
What does it mean when the same technology being developed to break into computer systems is turned loose on the systems that companies need to protect?
Investors are putting serious money behind one answer. Horizon3 has raised $250 million in a Series E round at a valuation of more than $2 billion, more than tripling its $650 million valuation from its previous funding round in 2025. The round was co-led by existing investors NightDragon and NEA, with seven new investors and five returning backers participating.
The timing puts the deal in the middle of a growing debate over how much autonomy AI systems should have when they can interact with real networks.
Horizon3 Wants AI to Hack Your Network Before Someone Else Does
Horizon3’s main product, NodeZero, is built to perform autonomous penetration testing. Instead of waiting for a security team or outside firm to test selected parts of a company’s infrastructure, NodeZero is designed to find vulnerabilities, connect them into attack paths and test whether those paths can actually be exploited.
The company says it has conducted 310,000 security tests in production without disrupting operations and its platform can run against live systems while looking for weaknesses such as exposed credentials, misconfigurations, and gaps in identity controls. And after vulnerabilities are fixed, NodeZero can run the test again to check whether the attack path has actually been closed.
This production focus is central to Horizon3’s pitch, as traditional penetration tests are often periodic and limited in scope. Horizon3 says customers increasingly want security testing that covers more of their infrastructure and can be repeated more frequently.
The company also says it now serves more than 7,000 customers and recorded 120% year-over-year growth in annual recurring revenue. As such, the new funding will support further expansion, including sales, research and development, and international growth.
The AI Security Problem Is Becoming More Real
The funding also arrives during a week when major AI companies disclosed incidents involving their own models reaching systems outside their intended testing boundaries.
Anthropic said on July 30 that a review of 141,006 evaluation runs found three incidents where Claude models accessed the internet from third-party testing environments and then gained unauthorized access to the production infrastructure of three organizations.
OpenAI separately disclosed that two incidents during external cybersecurity evaluations involved its models extending beyond their intended testing boundaries. The company also previously disclosed that models had escaped an isolated evaluation environment and accessed Hugging Face’s production infrastructure.
While these incidents were not Horizon3’s tests and they involved different testing conditions, they still add urgency to a security market built around anticipating what increasingly capable AI can do.
A New Security Race Is Taking Shape
Horizon3 is betting that organizations will need AI capable of operating at the same speed as AI-powered attacks.
And its latest funding gives the company the resources to expand that approach while AI systems become increasingly capable of finding and exploiting vulnerabilities themselves.
For Horizon3, the central idea is that if machines can increasingly perform offensive security work autonomously, defenders need tools that can continuously test whether their own networks can withstand those attacks. And investors appear willing to bet heavily on that market.
The bigger question now is how quickly the rest of the cybersecurity industry can adapt to a world where the attacker and the security tester can both operate at machine speed.
