Horizon3 raises $250M: pentesting is continuous now
Horizon3 tripled to a $2B valuation selling autonomous penetration testing. The annual pentest PDF is dead — attackers already run continuously.
Horizon3 raised a $250 million Series E at a valuation above $2 billion, roughly triple the $650 million it carried at its Series D just over a year ago. The product is NodeZero, an autonomous penetration testing platform that doesn't hand you a vulnerability list — it tries to exploit what it finds and chains the results into working attack paths. The valuation isn't the story. The shift in cadence is.
What actually happened
Per Horizon3's announcement on August 3, the oversubscribed round was co-led by existing investors NightDragon and NEA, with new money from Acrew, Blue Cloud Ventures, EDBI, PSG, SAIC, and Sapphire, plus returning backers including Craft Ventures, Qualcomm Ventures, and SignalFire.
The traction number that matters: NodeZero has run 310,000 production security tests across thousands of organizations, per Help Net Security's report on the round. Not lab tests — production networks, cloud accounts, Kubernetes clusters.
CEO Snehal Antani's framing is deliberately blunt: the company spent six years earning the right to autonomously pentest sensitive networks "with no humans in the loop." The roadmap money goes toward autonomous blue-team agents that remediate what the attacker agents find, closing the loop on both ends.
Why continuous pentesting matters for your business
Most small businesses buy a penetration test the way they buy a fire inspection: once a year, because a customer or insurer asked for it. You get a PDF, you fix the reds, you file it.
That model made sense when running an attack took a skilled human a week. It doesn't now. Unit 42 documented an autonomous campaign against 460+ targets that ran with almost no human input. Your attack surface is being probed continuously whether or not you're testing continuously. A once-a-year snapshot describes a network that no longer exists — you've since added an n8n instance, three SaaS integrations, and an AI agent with an API key.
You probably aren't buying NodeZero. The lesson is the cadence, not the vendor:
- Inventory what has a public IP. Automation servers, admin consoles, staging environments. That list changes monthly and nobody owns it.
- Attach a check to deploys, not to the calendar. An external port scan and a dependency audit in CI catch more than an annual review.
- Test attack paths, not findings. "Low severity" plus "low severity" plus a reused credential is how breaches actually happen.
- Write down who fixes it. Continuous findings with no owner is just a louder backlog.
Key takeaways
- Horizon3 raised $250M at a $2B+ valuation, tripling from $650M, for autonomous pentesting — 310,000 production tests run
- Funding goes toward autonomous blue-team agents that remediate findings from the attacker agents
- Attackers already operate continuously; an annual pentest describes a network you no longer run
- Move the check to your deploy pipeline and assign an owner, or continuous findings just become a bigger backlog
Security checks belong in the pipeline, not on the calendar. We build deployment workflows with dependency audits and exposure checks wired in from day one — see how we set that up.
Sources: Businesswire, Help Net Security, TechCrunch.
- #security
- #penetration-testing
- #ai-agents
- #funding
- #automation
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
WSO2 Agent Manager GA: an agent control plane you host
WSO2 Agent Manager hit GA September 15 under Apache 2.0, self-hosted or SaaS. What an open agent control plane changes about governing the agents you already run.
Read itOpenAI's misalignment disclosure now runs on a 6-day clock
OpenAI published its AI misalignment disclosure framework with six new incident reports and stated review windows of 6 and 12 business days. Put the number in your contract.
Read it