Horizon3, whose AI penetration testing platform NodeZero helps find and exploit attack paths in production systems, raised a $250M Series E at a $2B valuation
Context & Ripple Effects
Horizon3’s latest round follows its earlier $100M Series D for NodeZero, showing continued investor backing for a platform positioned around finding and exploiting attack paths in production environments.
The financing arrives alongside funding for adjacent AI-security approaches, including Depthfirst’s $80M Series B for vulnerability intelligence. Together, the coverage suggests investors are backing multiple layers of automated security testing and remediation rather than a single product category.
First-order effects
- Horizon3 gains $250M of new financing and a $2B valuation benchmark, giving NodeZero’s developer additional capacity to pursue its penetration-testing product strategy.
- Existing and new investors now have a clearer market valuation for a company whose core product automates attack-path discovery and exploitation in production systems.
Second-order effects
- AI-native security vendors pursuing vulnerability discovery, code scanning, credential protection, and threat monitoring will face sharper pressure to distinguish where their tools fit in the security workflow; Depthfirst is one adjacent example.
- Security buyers may increasingly compare point products against platforms that can simulate attack paths, raising the importance of demonstrable workflow coverage rather than AI branding alone.
Third-order effects
- If financings continue to favor automated offensive testing and broader security intelligence, AI security may consolidate around platforms that combine discovery, validation, and remediation workflows.
- The pattern points to a more capital-intensive security-software market, though it remains unclear whether buyers will standardize on broad platforms or retain specialized tools for distinct security functions.
The trend: AI security is moving from narrowly framed detection tools toward funded platforms that automate more of the vulnerability-testing and response lifecycle.