slug>/ article for body. AVOID: Cadence is sparse (CVE disclosures, not daily); gaps of weeks are normal, not a failure. | 2026-07-05 admiralty audit: B, original vuln discovery/disclosure with PoC/IOC; stays active. Sparse cadence (CVE-driven) is normal, not a failure.
Cited in 4 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 4).
- CVE-2026-9586, Sangoma Switchvox: an unauthenticated XML phone-notification endpoint reaches PostgreSQL COPY TO PROGRAM, and honeypots caught exploitation nearly seven weeks after the patch shipped2026-09-03
- CVE-2026-48558, SimpleHelp RMM: OIDC SSO authentication bypass, actively exploited2026-06-30
- CVE-2026-48558, SimpleHelp RMM: unauthenticated OIDC authentication bypass yields a full technician session2026-06-13
- CVE-2026-42271, BerriAI LiteLLM: low-privilege command injection to host RCE, added to CISA KEV2026-06-09