Horizon3 Attack Team

117 posts

Horizon3 Attack Team banner
Horizon3 Attack Team

Horizon3 Attack Team

@Horizon3Attack

@Horizon3ai Attack Team | Security Research | Exploit Dev | TTPs

เข้าร่วม Aralık 2021
54 กำลังติดตาม12.3K ผู้ติดตาม
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
Today we are disclosing the details of CVE-2025-40551, an unauth deserialization vuln leading to remote code execution affecting SolarWinds WebHelpDesk. Find the technical details, indicators of compromise, and proof-of-concept exploit in the blog. horizon3.ai/attack-researc…
English
2
74
261
29.9K
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
We found an interesting CTF-inspired vuln CVE-2026-22200 affecting osTicket, a popular ticketing system. It allows anonymous attackers to exfil local files as BMP images through the mPDF library. This can be chained to RCE if the host is vuln to CNEXT (CVE-2024-2961) horizon3.ai/attack-researc…
English
3
21
93
8.3K
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
Today we are disclosing the details of CVE-2025-64155, an unauth argument injection leading to root remote code execution affecting the Fortinet FortiSIEM. Find the technical details, indicators of compromise, and proof-of-concept exploit in the blog. horizon3.ai/attack-researc…
English
5
99
334
34.2K
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
Check out our new deep dive on CVE-2025-66039 and other related CVEs. We found an authentication bypass, multiple SQL injections, and file upload to RCE in FreePBX. horizon3.ai/attack-researc…
English
4
52
193
19.1K
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
horizon3.ai/attack-researc… While investigating prior CISA KEVs effecting N-able N-central, we discovered a series of vulns that would allow an unauth attacker to leak files via XXE, and in most cases, compromise the N-central database. The DB contains AD creds, API keys, SSH keys, and integration secrets. Check out our latest blog detailing CVE-2025-9316 and CVE-2025-11700.
English
0
22
50
9.9K
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
Session keys and passwords aplenty, here’s our deep-dive for CVE-2025-5777, aka CitrixBleed 2. Apart from the normal root-cause analysis, we’ve doubled down on actionable steps to investigate Indicators of Compromise. horizon3.ai/attack-researc…
English
2
87
234
58.2K
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
@Chak092 This is an example log from ns.log that shows what the non-printable characters look like. We have blurred the specific subsystem source for the time being.
Horizon3 Attack Team tweet media
English
0
0
2
272
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
CVE-2025-5777, aka #CitrixBleed 2, allows leaking of memory in the response which can allow for compromising session tokens, and other sensitive information. A deep-dive to follow next week.
Horizon3 Attack Team tweet media
English
4
75
296
32.7K
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
Just finished reproducing CVE-2025-32433 and putting together a quick PoC exploit — surprisingly easy. Wouldn’t be shocked if public PoCs start dropping soon. If you’re tracking this, now’s the time to take action. #Erlang #SSH
GIF
English
12
134
430
59.9K
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
We discovered an interesting code injection vulnerability, CVE-2025-3248, affecting #Langflow, a popular agentic AI workflow tool. This enables unauthenticated attackers to fully compromise Langflow servers. horizon3.ai/attack-researc…
English
0
37
76
8K
Horizon3 Attack Team
Horizon3 Attack Team@Horizon3Attack·
Today, we are disclosing the details of 4 vulns effecting #Ivanti #EPM which allow an unauth attacker to coerce the machine credential of the EPM server to be used in relay attacks. horizon3.ai/attack-researc… Depending on the environment, compromising the EPM server may be possible - allowing attackers to pivot from the EPM server to EPM clients. 🔺 CVE-2024-10811 🔺 CVE-2024-13161 🔺 CVE-2024-13160 🔺 CVE-2024-13159
English
0
75
186
19.6K