New capabilities deliver continuous, end-to-end attack-path validation across web apps, infrastructure, cloud, data, and identity – proving real business impact, not isolated findings
Horizon3 today announced the expansion of its NodeZero® platform with AI-powered web application pentesting capabilities. NodeZero, the world’s most experienced AI hacker, can now autonomously and safely test web applications the way real attackers operate, chaining vulnerabilities from application abuse through credential theft, lateral movement, cloud pivots, and sensitive data exposure.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260729113126/en/

Web applications have never been more exposed or more critical to secure. The rapid deployment of “vibe-coded” applications built with generative AI has introduced a wave of systems riddled with exploitable flaws. At the same time, threat actors are using AI to rapidly find and weaponize those weaknesses faster than defenders can patch them.
Traditional approaches that test web applications in isolation fall short because a web app is rarely the final objective, but instead the front door into the business. Once inside, attackers live off the land. They steal credentials, move laterally across the network, pivot into cloud environments, and reach the sensitive data that matters to the business.
NodeZero WebApp Pentesting closes the gap by delivering production-safe autonomous testing that spans web applications, infrastructure, cloud, data, and identity. It proves what is actually exploitable, quantifies the business consequence of each attack path, and maps those paths to the tactics of known threat actors, enabling companies to accurately prioritize and urgently fix vulnerabilities that matter.
"Legacy web application security tools are notoriously noisy. They flood teams with theoretical findings that lack context or business impact," said Snehal Antani, Co-Founder and CEO of Horizon3. "The first generation of AI-driven web app pentesting performed well in cyber ranges, Capture the Flag (CTF) labs, and on bug-bounty leaderboards, but it wasn't built to run safely against real enterprise production systems. Until now, no technology could chain vulnerabilities across application, infrastructure, cloud, and identity at scale. That's where NodeZero is different. We built the World's Best AI Hacker by running hundreds of thousands of production-safe tests against the largest, most sensitive networks in the world. With each test the system gets smarter, and that same engine now operates end-to-end from the web app all the way to business impact.”
NodeZero® WebApp Pentesting delivers:
- Continuous, autonomous testing of pre-production and production applications, using the same production safe engine that already powers NodeZero's internal, external, and cloud pentesting.
- Full attack-path chaining that demonstrates how weaknesses such as SQL injection and broken access control can escalate into host compromise, domain control, or data exposure.
- Evidence of exploitability and business risk to accurately prioritize and urgently remediate, versus the legacy approach that is noisy, theoretical risk.
- Coverage of the OWASP Top 10, complex access-control failures that traditional scanners routinely miss, and the credential-based attack techniques that mirror how modern adversaries actually operate.
Horizon3 initially made the new capabilities available through an Early Access program where 95 customers globally, including Fortune 10 enterprises, safely tested hundreds of production web applications. During the Beta, a major social media company discovered a broken access control flaw in a critical component that was missed by human reviewers, showcasing the power of using AI to comprehensively discover and exploit difficult-to-find vulnerabilities. Horizon3 will showcase the new solution live at Black Hat USA 2026, booth 4357. Learn more at Horizon3.ai.
About Horizon3
Horizon3, the AI-native proactive security company behind NodeZero, shifts the advantage from attackers to defenders by giving organizations the power to fight AI with AI. NodeZero, the World's Best AI Hacker, autonomously tests defenses at machine speed, safely finds and prioritizes exploitable attack paths, instantly verifies fixes and drives a continuous hack, fix, verify loop. More than 6,500 organizations, including the NSA, CISA, major healthcare providers and four of the Fortune 10, trust Horizon3 to prioritize what matters most, for security they can prove. Follow Horizon3 on LinkedIn and X.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260729113126/en/
Contacts
Media Contact
Stephen Gates
press@horizon3.ai
