DrochaidHorizon3.ai
NodeZero/Why now
The case for NodeZero

Why now

AI gave attackers machine speed. Match it with proof your defences hold — every day, not once a year.

AI has collapsed the time between a weakness existing and a breach happening. The tools you’ve bought were built for a slower world — and in Australia, your obligations just moved. Here’s what changed, and what to do about it.

Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner
The future of cyber warfare will run at machine speed – algorithm vs. algorithm – with humans by exception.
Snehal AntaniSnehal AntaniCEO and co-founder, Horizon3.ai
Machine speed is the ultimate disruptor
100×

more “manoeuvre decisions per minute” an algorithm-driven attack can make than the team defending against it.

By the time a defender has sifted the logs, triaged the alerts and won approval to act, the attack has already adapted and moved on.

Within five years that gap could reach 100,000× — fast enough to leave human-paced defence behind.

Horizon3.ai — Our security vision

AI handed attackers scale and speed.

In April 2026, Anthropic’s Project Glasswing revealed that an AI model had found thousands of zero-day vulnerabilities across every major operating system and browser — flaws that had survived decades of expert review. The lesson isn’t a new kind of vulnerability. It’s that the effort to find, weaponise and chain weaknesses has collapsed towards zero. What used to take a skilled team weeks now compresses into minutes.

Beyond the Mythos hype: what AI-driven vulnerability discovery actually changes

Weaponised faster

Raw findings become working exploits in near real time.

Barrier removed

Chaining weaknesses together no longer needs rare expertise.

Path compressed

Initial access to a high-value asset, in one short hop.

The people building the AI are saying it plainly.

Not vendor noise — the labs building these models and the national cyber authorities watching them, in their own words.

During our testing, we found that Mythos Preview is capable of identifying and then exploiting zero-day vulnerabilities in every major operating system and every major web browser when directed by a user to do so.
Anthropic Frontier Red Team
Anthropic
the bottleneck in cybersecurity is now verifying, disclosing, and patching the large numbers of vulnerabilities that Mythos-class models can surface.
AI will make it easier, faster and cheaper to discover and exploit weaknesses that previously required more time, skill or resource for attackers to identify.
UK National Cyber Security Centre
UK NCSC

So what? Left unchecked, this only gets worse.

None of this is a one-off. The economics now favour the attacker, and the curve runs one way. Here’s the trajectory if defending stays an annual, human-paced exercise.

Near term

Automated attacks keep getting through.

Automated attacks will keep getting through organisations that have deployed every recommended tool — because this was never a tools problem. It’s an effectiveness problem: siloed products aren’t built to work as one, and attackers move through the seams between them.

Mid term

The gap widens.

Adversaries will shift to autonomous attack platforms faster than defenders can improve — and prove — their controls actually hold. The distance between tools deployed and attacks stopped keeps growing.

Long term

Defence becomes humans by exception.

Within a decade, defence will run algorithm against algorithm. No human team can keep pace with attacks that adapt in seconds — and as automation lowers the barrier to entry, the volume of those attacks only climbs.

The trajectory is set. What you control is whether you can prove — today, and every day after — that your defences hold, and keep proving it as the curve steepens.

Two things got worse at once: more weaknesses, less time.

Speed isn’t the whole story. AI is also surfacing genuinely new weaknesses — Project Glasswing found flaws that had hidden in widely used software for decades, invisible to millions of automated tests and years of expert review.

So defenders are caught in a pincer: the pool of exploitable weaknesses keeps growing, while the time to weaponise any one of them collapses. More to fix, and less time to fix it. “Patch everything” was already a losing race — now the backlog grows faster than any team can clear it.

Your obligations are tightening — and the clock isn’t yours to set.

This isn’t a fixed bar you clear once. It’s a ratchet, tightening on timelines you don’t control — audit cycles, contract renewals, regulator deadlines. And primes are pushing the same requirements down the supply chain.

DISP

Moving from four to eight mandatory controls.

SOCI & CIRMP

Demonstrated cyber resilience for critical infrastructure.

APRA CPS 230 / 234

Tested, board-attested operational resilience.

Essential Eight ML2

Evidence for every control — and a defensible path to maturity.

For Australian defence and critical-infrastructure suppliers, security uplift you can prove is now tied to revenue — the contract you’re bidding for assumes it. Attestation by checklist won’t survive contact with an auditor, let alone an attacker, and the time to find the gaps is before the assessment, not after it.

And if you’re still working towards Essential Eight Maturity Level 2, continuous testing shows exactly which controls have evidence gaps — a defensible path to maturity you can start now, not just a longer to-do list.

The attacker’s AI has new moves. So does your testing.

For every step an AI-armed attacker takes, NodeZero takes the same one first — against your real environment, safely, with evidence you can hand to an auditor.

An AI-armed attackerNodeZero, first
Finds weaknesses across your environment faster than your team can patch themFinds the same weaknesses first — safely, inside your production environment
Turns raw findings into working exploits in near real timeProves which findings are genuinely exploitable, with evidence at every step
Chains weaknesses into a path to the assets that matterWalks the same attack paths end-to-end, and shows you exactly where they lead
Iterates until something gets throughRe-tests continuously — not once a year — and verifies every fix actually holds

Meet machine-speed attack with machine-speed proof.

You can’t out-human an AI-armed attacker, and you can’t wait a year between tests. NodeZero runs real attacks inside your environment — continuously, safely — and proves exactly what an attacker could reach today. Not a simulation. Not a scanner’s guess. Proof. And because it’s real proof, it’s also the evidence your DISP, Essential Eight and SOCI obligations now demand.

It runs on inference, never training — your environment’s data is used to find risk, not to train a model, and stays inside the boundary you approve.

< 03:30
to fully compromise a public Hack The Box target.
Horizon3.ai — Our security vision
07:19
to Domain Admin in a financial-services network — undetected.
Horizon3.ai — Our security vision

Every action is deterministic, production-safe and reproducible — the creative AI does the thinking, never the exploiting. The AI approach →

Don’t assume you’re secure. Prove it.

See NodeZero run against a live environment with the Drochaid team.