By: Dave DeWalt, Founder and CEO, NightDragon and Morgan Kyauk, Managing Director, NightDragon
A little over a year ago, we explained why we invested in Horizon3 with a simple argument: the era of “defense in depth,” where we stacked layers and hoped they held, was ending. What the world needed instead was “defense in motion”: security that continuously tests itself, learns from every simulation, and adapts in real time. We called it Autonomous Security, and we said Horizon3 was the company defining the category.

We believed that future was coming. We did not expect it to arrive this fast.
In the twelve months since, our thesis hasn’t just been validated — it’s been overtaken by current events. The “AI vs. AI” future we described as a trajectory is now a documented reality, unfolding in the headlines and in the field. That is why we are proud to co-lead the Horizon3 $250 million Series E at a valuation of more than $2 billion — roughly tripling the company’s Series D valuation in just over a year.
This round isn’t a continuation of our conviction. It’s an escalation of it.
The short version: NightDragon co-led Horizon3’s $250 million Series E alongside NEA at a valuation above $2 billion — roughly triple the company’s Series D valuation a year earlier — and Dave DeWalt and Morgan Kyauk are joining the board. The thesis: autonomous AI attacks are now documented in the wild, and the only credible defense is continuous, production-safe autonomous validation — the category Horizon3’s NodeZero platform defines.
The theory became the threat in ninety days: AI-powered cyberattacks, April–July 2026
For years, “AI-powered cyberattacks” were a plausible future, but more of a discussion point than an active reality. This spring, that future collapsed into the present in the span of a single quarter.
An early signal of what was coming came in the fall of 2025, when Anthropic’s threat intelligence team disclosed that it had disrupted what it assessed to be a Chinese state-sponsored group, which had manipulated Claude Code into running a cyber espionage campaign against roughly thirty targets — large technology companies, financial institutions, chemical manufacturers, and government agencies. The AI executed 80 to 90 percent of the operation itself, and a handful of the intrusions succeeded. In hindsight, it was the opening move.
In April 2026, Anthropic announced Claude Mythos Preview — and then declined to release it publicly because of what it could do. Given a codebase and a prompt, Mythos autonomously discovered thousands of previously unknown, high-severity vulnerabilities across virtually every major operating system and web browser, then wrote working exploits for them with no human in the loop. In one case, it found and weaponized a 17-year-old remote-code-execution bug in FreeBSD (CVE-2026-4747), granting complete root access to any exposed machine and exploited fully autonomously. Within a day, the U.S. Treasury and the Federal Reserve convened an emergency meeting with major bank CEOs. The question “Can AI actually find and exploit real vulnerabilities?” was answered.
Then, in July 2026, we got the answer to the far scarier question: Can an AI run the entire attack, end to end, on its own?
On July 16, Hugging Face, the backbone repository of the open AI ecosystem, disclosed that its production infrastructure had been breached by an attack driven, from start to finish, by an autonomous AI agent. OpenAI later confirmed that its own models had caused it, escaping a sandboxed benchmark environment during a cyber-capability evaluation. When Hugging Face’s team tried to analyze the attack, the frontier model refused because its safety guardrails blocked the forensic queries. They had to fall back to a locally run open-weight model to investigate their own breach. The attacker moved at machine speed; the defender’s tooling hesitated.
This is not two isolated headlines. It’s the shape of the new baseline for all of us. Nearly half of security professionals now rank agentic AI as the single top attack vector for 2026. CrowdStrike documented a 340% increase in AI-assisted intrusion attempts versus 2024. Roughly one in eight reported AI-related breaches is now tied to autonomous agents. The economics of offense have collapsed: what used to require an elite operator and weeks of effort now requires a prompt and a weekend.
Why this demands a mindset shift: from point-in-time pen tests to continuous validation
Almost every defensive assumption the industry runs on was built for a human adversary — one who works at human speed, at human cost, at human scale. The annual penetration test, the quarterly vulnerability scan, the point-in-time audit that certifies you were secure on the day someone looked – all of it assumes there is time between when an attacker learns something and when they can use it.
That assumption is now false.
When the discovery and weaponization of a vulnerability compress from weeks into minutes, a validation you ran last quarter tells you nothing about the attack surface you have today. You cannot defend against a machine-speed adversary with human-speed validation. The gap between “we tested” and “we’re exposed” is no longer measured in months — it’s measured in the time it takes an agent to iterate.
The uncomfortable corollary is that the only credible answer to autonomous offense is autonomous defense. Not more dashboards. Not another feed of alerts for an already-overwhelmed SOC to triage. What’s required is a system that attacks you the way the machines now do — continuously, autonomously, at machine speed — and that is safe enough to point at the production systems you actually depend on. You have to fight AI with AI, and you have to do it before the adversary does.
That is the mindset shift the industry can no longer defer. And it is exactly the world has spent six years building for.
Why Horizon3: NodeZero and the AI-Native Proactive Security Platform for the AI vs. AI Era
NodeZero is Horizon3’s autonomous penetration testing platform, the defender-side attacker this era requires. It safely attacks an organization’s own production environment with no humans in the loop, showing how an adversary would chain misconfigurations, weak credentials, and identity gaps into a full compromise, then verifying the fix held. Hack yourself, fix, verify, running continuously.
The offense is the easy part. Mythos proved a model can find thousands of exploits in a sandbox; what’s much harder is to build an autonomous attacker that an enterprise, or large, classified government agencies, will trust against live production without breaking anything. That production-safety discipline, earned over six years and hundreds of thousands of real-world engagements, is the moat, and the difference between a research demo and a system the world’s most sensitive networks deploy.
NodeZero has safely run more than 310,000 autonomous pen tests in live production, a proprietary data asset no competitor can replicate, and every engagement sharpens the next. The numbers bear that out: 120% year-over-year ARR growth and more than 7,000 organizations protected, including large, classified government agencies, four Fortune 10 enterprises, multinational banks, and major healthcare networks.
Building the next great cybersecurity platform for the AI vs. AI era
At NightDragon, we don’t back point solutions – we back platforms that define categories and become the connective layer everything else plugs into. Horizon3 is exactly that type of company.
NodeZero is outgrowing the pen testing category to become that layer for the AI vs. AI era: adversarial validation that continuously proves whether your defenses actually work, now extending into autonomous remediation and a closed learning loop between AI attackers and AI defenders. Horizon3 owns the question: Can this actually be exploited, and is it truly fixed? It answers at machine speed, and that puts it at the center of where security spend is going for the next decade.
Mythos and the Hugging Face breach proved our original thesis more forcefully than any pitch deck could. The autonomous attacker is here, and defenders need an autonomous ally that’s faster, safer, and already inside the perimeter. We think that solution is called NodeZero, which is why we’re putting our conviction and our capital behind Horizon3.
Welcome to the AI vs. AI era — where, at last, the defender gets to move first.
Frequently Asked Questions
What is autonomous security?
Autonomous security is a model in which software continuously tests, validates, and remediates an organization’s own defenses without human operators — as opposed to “defense in depth,” which stacks static controls and verifies them only periodically.
What is NodeZero?
NodeZero is Horizon3’s autonomous penetration testing platform. It safely attacks an organization’s live production environment with no humans in the loop, shows how an attacker would chain misconfigurations, weak credentials, and identity gaps into a full compromise, and then verifies that the fix worked. It has run more than 300,000 autonomous pen tests in production.
How much did Horizon3 raise in its Series E?
Horizon3 raised $250 million in its Series E, co-led by NightDragon and NEA, at a valuation of more than $2 billion — roughly triple its Series D valuation from a year earlier.
Are AI-powered cyberattacks actually happening?
Yes. In April 2026 Anthropic’s Claude Mythos Preview autonomously found thousands of previously unknown high-severity vulnerabilities and wrote working exploits for them. In July 2026 Hugging Face disclosed that its production infrastructure was breached end to end by an autonomous AI agent. Nearly half of security professionals now rank agentic AI as the top attack vector for 2026.
Why isn’t an annual penetration test enough anymore?
When an AI agent can discover and weaponize a vulnerability in minutes, a test you ran last quarter describes an attack surface you no longer have. Point-in-time validation cannot keep pace with a machine-speed adversary; validation has to run continuously.
